Command Center: Strata Cloud Manager
Focus
Strata Cloud Manager

Command Center: Strata Cloud Manager

Table of Contents

Command Center: Strata Cloud Manager

The Strata Cloud Manager Command Center provides a top-level view of the health and security of all your users, IoT devices, hosts, and applications across Prisma Access, NGFW, and Prisma SD-WAN.
Where Can I Use This?What Do I Need?
  • Prisma Access (Managed by Panorama or Strata Cloud Manager)
  • NGFW, including Cloud NGFWs and those funded by Software NGFW Credits
  • Prisma SD-WAN
Each of these licenses include access to Strata Cloud Manager:
The other licenses and prerequisites needed to access the Command Center:
  • Strata Logging Service
  • A specific license to view certain metrics in the Command Center that is outlined below
  • A role that has permission to view the Command Center
→ The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
The Strata Cloud Manager Command Center is your new NetSec homepage; it is an interactive visual summary that will help you assess the health, security, and efficiency of your network. The command center provides a consolidated view of the NetSec platform, and gives you comprehensive visibility into your Sources, Applications, Prisma Access deployment, your NGFWs, Prisma SD-WAN branch sites, and your security services in a single place.
The command center enables you to interact with the data and visualize the relationships between events on the network, so that you can take immediate actions to strengthen your security.
The command center is integrated with the new Activity Insights dashboards (InsightsActivity Insights), and will highlight anomalies detected by your onboarded licenses and subscriptions through actionable insights, and provide a path to remediate those anomalies.
From the new homepage, you can see:
  • A comprehensive view of all traffic on your network flowing between sources (users, IoT devices, external hosts) to applications (internet, SaaS, private).
  • How assets such as users, devices, and applications are being accessed and secured.
  • Navigate to specific dashboards with context for deeper understanding of the issues impacting your network.
  • Types of threats encountered while users are working.
  • Traffic from Prisma SD-WAN branch sites, including Local Breakout paths and branch site health.
Launch Strata Cloud Manager and click Command Center (
) to get started.

How to Interact with the Strata Cloud Manager Command Center

Each view in the command center neatly breaks down all the information you would need to assess the health and security of your network.
The command center automatically refreshes data every 5 minutes and displays the last 24 hours of data by default. You have the option to filter this data for different time periods: the past 1 hour, 3 hours, 7 days, or 30 days.
Each command center view displays different types of visual data flowing from the sources, through Prisma Access and NGFWs or security subscriptions deployed on your network, to the various applications on your network.
The Sources bubbles (hybrid workers, office users, IoT devices, Prisma Browser users, Prisma SD-WAN branch sites, and others) are on the left and the Applications bubbles (accessed on the internet, SaaS, and hosted on-prem or in-cloud) are on the right. The application bubbles display the top three most used applications in each category.
Sources include:
  • IoT Devices – Devices discovered by an active IoT Security license and enabled.
  • Users – Remote and Branch users.
  • Other – Internal and external hosts accessing resources on the internet.
  • Prisma SD-WAN Branch Sites – Branch locations connected through Prisma SD-WAN, including traffic counts and Local Breakout path breakdowns. This also includes third-party branch sites used in remote network scenarios and SD-WAN branch sites.
  • Secure Direct Access — Traffic originating from branch sites that reaches applications in different environments. With a Branch Security license, security is enforced at the branch. Without a Branch Security license, this represents traffic going directly from branch to applications without additional security inspection.
Applications include:
  • Internet Apps – Applications accessed using a web browser.
  • SaaS Apps – Cloud apps owned and managed by an application service provider.
  • Private Apps – Applications hosted in a data center.
You can filter the data in the central view by clicking on the bubbles for sources, deployments, or applications. This will provide you a more detailed view of the tracked data for that view in relation to the bubble selected.
By selecting filters (
), you can filter the data in the command center views by the following:
  • Platform Devices — Prisma Access, NGFW, Direct Source Access, Secure Direct Access
  • Sources — Branch Sites, Users, IoT
  • Connection Types — Prisma Browser, Prisma SD-WAN, and others
There is no direct way to filter all Command Center data by Prisma Browser or Prisma SD-WAN. These are connection types that sit behind Users, IoT, or Unclassified Hosts sources.
When looking at one of the views, you can mouse over the lines for more information about your network, such as the traffic or the threats blocked or allowed on your network.
With an AI Access license, you can filter the traffic in all command center views by GenAI Apps only to better evaluate how GenAI apps in use by users on your network might be affecting your data and security posture.
With an Strata Cloud Manager Pro license, you can enable the Quantum Readiness View to start evaluating your post-quantum cryptography (PQC) posture.
For more information about PQC, Quantum Security, and Quantum Readiness, click here.
When looking at one of the views, you can mouse over the lines for more information about your network, such as the traffic or the threats blocked or allowed on your network.
Below the central visual summary are several key metrics tracked by your activated subscriptions that provide actionable insights into your network. These key metrics provide the ability to navigate to one of several detailed context pages where you can find more information about the metrics that have surfaced and drill-down into possible solutions.

