Incidents and Alerts
Focus
Focus
Prisma SD-WAN

Incidents and Alerts

Table of Contents

Incidents and Alerts

Learn about alerts and incidents in Prisma SD-WAN, including event types, severity levels, filtering options, and event correlation.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN (Managed by Strata Cloud Manager)
  • Prisma SD-WAN
Prisma SD-WAN incidents can now be managed directly under IncidentsIncidents in Strata Cloud Manager. This guide covers the legacy Prisma SD-WAN incidents system, which will eventually be retired. To learn more, see Prisma SD-WAN Incidents in Strata Cloud Manager.
Prisma SD-WAN generates alerts and incidents when the system reaches system-defined or customer-defined thresholds or there is a fault in the system. The Overview tab displays events by category with severity ratings of Critical, Warning, or Informational, along with Incidents by Priority, Your Top Incidents, and Your Top Alerts.
An alert may or may not be an indication of a fault in the network. An alert is raised when the system reaches system-defined or customer-defined thresholds.
An incident is an indication of a fault in the system. Incidents are raised and cleared and vary in severity:
  • Critical—Whole or part of a network is down and requires immediate action.
  • High—Impacts the network and needs immediate attention.
  • Warning—Network is degraded and needs attention soon.
Use incident policies to suppress or escalate incidents based on schedule, code, or resource. You can also change the default priority of system-generated incidents to align with your business requirements.

Which Situation Applies to You?

The following content applies to the legacy Prisma SD-WAN incident system. If you are using or preparing to move to Strata Cloud Manager Incidents, use the links in the table below to find the content that applies to you.
Your situationWhat to do
You are using the legacy Incidents and Alerts system and have not yet moved to Strata Cloud Manager Incidents.Continue reading this topic. You do not need to migrate — the legacy system remains available.
You want to move to Strata Cloud Manager Incidents, or you are planning your migration.See Prisma SD-WAN Incidents in Strata Cloud Manager.
You have no existing incident policies or CloudBlades.See Prepare for Strata Cloud Manager Incidents and contact Prisma SD-WAN Support to enable Strata Cloud Manager Incidents for your tenant.
You have already enabled Strata Cloud Manager Incidents.See Monitor Incidents in Strata Cloud Manager.

Filter Alerts and Incidents

If you have enabled Strata Cloud Manager Incidents, filter and manage your incidents under IncidentsIncidents in Strata Cloud Manager.
Filter and sort alerts and incidents by various parameters so that you can take appropriate action on the events that require attention. Select the Filter widget on the Troubleshooting page to filter alerts and incidents.
Filter and sort alerts and incidents based on the following criteria:
Acknowledge indicates that you are aware of the incident but may not be taking any action at this time. You Acknowledge only unresolved incidents. Acknowledging an incident enables you to display and focus on incidents that require attention. You can select one or more incidents (bulk acknowledge) for Acknowledge.
Unacknowledge indicates that you are aware of the incident but may not be taking any action at this time. You Unacknowledge only acknowledged incidents. You can select one or more incidents for Unacknowledge.
  • Filter By—Filter alerts and incidents by their status:
    • Show Resolved—Displays only resolved incidents when the fault causing the incident is removed.
    • Include Acknowledged—Displays acknowledged and unacknowledged incidents.
    • Show Only Acknowledged—Displays only acknowledged incidents.
    • Show Only Suppressed—Displays only suppressed incidents.
    • Include Suppressed—Displays suppressed and unsuppressed incidents.
      Only incidents are filtered as acknowledged and suppressed. Only Acknowledged incidents are filtered and you can unacknowledge those incidents.
  • Sort By—Sort alerts and incidents by time or severity to display the latest alerts and incidents first.
  • Sites—Sort alerts and incidents by sites to display based on:
    • Site—Name or address search.
    • Viewing—Traffic volume, initiation failure, transaction failure.
    • Site type—Branch or data center.
    • Admin state of the site—Active, monitor or disabled.
  • Severity—Sort alerts and incidents based on the following severity categories:
    • Critical—Whole or part of a network is down and requires immediate action.
    • High—Impacts the network and needs immediate attention.
    • Warning—Degrades the network and needs attention soon.
  • Priority—Sort alerts and incidents based on the priority level:
    • Priority 1 (P1)
    • Priority 2 (P2)
    • Priority 3 (P3)
    • Priority 4 (P4)
    • Priority 5 (P5)
  • Category—Sort alerts and incidents based on the following options:
    • Configuration—Indicates policy rule conflicts or compliance violations.
    • Device—Indicates device hardware, software, system resource, or management issues.
    • Digital Experience—Indicates application performance or user experience issues.
    • Network & Traffic—Indicates WAN circuit, VPN tunnel, or site-connectivity issues.
    • Network Services—Indicates BGP, DHCP, NTP, or DNS service failures.
    • Security Services—Indicates branch security service connectivity or policy enforcement failures.
    • Services—Indicates service endpoint or standard VPN connectivity issues.
    • Software—Indicates unsupported or end-of-life device software images.
  • Code—Sort alerts and incidents based on the alert and incident event codes.
  • Time—Sort alerts by time to display the latest alerts and incidents first.
  • Correlation ID—Correlation ID is a system-generated ID for a raised incident. An incident is associated with raise and clear states. There can be multiple incidents with the same event code in either a raised or cleared state at any given time. Using the correlation ID, you may distinguish between incidents with the same event code. When an incident is cleared, the correlation ID indicates that the specific incident is cleared. This ID is always associated with an incident even if the incident is cleared or resolved.

Event Correlation of Incidents

Event correlation described here applies to the legacy Prisma SD-WAN incident system. If you have enabled Strata Cloud Manager Incidents, manage your incidents under IncidentsIncidents in Strata Cloud Manager.
The event engine performs multiple functions such as incident correlation, suppression, and escalation depending on the network conditions and the administrator configured event policy rules. This improves the operational efficiency of the app-fabric by automatically correlating incidents into an event and the comprehensive event framework control granted by setting the event policies.
The controller analyzes the incoming incidents from the ION devices to determine if they are related and then it aggregates the incidents into a single incident in real time. For example, if the controller receives multiple VPN down incidents, the controller analyzes the incident in real time, determines if they are related, and generates a single Secure Fabric Link incident for the event, while suppressing the original list of incidents.