What is the cause when alerts generated by a correlation rule are not creating an incident?
The correct answer is A -- The rule is configured with alert severity below Medium.
By default, in Cortex XSIAM, only alerts with a severity of Medium or higher will automatically generate incidents. If a correlation rule creates alerts with severity set below Medium (such as Low or Informational), these alerts will not result in the automatic creation of an incident. This ensures that incident queues are not filled with low-priority events.
'Incidents are generated only for alerts with severity of Medium or higher. Alerts below this threshold will not automatically create incidents.'
Document Reference: XSIAM Analyst ILT Lab Guide.pdf
Page: Page 28 (Alerting and Detection section)
===========
Olga
3 days agoGabriele
9 days agoAbel
14 days agoIra
19 days agoJenise
24 days agoRaina
29 days agoLisbeth
2 months agoReid
2 months agoFrance
2 months agoVi
2 months agoRodrigo
2 months agoGerman
2 months agoMarti
3 months agoNakita
3 months agoFrank
3 months agoLawrence
3 months agoNohemi
3 months agoVivienne
3 months agoShantay
4 months agoVivan
4 months agoJosephine
4 months agoReuben
4 months agoTatum
5 months agoGilma
5 months agoDawne
4 months ago