Focus
Strata Cloud Manager

Incident Domains

Table of Contents

Incident Domains

Learn about incident domains in Strata Cloud Manager, which group incident codes into system-defined functional areas for simplified cross-product incident management.
Where Can I Use This?What Do I Need?
  • One of the following licenses:
Incident domains in Strata™ Cloud Manager group incident codes into system-defined functional areas to simplify management across your environments. This functional grouping enables you to apply unified configuration rules and view related incidents across multiple products, complementing traditional product-centric workflows.
This approach gives you two complementary paths for incident management:
  • Domain-based—A single configuration rule covers all incidents within a functional domain across all relevant products (including Next-Generation Firewalls (NGFWs), Prisma® Access, and software-defined wide area network (SD-WAN) platforms).
  • Product-based—Retains existing product-specific workflows for teams structured around product ownership.
Domains coexist with the product taxonomy and do not replace it; the two approaches represent mutually exclusive filter modes in the web interface. Incident domains feature the following key properties:
  • System-defined—Palo Alto Networks® assigns incident codes to domains. You can't create, modify, or delete domains.
  • Cross-product—A single domain can include incident codes from multiple products.
  • Mutually exclusive—Each incident code belongs to exactly one domain.
  • Immutable assignments—Once Palo Alto Networks® assigns an incident code to a domain and releases it, the assignment can't change.
On the Incidents > Summary page, you can use the Domain filter to view the incidents filtered by domains. When you select the Domain mode, the incident list shows all incidents tagged with the selected domain across all licensed products. To view a count of active incidents per domain, use the BY DOMAIN widget on the Summary page. To apply a domain as a filter directly, select the incident count next to the domain name.

Domain-Scoped Custom Incident Settings

You can create a custom incident setting scoped to an entire domain instead of a specific product or incident code. A domain-scoped setting applies the same raise or suppress action and notification profile to every incident code in that domain. To manage domain-scoped settings alongside product-scoped ones, filter the Custom Settings list by domain.
When you save a domain-scoped setting, Strata™ Cloud Manager checks whether a higher-precedence, product-scoped setting with the same action type already covers any incident codes in that domain. If an overlap exists, a conflict dialog appears showing the conflicting setting name, the total number of codes in the domain, and the specific codes that overlap. You can review the overlap and choose to proceed. Strata Cloud Manager saves your domain-scoped setting, which remains active for all codes not already governed by a higher-precedence setting. To configure this setting, see Create a Custom Incident Setting.

Domain Setting Precedence

Domain-scoped settings occupy the second-lowest priority in the incident settings hierarchy. Product-scoped settings take precedence over domain-scoped settings for the same incident code.
The custom incident settings hierarchy follows this precedence order, from most specific to least specific:
  1. Incident code and object level
  2. Incident code level
  3. Product, category, subcategory, and specific codes
  4. Product, category, and subcategory (all codes)
  5. Product and category (all codes)
  6. Product only (all codes)
  7. Domain level
  8. Default setting
To review detailed precedence and conflict resolution examples, see Incident Setting Resolution.

Domain Metadata in Integrations

All downstream integrations include domain information as a named field. In the incident list and the incident detail view, each incident displays the domain name and domain ID of the incident code. To filter and route notifications by functional domain in your external systems, webhook payloads and ServiceNow integration schemas include domain_id as an independent field.