<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Incident Promotions from Secure Endpoint to XDR in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171781#M8494</link>
    <description>&lt;P&gt;Thanks. Really appreciate the reply and sanity check.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2024 15:31:23 GMT</pubDate>
    <dc:creator>TimBTim</dc:creator>
    <dc:date>2024-09-05T15:31:23Z</dc:date>
    <item>
      <title>Incident Promotions from Secure Endpoint to XDR</title>
      <link>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171635#M8491</link>
      <description>&lt;P&gt;For anyone else using XDR.&lt;/P&gt;&lt;P&gt;Since the change occurred where all alerts from SE are sent XDR we have had little to zero incidents in XDR with SE observable's. While this may be a benefit and working as designed to only promote what would be considered actionable, it also has me wondering.&lt;/P&gt;&lt;P&gt;Curious if anyone else is using XDR and experiencing the same?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 11:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171635#M8491</guid>
      <dc:creator>TimBTim</dc:creator>
      <dc:date>2024-09-05T11:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Promotions from Secure Endpoint to XDR</title>
      <link>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171663#M8492</link>
      <description>Yes. Seeing the same thing here too.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 05 Sep 2024 12:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171663#M8492</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-09-05T12:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Promotions from Secure Endpoint to XDR</title>
      <link>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171667#M8493</link>
      <description>&lt;P&gt;I have an internal request created to improve the documentation around this data flow but don't currently have a timeline on when a change will be made to the documentation. I can share that part of the reason the change was made was so Secure Endpoint events will get processed with additional contextual information rather than just being Secure Endpoint events duplicated and displayed in XDR. I know that isn't much information, but hopefully that helps and I'll keep pushing to get the documentation updated with more details.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 12:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171667#M8493</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2024-09-05T12:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Promotions from Secure Endpoint to XDR</title>
      <link>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171781#M8494</link>
      <description>&lt;P&gt;Thanks. Really appreciate the reply and sanity check.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 15:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171781#M8494</guid>
      <dc:creator>TimBTim</dc:creator>
      <dc:date>2024-09-05T15:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Incident Promotions from Secure Endpoint to XDR</title>
      <link>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171794#M8495</link>
      <description>&lt;P&gt;Thanks. I appreciate the reply on this. Yes, I would agree that documentation would help.&lt;/P&gt;&lt;P&gt;I am sure it is to make incidents more valuable in terms of actionable investigation, but have a little better understanding and some context would be helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 15:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/incident-promotions-from-secure-endpoint-to-xdr/m-p/5171794#M8495</guid>
      <dc:creator>TimBTim</dc:creator>
      <dc:date>2024-09-05T15:40:33Z</dc:date>
    </item>
  </channel>
</rss>