Strata Cloud Manager Command Center Views

The command center provides you with five different views, each with their own tracked data and metrics to examine and interact with.

Command Center (Summary)

Review the data provided by the Summary view.
The Summary view displays a high-level look at all traffic from your users, Prisma Browser users, IoT devices, external hosts, and Prisma SD-WAN branch sites, as well as a preview of some of the issues and anomalies on your network that are spotlighted by the other views. You can use this view as the first-look into the health and security of your network each day.
Summary Licenses
  • You must have at least one of these licenses that comes with a Strata Logging Service license to use the Strata Command Center:
    • Prisma Access license
    • AIOps for NGFW Premium license
  • Or an AIOPs for NGFW Free license alongside a Strata Logging Service license
  • Licenses that are needed for additional metrics in the Summary view:
    • Cloud-Delivered Security Services (CDSS) subscriptions
    • Data Security subscriptions
    • ADEM license
    • AI Access license
    • Prisma Browser license
    • Strata Logging Service (SLS) add-on for Prisma SD-WAN — required to see Prisma SD-WAN data in the Summary view
    • Branch Security license (optional) — enables threat data from Prisma SD-WAN ION devices in the Summary bottom widgets

Central Summary View

The central Summary view provides a look into the data being transferred between the IoT devices, users, external hosts accessing resources from the internet, internet apps, SaaS apps, and private apps on your network.
The lines in the Summary view represent the traffic on your network. Hovering over a line shows the number of sources (users, devices, or sites) behind that traffic path.
You can see how these sources are accessing applications and being secured by your network infrastructure:
  • Prisma Access deployments
  • Next-Generation Firewalls
  • Prisma SD-WAN branch sites
  • Direct Source Access — traffic reaching SaaS applications without passing through a security inspection point (typically from unmanaged or BYOD devices such as contractor laptops or personal devices)
  • Secure Direct Access — With a Branch Security license, this represents traffic reaching applications with security enforcement applied at the branch. Without the Branch Security license, this represents direct access traffic reaching SaaS applications without passing through a security inspection point (typically from unmanaged or BYOD devices such as contractor laptops or personal devices).
There is no direct way to filter all Command Center data by Prisma Browser or Prisma SD-WAN. These are connection types that sit behind Users, IoT, or Unclassified Hosts sources.

Prisma Browser in the Summary View

When Prisma Browser is deployed, it appears in the Summary traffic diagram as an inspection and enforcement point positioned between users and their destinations. Clicking the Prisma Browser node switches the view to a Prisma Browser-centric view that highlights only the traffic paths relevant to Prisma Browser and updates the traffic volumes accordingly.
The Summary page also displays the total number of browser events with a breakdown by event type, giving admins a picture of the scale of browser-level activity across the organization.

Actionable Insights

The Summary page surfaces two actionable insights to help admins identify security gaps and act on them:
Direct App Access When traffic to SaaS applications is reaching destinations without passing through any security inspection, the Summary page flags this and recommends enforcing Prisma Browser on those applications. This ensures that unmanaged and BYOD devices — contractors, third parties, remote workers — must use Prisma Browser as their access method, bringing that traffic under policy control.
Last-Mile Protection Opportunity When traffic is already flowing through Prisma Access or NGFW but Prisma Browser's last-mile controls could provide an additional layer of protection on managed devices, the Summary page surfaces this as a recommendation. Admins can use this signal to identify managed devices that would benefit from Prisma Browser being enabled on top of existing network security measures.

