Resolution reasons for incidents and alerts
Describes the resolution reasons for incidents and alerts.
When you resolve an incident or alert you must also specify a resolution reason. The following table describes the resolution reasons available for selection.
Resolved - True Positive
The incident was correctly identified by Cortex XDR as a real threat, and the incident was successfully handled and resolved.
Resolved - False Positive
The incident is not a real threat.
Resolved - Security Testing
The incident is related to security testing or simulation activity such as a BAS, pentest, or red team activity.
Resolved - Known Issue
The incident is related to an existing issue or an issue that is already being handled.
Resolved - Duplicate Incident
The incident is a duplicate of another incident.
Last updated
Was this helpful?
