| March 1, 2024 The probable cause
                                        analysis  is enhanced to use the Cortex Data Lake
                                    (CDL) logs and provide additional metadata to identify the
                                    probable cause that led to the creation of an alert or incident.
                                    This analysis enables pinpointing the policies, applications,
                                    source zones, URLs, source IPs, and regions potentially causing
                                    the alert, thereby facilitating appropriate remediation actions.
                                    For instance, when session exhaustion triggers an
                                        Adverse Resource Usage  alert, you can
                                    utilize the probable cause analysis to identify the primary
                                    contributors to the alert and follow the suggested remediation
                                    recommendations. |