What is the cause when alerts generated by a correlation rule are not creating an incident?
The correct answer is A -- The rule is configured with alert severity below Medium.
By default, in Cortex XSIAM, only alerts with a severity of Medium or higher will automatically generate incidents. If a correlation rule creates alerts with severity set below Medium (such as Low or Informational), these alerts will not result in the automatic creation of an incident. This ensures that incident queues are not filled with low-priority events.
'Incidents are generated only for alerts with severity of Medium or higher. Alerts below this threshold will not automatically create incidents.'
Document Reference: XSIAM Analyst ILT Lab Guide.pdf
Page: Page 28 (Alerting and Detection section)
===========
Lisbeth
1 day agoReid
6 days agoFrance
12 days agoVi
17 days agoRodrigo
22 days agoGerman
27 days agoMarti
1 month agoNakita
1 month agoFrank
1 month agoLawrence
2 months agoNohemi
2 months agoVivienne
2 months agoShantay
2 months agoVivan
2 months agoJosephine
3 months agoReuben
3 months agoTatum
3 months agoGilma
3 months agoDawne
2 months ago