Incident Domains
Learn about incident domains in Strata Cloud Manager, which group incident codes into
system-defined functional areas for simplified cross-product incident
management.
| Where Can I Use This? | What Do I Need? |
Incident domains in Strata™ Cloud Manager group incident codes into system-defined
functional areas to simplify management across your environments. This functional
grouping enables you to apply unified configuration rules and view related incidents
across multiple products, complementing traditional product-centric workflows.
This approach gives you two complementary paths for incident management:
Domain-based—A single configuration rule covers all incidents within a
functional domain across all relevant products (including Next-Generation
Firewalls (NGFWs), Prisma® Access, and software-defined wide area network
(SD-WAN) platforms).
Product-based—Retains existing product-specific workflows for teams
structured around product ownership.
Domains coexist with the product taxonomy and do not replace it; the two approaches
represent mutually exclusive filter modes in the web interface. Incident domains feature
the following key properties:
System-defined—Palo Alto Networks® assigns incident codes to domains. You
can't create, modify, or delete domains.
Cross-product—A single domain can include incident codes from multiple
products.
Mutually exclusive—Each incident code belongs to exactly one domain.
Immutable assignments—Once Palo Alto Networks® assigns an incident code to
a domain and releases it, the assignment can't change.
On the Incidents > Summary page, you can use the Domain filter to view
the incidents filtered by domains. When you select the Domain mode, the incident list
shows all incidents tagged with the selected domain across all licensed products. To view
a count of active incidents per domain, use the BY DOMAIN widget on the
Summary page. To apply a domain as a filter directly, select the incident
count next to the domain name.
Domain-Scoped Custom Incident Settings
You can create a custom incident setting scoped to an entire domain instead of a
specific product or incident code. A domain-scoped setting applies the same raise or
suppress action and notification profile to every incident code in that domain. To
manage domain-scoped settings alongside product-scoped ones, filter the Custom
Settings list by domain.
When you save a domain-scoped setting, Strata™ Cloud Manager checks whether a
higher-precedence, product-scoped setting with the same action type already covers
any incident codes in that domain. If an overlap exists, a conflict dialog appears
showing the conflicting setting name, the total number of codes in the domain, and
the specific codes that overlap. You can review the overlap and choose to proceed.
Strata Cloud Manager saves your domain-scoped setting, which remains active for all
codes not already governed by a higher-precedence setting. To configure this
setting, see
Create a Custom Incident Setting.
Domain Setting Precedence
Domain-scoped settings occupy the second-lowest priority in the incident settings
hierarchy. Product-scoped settings take precedence over domain-scoped settings for
the same incident code.
The custom incident settings hierarchy follows this precedence order, from most
specific to least specific:
Incident code and object level
Incident code level
Product, category, subcategory, and specific codes
Product, category, and subcategory (all codes)
Product and category (all codes)
Product only (all codes)
Domain level
Default setting
Domain Metadata in Integrations
All downstream integrations include domain information as a named field. In the
incident list and the incident detail view, each incident displays the domain name
and domain ID of the incident code. To filter and route notifications by functional
domain in your external systems, webhook payloads and ServiceNow integration schemas
include domain_id as an independent field.