Prisma SD-WAN View in Summary

Admins with a Prisma SD-WAN deployment can view Prisma SD-WAN data by filtering through the IoT or Users source on the Command Center:
  • The total number of Prisma SD-WAN branch sites deployed across the organization
  • Total IoT devices, users, and hosts at those branch sites
  • A Local Breakout traffic category that shows traffic leaving branch sites directly to the internet or private networks without routing through Prisma Access or an NGFW. With a Branch Security license, this traffic is classified as Secure Direct Access, meaning security is enforced at the branch. Without the Branch Security license, Local Breakout traffic is broken down by path type:
    • Direct Internet — traffic exiting directly to the internet from the branch, with a count of unique circuits
    • Private WAN — traffic traversing private wide-area network connections, with a count of unique circuits
    • Prisma SD-WAN Transit VPN — traffic using Prisma SD-WAN secure transit paths, with a count of active paths
    • 3rd Party VPN — traffic routed through third-party VPN services, with a count of active paths
The Local Breakout category helps admins understand how much branch traffic is being secured by Prisma SD-WAN on-box controls versus traffic going directly out without additional inspection.

Source Sub-Types

The Summary page recognizes the following source sub-types, which determine how traffic is classified in the traffic diagram and widgets:
Source Sub-TypeWhat it represents
User Devices with Access AgentA managed device using the Prisma Access agent
User Devices with Prisma BrowserA device accessing applications through Prisma Browser
Prisma SD-WAN SiteA branch site managed by Prisma SD-WAN
Third-Party SiteA branch site using a third-party SD-WAN or connectivity solution
NGFW SiteA branch site using PAN-OS SD-WAN (NGFW-based, distinct from Prisma SD-WAN)
Enterprise ProxyTraffic routed through an enterprise proxy
OtherUnclassified source

Total Threats Count

The Total Threats Count widget gives you a quick view into the total number of threats detected in your network, how many threats have been blocked, how many threats have been alerted, and the change in threats from a selected time range.
Click through to the Activities Insights (InsightsActivity InsightsThreats) screen for a more detailed breakdown of threats on your network.
Widgets in Summary are not impacted by the filter selections.

Best Practices Security Posture Assessment

The Best Practices Posture Assessment widget gives you a quick view into your overall security posture score as a percentage, the change in that score from the selected time range, and the number of critical recommendations that have been identified across your deployment. A higher score reflects better alignment with security best practices across your Prisma Access, NGFW, and Prisma SD-WAN environment.
Click through to the Zero Trust Posture dashboard (InsightsZero Trust Posture) for a full breakdown of your posture score, a prioritized list of recommendations, and guidance on the steps you can take to improve your security posture.

IoT Risky Device Count

The IoT Risky Device Count widget displays the count of IoT devices at critical severity risk, along with the top 5 IoT asset types across your organization. This gives admins visibility into the scale of high-risk IoT activity at a glance.

GenAI Applications

The GenAI Applications widget gives you a quick view into the total number of GenAI applications in use across your network, the change in GenAI app count from the selected time range, and the total number of users who have accessed GenAI applications.
Click through to the AI Access Security dashboard (InsightsAI Access) for a detailed breakdown of GenAI application adoption, usage trends by user and application category, and recommendations for how to better govern and secure GenAI access across your organization.

