Create a Custom Incident Setting
Focus
Strata Cloud Manager

Create a Custom Incident Setting

Table of Contents

Create a Custom Incident Setting

Where Can I Use This?What Do I Need?
  • One of the following licenses:
Create your own custom incident setting.
  1. Navigate to Incidents > Incidents > Settings.
  2. Select New Custom to create a new incident setting.
  3. Enter the Setting Name and Description.
  4. In the Scope is equal to field, choose Domain to scope the setting to an entire incident domain.
    Selecting Domain disables the Product, Category, and Subcategory fields. A Domain dropdown appears in their place.
    For Domain is equal to, choose the domain you want to configure (for example, Remote Network). After you select a domain, Strata Cloud Manager displays an expandable, read-only list of all incident codes assigned to that domain.
    If any incident codes in the selected domain are already covered by a higher-precedence product-scoped setting with the same action type, a conflict dialog appears showing:
    • The name and scope of the existing conflicting setting
    • The total number of incident codes in the domain and the number that overlap
    • An expandable list of the specific overlapping incident codes
    Product-scoped settings always take precedence over domain-scoped settings for overlapping codes. Click Proceed Anyway to save the domain setting and let the precedence rules handle the overlap, or click Cancel to adjust your configuration.
  5. Select the Product.
    You can choose a product from the following options in the Product field: Cloud NGFW, NGFW, Prisma Access, Posture, or WildFire.
    See Custom Posture Check Management for information about the Posture incidents and see WildFire Incidents for information about the WildFire incidents.
    After selecting the fields, if you change the product, then the other fields will be reset.
  6. Select one or more values from the Severity dropdown.
    Available severity levels are Critical, High, Warning, and Informational. If you do not select a severity, the setting applies to incidents of any severity level. See Severity Criteria for Incident Settings.
    When you select a severity, Strata Cloud Manager filters the Incident Category, Incident Subcategory, and Incident Code dropdowns to show only options that contain incidents matching your selected severity levels.
  7. Select the Incident Category, Incident Subcategory, and Incident Code. You can leave any of these fields set to Any to match all values in that dimension. The subcategory and code dropdowns filter based on your previous selections.
  8. Select the Object Type and the condition associated with it.
    You can create custom incident settings scoped to individual ZTNA application objects.
  9. Select the actions that Strata Cloud Manager has to take when the above conditions are met. Select Raise or Suppress and set the priority. Severity of the incident is derived from the incident code.
  10. Configure the raise and clear conditions of an incident.
    If an incident supports customization, you can configure the specific conditions that must be met before the incident is raised or cleared, including customizable time windows, event frequency thresholds, and state persistence requirements. See Incident Customization for Raise and Clear Conditions for more information.
  11. Select the notification profile.
  12. Save Setting.