Focus
Strata Cloud Manager

Command Center (Summary)

Table of Contents


Command Center (Summary)

Review the data provided by the Summary view.
The Summary view displays a high-level look at all traffic from your users, Prisma Browser users, IoT devices, external hosts, and Prisma SD-WAN branch sites, as well as a preview of some of the issues and anomalies on your network that are spotlighted by the other views. You can use this view as the first-look into the health and security of your network each day.
Summary Licenses
  • You must have at least one of these licenses that comes with a Strata Logging Service license to use the Strata Command Center:
    • Prisma Access license
    • AIOps for NGFW Premium license
  • Or an AIOPs for NGFW Free license alongside a Strata Logging Service license
  • Licenses that are needed for additional metrics in the Summary view:
    • Cloud-Delivered Security Services (CDSS) subscriptions
    • Data Security subscriptions
    • ADEM license
    • AI Access license
    • Prisma Browser license
    • Strata Logging Service (SLS) add-on for Prisma SD-WAN — required to see Prisma SD-WAN data in the Summary view
    • Branch Security license (optional) — enables threat data from Prisma SD-WAN ION devices in the Summary bottom widgets

Central Summary View

The central Summary view provides a look into the data being transferred between the IoT devices, users, external hosts accessing resources from the internet, internet apps, SaaS apps, and private apps on your network.
The lines in the Summary view represent the traffic on your network. Hovering over a line shows the number of sources (users, devices, or sites) behind that traffic path.
You can see how these sources are accessing applications and being secured by your network infrastructure:
  • Prisma Access deployments
  • Next-Generation Firewalls
  • Prisma SD-WAN branch sites
  • Direct Source Access — traffic reaching SaaS applications without passing through a security inspection point (typically from unmanaged or BYOD devices such as contractor laptops or personal devices)
  • Secure Direct Access — With a Branch Security license, this represents traffic reaching applications with security enforcement applied at the branch. Without the Branch Security license, this represents direct access traffic reaching SaaS applications without passing through a security inspection point (typically from unmanaged or BYOD devices such as contractor laptops or personal devices).
There is no direct way to filter all Command Center data by Prisma Browser or Prisma SD-WAN. These are connection types that sit behind Users, IoT, or Unclassified Hosts sources.

Prisma Browser in the Summary View

When Prisma Browser is deployed, it appears in the Summary traffic diagram as an inspection and enforcement point positioned between users and their destinations. Clicking the Prisma Browser node switches the view to a Prisma Browser-centric view that highlights only the traffic paths relevant to Prisma Browser and updates the traffic volumes accordingly.
The Summary page also displays the total number of browser events with a breakdown by event type, giving admins a picture of the scale of browser-level activity across the organization.

Actionable Insights

The Summary page surfaces two actionable insights to help admins identify security gaps and act on them:
Direct App Access When traffic to SaaS applications is reaching destinations without passing through any security inspection, the Summary page flags this and recommends enforcing Prisma Browser on those applications. This ensures that unmanaged and BYOD devices — contractors, third parties, remote workers — must use Prisma Browser as their access method, bringing that traffic under policy control.
Last-Mile Protection Opportunity When traffic is already flowing through Prisma Access or NGFW but Prisma Browser's last-mile controls could provide an additional layer of protection on managed devices, the Summary page surfaces this as a recommendation. Admins can use this signal to identify managed devices that would benefit from Prisma Browser being enabled on top of existing network security measures.

Prisma SD-WAN View in Summary

Admins with a Prisma SD-WAN deployment can view Prisma SD-WAN data by filtering through the IoT or Users source on the Command Center:
  • The total number of Prisma SD-WAN branch sites deployed across the organization
  • Total IoT devices, users, and hosts at those branch sites
  • A Local Breakout traffic category that shows traffic leaving branch sites directly to the internet or private networks without routing through Prisma Access or an NGFW. With a Branch Security license, this traffic is classified as Secure Direct Access, meaning security is enforced at the branch. Without the Branch Security license, Local Breakout traffic is broken down by path type:
    • Direct Internet — traffic exiting directly to the internet from the branch, with a count of unique circuits
    • Private WAN — traffic traversing private wide-area network connections, with a count of unique circuits
    • Prisma SD-WAN Transit VPN — traffic using Prisma SD-WAN secure transit paths, with a count of active paths
    • 3rd Party VPN — traffic routed through third-party VPN services, with a count of active paths
The Local Breakout category helps admins understand how much branch traffic is being secured by Prisma SD-WAN on-box controls versus traffic going directly out without additional inspection.

Source Sub-Types

The Summary page recognizes the following source sub-types, which determine how traffic is classified in the traffic diagram and widgets:
Source Sub-TypeWhat it represents
User Devices with Access AgentA managed device using the Prisma Access agent
User Devices with Prisma BrowserA device accessing applications through Prisma Browser
Prisma SD-WAN SiteA branch site managed by Prisma SD-WAN
Third-Party SiteA branch site using a third-party SD-WAN or connectivity solution
NGFW SiteA branch site using PAN-OS SD-WAN (NGFW-based, distinct from Prisma SD-WAN)
Enterprise ProxyTraffic routed through an enterprise proxy
OtherUnclassified source

Total Threats Count

The Total Threats Count widget gives you a quick view into the total number of threats detected in your network, how many threats have been blocked, how many threats have been alerted, and the change in threats from a selected time range.
Click through to the Activities Insights (InsightsActivity InsightsThreats) screen for a more detailed breakdown of threats on your network.
Widgets in Summary are not impacted by the filter selections.

Best Practices Security Posture Assessment

The Best Practices Posture Assessment widget gives you a quick view into your overall security posture score as a percentage, the change in that score from the selected time range, and the number of critical recommendations that have been identified across your deployment. A higher score reflects better alignment with security best practices across your Prisma Access, NGFW, and Prisma SD-WAN environment.
Click through to the Zero Trust Posture dashboard (InsightsZero Trust Posture) for a full breakdown of your posture score, a prioritized list of recommendations, and guidance on the steps you can take to improve your security posture.

IoT Risky Device Count

The IoT Risky Device Count widget displays the count of IoT devices at critical severity risk, along with the top 5 IoT asset types across your organization. This gives admins visibility into the scale of high-risk IoT activity at a glance.

GenAI Applications

The GenAI Applications widget gives you a quick view into the total number of GenAI applications in use across your network, the change in GenAI app count from the selected time range, and the total number of users who have accessed GenAI applications.
Click through to the AI Access Security dashboard (InsightsAI Access) for a detailed breakdown of GenAI application adoption, usage trends by user and application category, and recommendations for how to better govern and secure GenAI access across your organization.