: Monitor Prisma Access Incidents Through the Strata Multitenant Cloud Manager
Focus
Focus

Monitor Prisma Access Incidents Through the Strata Multitenant Cloud Manager

Table of Contents

Monitor Prisma Access Incidents Through the Strata Multitenant Cloud Manager

Learn how to monitor Prisma Access incidents in the Strata Multitenant Cloud Manager.
Where Can I Use This?What Do I Need?
  • Strata Multitenant Cloud Manager
If you activate a SASE license or a Prisma Access license for your tenant, you can view detailed reports on the security incidents seen by your tenants. To view this information, access the Strata Multitenant Cloud Manager and select IncidentsPrisma Access Incidents. Prisma Access Incidents replaces the Security Alerts page.
You can view the incident information for a specific tenant and all its children or for all tenants. You can also specify the time range for which you want the reports to display, the alert type that you want to see, and the alert severity level.
Use Region to select and display information for another region. Use Tenant to select and display information for another tenant or subtenant.
You can specify a Time range for displaying the incident information (default display is for the previous 7 days).
This page displays the following widgets:
Widget
Description
Total Incidents
Displays the total number of open incidents compared to the number of open critical incidents versus number of open warning incidents.
Incident Trend
Displays a graph of the number of incidents seen for the chosen tenant and time range. Select to view Open Critical Incidents, Open Warning Incidents, or Open Cleared Incidents.
Tenant Incidents
Displays details about incidents seen per tenant, including information such as the following:
  • Severity — Critical (previously high), warning (previously medium), or informational
  • Tenant — Name of the tenant
  • Incident Title — The title for each incident of all statuses. Select the title to view the incident overview details.
  • Category:
    • Authentication
    • CIE
    • DNS
    • EP
    • GATEWAY
    • GP
    • Internal
    • MU
    • PORTAL
    • Prisma Access
    • Infrastructure
    • RN
    • SC
    • Security
    • SystemBoundary
  • ID — The UUID of the incident object
  • Status — Raised, cleared
  • Created — Date and time the incident is created
  • Updated — Date and time the incident is updated