Threats

Review the data provided by the Threats view.
The Threats view shows the traffic inspected on your network and threats detected by your CDSS subscriptions and Prisma SD-WAN devices. You can use this view to monitor the blocked and alerted threats on your network across Prisma Access, NGFW, and Prisma SD-WAN, or investigate areas of your network that need updated policies to better block any alerted threats.
Threats Licenses
  • Threats licenses, including:
    • Threat Prevention license
    • URL Filtering license
    • WildFire license
    • DNS Security license
    • Branch Security license (optional) — enables threat visibility from Prisma SD-WAN ION devices at branch sites

Central Threats View

The central Threats view provides a look into all the threats on your network that have been identified by your active Cloud-Delivered Security Services subscriptions and Prisma SD-WAN ION devices at branch sites.
The Threats view will show how your Palo Alto Networks CDSS subscriptions are protecting your traffic by monitoring potential threats on your network. The Command Center gives you insight into the traffic inspected for your IoT devices, users, and applications, and the total number of threats allowed or alerted.
The lines in the central Threats view represent the traffic being monitored by your security subscriptions, with the thickness representing the volume of threats detected and the color representing if the threats are of critical, high, medium, or low severity.
Hovering over a traffic line shows the volume of threats detected for that traffic path. Use the global filters at the top of the page to narrow the view by source type, platform, or security service.

Platform Types and Filter Scopes

The Threats view supports the following platform types:
  • Prisma Access
  • NGFW
  • Secure Direct Access — With a Branch Security license, this represents traffic reaching destinations with security enforcement applied at the branch. Without a Branch Security license, this represents direct access traffic that does not pass through a security inspection point.
To view threats specific to Prisma SD-WAN, filter by IoT or Users in the Command Center and select the Prisma SD-WAN connection type.
Standalone Prisma SD-WAN: When a tenant has only a Prisma SD-WAN license (no Prisma Access), the Threats page displays only the threats detected by Prisma SD-WAN devices, if the Branch Security subscription is enabled.

Security Subscriptions

The Security Subscriptions widget gives you a view into your Cloud-Delivered Security Subscriptions, which ones are active, and a snapshot of how they are securing your network.
SubscriptionDescription
Threat PreventionThreat Prevention defends your network against both commodity threats—which are pervasive but not sophisticated—and targeted, advanced threats perpetuated by organized cyber adversaries.
URL FilteringAdvanced URL Filtering is our comprehensive URL filtering solution that protects your network and users from web-based threats.
WildFireThe cloud-delivered WildFire malware analysis service uses data and threat intelligence from the industry’s largest global community, and applies advanced analysis to automatically identify unknown threats and stop attackers in their tracks.
DNS SecurityAutomatically secure your DNS traffic by using Palo Alto Networks DNS Security service.
Clicking on the Security Subscriptions widget (Command CenterView Security Subscriptions) gives you a detailed report of the status of your subscriptions in relation to your NGFWs and Prisma Access deployments. Click Back to the Dashboard to return to the Threats view.

Total Threats Count

The Total Threats Count widget gives you a quick view into the total number of threats detected in your network, how many threats have been blocked, how many threats have been alerted, and the change in threats from a selected time range. This widget also surfaces New and Unknown Threats as a separate metric — threats that do not yet have a known signature — broken down by those that were blocked and those that were allowed through. New and unknown threats represent a higher-risk category and help security teams prioritize investigation into emerging threats before they are widely classified.
Click through to the Activities Insights (InsightsActivity InsightsThreats) for a more detailed breakdown of threats on your network.

Best Practices Security Posture Assessment

The Best Practices Security Posture Assessment widget gives you a view into your security posture score as a percentage, the change in that score from the selected time range, and the number of critical recommendations related to threat prevention gaps in your deployment. This score reflects how well your security policies and subscriptions are aligned with best practices for threat prevention across Prisma Access, NGFW, and Prisma SD-WAN.
Click through to the Zero Trust Posture dashboard (InsightsZero Trust Posture) for a full breakdown of your posture score, a prioritized list of security recommendations, and guidance on how to close the gaps that are impacting your posture score.

Operational Health

Review the data provided by the Operational Health view.
The Operational Health view shows the health of infrastructure and user experience on your network. You can use this view to monitor the health of your NGFWs, Prisma Access deployments, and Prisma SD-WAN branch sites as well as the user experience on your network and review the severity of open incidents in each area.
Operational Health Licenses
  • Monitoring subscriptions, including:
    • ADEM Observability
    • AI-Powered ADEM
    • AIOps for NGFW premium
  • Strata Logging Service (SLS) add-on for Prisma SD-WAN — required for Prisma SD-WAN branch site data to appear
  • ADEM license (optional) — enables the Remote Site Experience Score widget for Prisma SD-WAN branch sites

