March 1, 2024
The probable cause
analysis is enhanced to use the Cortex Data Lake
(CDL) logs and provide additional metadata to identify the
probable cause that led to the creation of an alert or incident.
This analysis enables pinpointing the policies, applications,
source zones, URLs, source IPs, and regions potentially causing
the alert, thereby facilitating appropriate remediation actions.
For instance, when session exhaustion triggers an
Adverse Resource Usage alert, you can
utilize the probable cause analysis to identify the primary
contributors to the alert and follow the suggested remediation
recommendations.
|