Incident and Alert Event Categories
Focus
Focus
Prisma SD-WAN

Incident and Alert Event Categories

Table of Contents

Incident and Alert Event Categories

Incident event codes in Prisma SD-WAN are organized into eight categories based on the type of failure or condition detected.
Where Can I Use This?What Do I Need?
  • Prisma SD-WAN (Managed by Strata Cloud Manager)
  • Prisma SD-WAN
Prisma SD-WAN groups incident event codes into eight categories based on the area of the network affected. In Strata Cloud Manager Incidents, all event codes appear with the INC_SDWAN_ prefix. The following table describes each category.
Incident and Alert Event Categories
CategoryDescription
ConfigurationIncidents related to policy rule conflicts, dropped rules, and device or network best-practice compliance violations. These incidents indicate that a policy rule conflicts with another rule, has been dropped because it exceeds platform limits, or that a device configuration does not meet recommended guidelines.
DeviceIncidents related to ION device hardware failures, software process errors, system resource constraints, and device management issues. These include disk failures, high memory or CPU utilization, interface errors, process restarts, controller disconnections, and license verification failures.
Digital ExperienceIncidents related to application performance and user experience monitoring. These include high volumes of unclassified application traffic and application performance degradation detected through application monitoring.
Network & TrafficIncidents related to WAN circuit availability, VPN tunnel connectivity, site-level routing, and spoke high-availability cluster state. These include direct internet and private WAN path failures, secure fabric link degradation or outage, site connectivity down or degraded, and spoke HA failover events.
Network ServicesIncidents related to network service availability, including BGP peering sessions, DHCP server and relay operation, NTP synchronization, and DNS resolution. These incidents indicate that a core network service required for device or site operation is unavailable or degraded.
Security ServicesIncidents related to branch security feature availability, including DNS Security cloud connectivity, URL filtering cloud server reachability, and security policy rule creation failures. These incidents indicate that a branch security service is disconnected or that a policy rule could not be enforced on the device.
ServicesIncidents related to service endpoint reachability and standard VPN connectivity to service destinations. These include service endpoint down events and standard VPN endpoint failures aggregated from interface-level incidents.
SoftwareIncidents related to the ION device software image, including unsupported or end-of-life software versions. These incidents indicate that the running image is not recognized by the controller or has reached end-of-life status.