Central Operational Health View

The central Operational Health view provides a look into the health of infrastructure and of the user experience on your network. If users have an Autonomous Digital Experience Management (ADEM) license, they will receive enhanced data in this view.
The Operational Health view will show how your Palo Alto Networks ADEM subscription monitors the digital experience across all users and branch sites, and applications in your SASE environment. The view also surfaces incidents detected on Prisma Access and NGFW deployments. The bottom widgets provide additional detail on user experience scores, site experience scores, and critical incidents across your network.
The lines in the central Operational Health view represent all the users and branch sites on your network. Users are organized by user experience score, and branch sites are organized by site experience score, with the colors of the lines representing a rating of good, fair, poor, or unmonitored.
Domains are listed from lowest to highest experience score, so the most problematic destinations appear at the top of the list, making it easier to prioritize troubleshooting.
Hovering over any domain name shows two experience scores (when applicable):
  • User Experience Score — reflects the quality of access to that domain for individual users
  • Site Experience Score — reflects the quality of access to that domain from branch sites

Source Types and Sub-Types

The Operational Health view supports two source types:
  • Users — Individual end users connecting through Prisma Access, Prisma Browser, or agentless proxy
  • Branch Sites — Prisma SD-WAN and third-party branch sites, allowing admins to view operational health from the perspective of an entire branch location rather than individual users
Source sub-types available for filtering:
Sub-TypeWhat it represents
Prisma BrowserUsers accessing applications through Prisma Browser
Access AgentUsers connecting via the Prisma Access agent
Agentless ProxyUsers connecting through an agentless proxy
Prisma SD-WAN Branch SitesBranch sites connected through Prisma SD-WAN
Third-Party SitesBranch sites using third-party connectivity
PAN-OS SD-WAN SitesBranch sites using PAN-OS SD-WAN (NGFW-based, distinct from Prisma SD-WAN)

Prisma SD-WAN in Operational Health

Prisma SD-WAN data is surfaced within the Operational Health view through the Users and Branch Sites source types. Admins can filter by Prisma SD-WAN Branch Sites as a source sub-type to view experience scores and incident data specific to branch locations connected through Prisma SD-WAN.
The Operational Health view displays the following for Prisma SD-WAN branch sites:
  • Site Experience Scores — the quality of application access from Prisma SD-WAN branch locations, broken down by Good, Fair, Poor, and Unmonitored
  • Open incidents generated by Prisma SD-WAN, visible in the Critical Incidents widget

Average User Experience

The Average User Experience widget gives you a quick view into the overall experience score for users on your network, the change in that score from the selected time range, and a breakdown of users by experience rating — Good, Fair, and Poor. The score reflects the quality of application access for individual end users as measured across segments of the service delivery chain from their device to the application.
Click through to the NetSec Health Dashboard (InsightsOperationalNetSec HealthUser Devices) for a detailed breakdown of user experience by device, location, and application, along with performance metrics and troubleshooting guidance.

Average Site Experience

The Average Site Experience widget gives you a quick view into the overall experience score for branch sites on your network, the change in that score from the selected time range, and a breakdown of sites by experience rating — Good, Fair, and Poor. The score reflects the quality of application access from branch locations as measured across segments of the service delivery chain from the site to the application.
Click through to the NetSec Health Dashboard (InsightsOperationalNetSec HealthSite) for a detailed breakdown of site experience by location, application, and path type, along with performance metrics and troubleshooting guidance.

Critical Incidents

The Critical Incidents widget gives you a quick view into the total number of critical open incidents across your deployment, the change in that count from the selected time range, and a breakdown by scope — including Prisma Access locations, NGFW devices, Prisma SD-WAN branch sites, and third-party branch sites. This gives you an immediate sense of where the most severe operational issues are concentrated across your network infrastructure.
Click through to the Incidents dashboard (Incidents and AlertsSummary) for a full view of all open incidents organized by severity, scope, and subcategory.

