Prisma Cloud: Multiple false positive alerts due to resources exposed to the Internet

Prisma Cloud: Multiple false positive alerts due to resources exposed to the Internet

1292
Created On 07/16/24 12:32 PM - Last Modified 02/21/25 14:53 PM


Symptom


The user has identified that two CSPM alert policies are generating false positive alerts reporting several instances where AWS resource is exposed to the Internet:

  • "Instances exposed to network traffic from the internet"

  • ”AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0)”

When investigating those alerts from "Instances exposed to network traffic from the internet" No public ip attached or either the instance was in stopped state.

 



Environment


  • Prisma Cloud SaaS - Enterprise edition
  • Cloud Accounts


Cause


  • The alerts are legitimate as the customer had allowed those public IPs in Security group.


Resolution


  • The user should use the Investigate option for affected alerts to verify the traffic direction.
  • The user can look at the source IP that caused violation and check in Security Group allowed list.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000010zFqCAI&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail