Notifications
Clear all
Topic starter
15/08/2026 2:20 am
Hey everyone, new here and to Cortex XDR. We've been running it for about three months now.
The detection seems powerful, but my console is flooded. Lots of "suspicious" but ultimately harmless script activity from our devs, and tons of medium-severity alerts that turn out to be normal admin tasks. It feels like we're drowning in false positives and spending more time tuning than actually investigating real threats.
Is this a common experience? How do you balance visibility with noise? Did you have to turn a lot of stuff off, or is there a better way to manage the alert volume? Looking for some real-world tuning tips.