Data Security

Review the data provided by the Data Security view.
The Data Security view shows all the sensitive data detected across your network and various connected SaaS applications. You can use this to monitor and identify high risk sensitive data flows in your organization.
Data Security Licenses
  • Data Security licenses, including:
    • SaaS Security license
    • Data Security license
    • Enterprise DLP license

Central Data Security View

The central Data Security view provides the sensitive and high risk data map across your network and connected SaaS applications. The command center gives you insight into sensitive data users in the organization, the specific sanctioned, unsanctioned, tolerated, or untagged applications where there is sensitive data activity detected (asset upload, download, or assets exposed) as well as number of assets allowed, blocked, quarantined, revoked sharing, or exposed.
The lines in the central Data Security view represent sensitive data being detected through data at rest and data in motion security solutions, with the thickness of the lines representing the quantity of data and the color representing whether that data has been flagged or classified as critical, high, medium, or low risk.

Security Subscriptions

The Security Subscriptions widget gives you a quick view into your active data security subscriptions, how many are currently enabled out of the total available, and which subscriptions are not yet licensed. This helps you quickly identify any gaps in your data security coverage — such as AI Access Security or Next-Generation CASB — that may be leaving data exposure risks unaddressed.
Click through to Activity Insights (InsightsActivity InsightsThreats) for a detailed view of how your active data security subscriptions are performing and the security events they have detected across your network.

Data Profiles at Risk

The Data Profiles at Risk widget gives you a quick view into the total number of data profiles at high severity risk, the change in that count from the selected time range, and a breakdown of at-risk profiles by data state — Data in Motion and Data at Rest. Data profiles represent sets of sensitive data patterns (such as PII, financial data, or intellectual property) that have been detected in your network traffic or stored assets.
Click through to Activity Insights (InsightsActivity InsightsThreats) for a detailed breakdown of which data profiles have been triggered, the assets involved, and the actions that have been taken or recommended.

Data Insights

The Data Insights widget gives you a quick view into three key data security metrics across your environment: Total Assets — the total number of data assets discovered across your SaaS applications and storage; Risk Score — an aggregate score reflecting the overall level of data exposure risk across your assets; and Posture Violations — the number of assets that are not in compliance with your data security policies. Each metric includes a percentage change from the selected time range.
Click through to Activity Insights (InsightsActivity InsightsThreats) for a detailed breakdown of your data asset inventory, risk scoring methodology, and posture violation details.

Command Center (App Security)

Learn about the new App Security dashboard in Strata Cloud Manager.
The App Security view displays a high-level look at the security of your web applications and APIs. Review protected applications, anomalies protected by your policies, alerted and blocked attacks, and discovered applications not currently protected by any security policy.
To learn more about how App Security keeps your network safe, click here.
App Security Licenses and Requirements
  • License:
    • Prisma Access license
    • Private App Security add-on license
  • Other prerequisites
    • Minimum dataplane PAN-OS 11.2.7 or later

Central App Security View

The central App Security view provides a look into the data being transferred between sources and private and discovered apps.
The lines in the central App Security view represent the total requests made on your network, with the thickness of the lines representing the volume of data being transferred from sources and applications.
You can see how these sources are being secured by your Prisma Access deployments with the requests organized into attacks (alerted and blocked), anomlaies, and clean.
The breakdown of applications also provides insight into the number of attacks to your most used apps.

Total Traffic Requests

The Total Traffic Requests widget gives you a quick view into the total number of traffic requests made, including Total Attacks, Attacks Blocked, and how those are trending on your network.
Filtering the Command Center by time period shows you the percent increase or decrease in each count over that selected period.

Recommended Policies and Anomalies Detected

The Recommended Policy and Anomalies Detected widget gives you a view into the total number of Anomalies detected on your network as well as the recommended policy actions you could complete to help lower that number.
Filtering the Command Center by time period shows you the percent increase or decrease of Anomalies and Recommendation over that selected period.
Clicking through the widget brings you to the Recommended tab of the Application Security dashboard, allowing you to start enabling policies to secure your network.

Previewed Policies and Attacks Alerted

The Previewed Policies and Attacks Alerted widget gives you a view into the previewed policies from App Security and the number and trend of attacks alerted on your network.
Filtering the Command Center by time period shows you the percent increase or decrease in requests and attacks over that time period.