09-05-2024 04:58 AM
For anyone else using XDR.
Since the change occurred where all alerts from SE are sent XDR we have had little to zero incidents in XDR with SE observable's. While this may be a benefit and working as designed to only promote what would be considered actionable, it also has me wondering.
Curious if anyone else is using XDR and experiencing the same?
Solved! Go to Solution.
09-05-2024 08:31 AM
Thanks. Really appreciate the reply and sanity check.
09-05-2024 05:40 AM
09-05-2024 08:31 AM
Thanks. Really appreciate the reply and sanity check.
09-05-2024 05:43 AM
I have an internal request created to improve the documentation around this data flow but don't currently have a timeline on when a change will be made to the documentation. I can share that part of the reason the change was made was so Secure Endpoint events will get processed with additional contextual information rather than just being Secure Endpoint events duplicated and displayed in XDR. I know that isn't much information, but hopefully that helps and I'll keep pushing to get the documentation updated with more details.
Thanks,
-Matt
09-05-2024 08:40 AM
Thanks. I appreciate the reply on this. Yes, I would agree that documentation would help.
I am sure it is to make incidents more valuable in terms of actionable investigation, but have a little better understanding and some context would be helpful.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide