Troubleshooting Agent Workflows
Focus
Focus
Strata Cloud Manager

Troubleshooting Agent Workflows

Table of Contents

Troubleshooting Agent Workflows

Diagnose connectivity failures, device health anomalies, and performance degradation using the Troubleshooting Expert Agent in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Strata Cloud Manager Pro
  • This feature is currently in Beta and available on request. Contact your account team to enable the feature.
  • Superuser role for agent administration, onboarding, and managing permissions
  • Network Administrator or Security Administrator role for agent interaction
This feature leverages a large language model or generative AI, and may contain errors. Double-check for accuracy before applying changes.
The Troubleshooting Expert Agent diagnoses connectivity failures, device health anomalies, and performance degradation across your network security infrastructure. When users report access issues or monitoring systems detect anomalies, this agent correlates data from multiple sources to identify the root cause and generate actionable remediation steps.
Unlike manual troubleshooting that requires you to check multiple dashboards and cross-reference logs, the Troubleshooting Agent automates the diagnostic workflow end-to-end. It retrieves relevant telemetry, applies correlation logic, and presents findings in a structured report that includes both the identified root cause and specific remediation actions you can approve for execution.
Supported Workflows
WorkflowTriggerDescription
Remote Network (IPSec VPN) ConnectivityNLQ, UI ClickTroubleshoot IPSec VPN tunnel failures for remote network connections, including IKE negotiation and routing issues.
Service Connection (IPSec VPN) ConnectivityNLQ, UI ClickDiagnose service connection tunnel issues between Prisma Access and on-premises infrastructure.
Prisma SD-WAN TroubleshootingNLQ, UI Click, IncidentRoot-cause SD-WAN branch connectivity failures, path quality degradation, and failover issues.
GlobalProtect App ConnectivityNLQ, UI ClickDiagnose GlobalProtect app connection failures including authentication, portal/gateway selection, and tunnel establishment.
ADEM DiagnosticsNLQ, UI ClickLeverage ADEM data to diagnose end-user experience issues and network path problems.
Trigger abbreviations: NLQ = natural language query through Strata Copilot; UI Click = contextual prompt on a Strata Cloud Manager page; Incident = automatic response to a Strata Cloud Manager incident.
Common Invocation Examples
QueryWhat It Does
@agent/troubleshooting Why can't user john.doe access Salesforce?Correlates ADEM data, traffic logs, and policy rules to identify the root cause of the user's access failure.
@agent/troubleshooting Check tunnel status for branch-office-3Retrieves IPSec tunnel telemetry, IKE logs, and routing state for the specified remote network.
@agent/troubleshooting My SD-WAN site is experiencing packet lossAnalyzes SD-WAN path metrics, SLA probes, and failover events to identify the degradation source.