Learn more about analyzing alerts in the alert side panel and the causality view.
To help you understand the full context of an alert, Cortex XDR provides the alert side panel and the causality view that enable you to quickly make a thorough analysis.
The causality view is available for XDR agent alerts that are based on endpoint data and for alerts raised on network traffic logs that have been stitched with endpoint data.
From the Alerts page, locate the alert you want to analyze.
Click the alert and review the information in the alert side panel. If you want to see more information about the alert, click Investigate to open the alert investigation panel.
Right-click anywhere in the alert, and select Investigate Causality Chain.
You can also view the causality chain over time using the Timeline view.
Review the chain of execution and available data for the process and, if available, navigate through the process tree.