> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/detailed-view.md).

# Detailed view

The **Detailed View** in the case card provides a table-based format and custom layouts, ensuring full backward compatibility. You can switch between the **Overview** and the **Detailed View** based on your workflow preferences.

The **Detailed View** supports deep inspection and manual analysis while maintaining access to the same underlying case data. It includes the following tabs:

| Tab                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Issues & Insights      | Displays a list of issues and insights linked to the case. Click on an issue or insight to open the issue card.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Key Assets & Artifacts | Displays asset and artifact information of the key artifacts, hosts, and users associated with the case. Hover over an icon for more information, or click the more options icon to see the available views and actions. For more information about investigating key assets and artifacts, see [Investigate artifacts and assets](/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-artifacts-and-assets.md).                                                                                                                                                                                                                                                                                                                         |
| Timeline               | <p>Displays a chronological representation of issues and actions relating to the case. Each timeline entry represents a type of action that was triggered in the issue.</p><p>Issues that include the same artifacts are grouped into one timeline entry and display the common artifact in an interactive link. Click on an entry to view additional details in the Details pane. You can also filter the timeline by action type. Depending on the type of action, you can select the entry to further investigate and take action on it.</p>                                                                                                                                                                                                                                       |
| Case War Room          | <p>The Case War Room is a collection of the Active Response investigation actions, artifacts, and collaboration pieces for an issue or case. It is a chronological journal of the case investigation. You can run commands and playbooks from the War Room and filter the entries for easier viewing.</p><p>The War Room facilitates real-time investigation. Powered by ChatOps, the War Room helps you perform different tasks related to their case investigation using CLI commands. For example, running real-time security actions through the CLI, without switching consoles, and running security playbooks, scripts, and commands. For more information, see <a href="/spaces/ocwvgxtzkvBHMLbPsZuG/pages/TdLltokhEYamuEiRw6pH">Use the War Room in an investigation</a></p> |
| Executions             | Displays the causality chains associated with the case. On this tab, you can investigate a causality chain and take actions on a host. For more information, see [Causality view](/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |

<details>

<summary>Investigate issues and insights</summary>

The **Issues & Insights** tab displays a table of the issues and insights associated with the case.

1. Use the toggle to switch between issues and insights, and add filters to the table to refine the displayed entries.
2. Click an issue to open the issue investigation panel. This panel provides detailed information about an issue, enables you to take actions on an issue, open the causality, and start remediation.
3. If required, you can unlink the issue from the case or link it to other related cases. Click the more options icon and select **Manage issue**+**Link to case** or **Unlink from case**.

{% hint style="info" %}

### Note

When an issue is resolved, it remains linked to a case. Once all of the issues in a case are resolved, the case is automatically closed.
{% endhint %}

</details>

<details>

<summary>Run an automation on an issue</summary>

You can run or rerun an automation on one or more issues. If there is currently an automation running on one or more of the selected issues, the **Run Automation** option does not appear. If an automation is running on the issue, but has been paused (for example, waiting for a user action), you can select to rerun the automation or select a new automation.

1. In the **Issues & Insights** tab, right-click one or more issues and click Run Automation.
2. If the issues have an automation already assigned, choose Rerun current Automation or Choose another Automation. If the playbooks do not have an automation assigned, select a action to run and define the action parameters.
3. Run the automation.

</details>

<details>

<summary>Investigate key assets and artifacts</summary>

The **Key Assets & Artifacts** tab displays all the case assets and artifact information of hosts, users, and key artifacts associated with the case.

1. Investigate artifacts.

   In the **Artifacts** section, review the artifacts associated with the case. Each artifact displays, if available, the artifact information and available actions according to the type of artifact: File, IP Address, and Domain.
2. Investigate hosts.

   In the **Hosts** section, review the hosts associated with the case. Each host displays, if available, host information and available actions.

   To further investigate the host, select the host name to display the Details panel. The panel is only available for hosts with the agent installed and displays the host name, whether it’s connected, along with the **Endpoint Details**, **Agent Details**, **Network**, and **Policy information** details. If the Details panel is not available, click the more options icon next to a host name to see the available options.
3. Investigate users.

   In the **Users** section, review the users associated with the case. Each user displays, if available, the user information and available actions

</details>

<details>

<summary>Investigate the case timeline</summary>

The **Timeline** tab is a chronological representation of issues and actions relating to the case.

1. Navigate to the **Timeline** tab and filter the actions according to the action type.
2. Investigate a timeline entry.

   Each timeline entry is a representation of a type of action that was triggered in the issue. Issues that include the same artifacts are grouped into one timeline entry and display the common artifact in an interactive link. Depending on the type of action, you can select the entry, host names, and artifacts to further investigate the action:

   * Locate the action you want to investigate:
     * For **Quick Actions** and **Case Management Actions**, you can add and view comments relating to the action.
     * For **Issues**, click the action to open the Details panel. In the panel, go to the **Issues** tab to view the issues table filtered by issues ID, the **Key Assets** to view a list of **Hosts** and **Users** associated to the issue, and an option to add **Comments**.
   * Select the Host name to display the endpoint data, if available.
   * Select the Artifact to display the following type of information:
     * **Hash artifact:** Displays the **Verdict**, **File name**, and **Signature status** of the hash value. Select the hash value to view the **Wildfire Analysis Report**, **Add to Block list**, **Add to Allow list** and **Search file**.
     * **Domain artifact:** Displays the **IP address** and **VT score** of the domain. Select the domain name to **Add to EDL**.
     * **IP address:** Display whether the IP address is **Internal** or **External**, the **Whois** findings, and the **VT score**. Expand **Whois** to view the findings and **Add to EDL**.
   * In action entries that involved more artifacts, expand **Additional artifacts found** to further investigate.

</details>

<details>

<summary>Investigate case executions</summary>

The **Executions** tab displays all the causality chains associated with the case. The causality chains are aggregated according to the following types of groupings:

* Host Name
  * Host with an agent installed
  * Host without an agent installed
  * Multiple Hosts
  * Undetected Host
* User Name
  * Username
  * Multiple Users
  * Undetected Users

{% hint style="info" %}

### Note

* Cloud-related issues are displayed in the User Name grouping.
* Prisma Cloud Compute issues are displayed in the Host Name grouping.
  {% endhint %}

How to investigate case executions

1. Investigate the host causality chains.

   In the **Executions** section, review the hosts associated with the case. Review the host information and click the more options icon to perform actions on the host, or open related views.
2. Investigate a causality chain.

   The causality chains are listed according to the Causality Group Owner (CGO), expand the CGO card you want to investigate. Each CGO card displays the CGO name, the following CGO event details, and the causality chain:

   * CGO Name
   * Issue Sources associated with the entire causality chain
   * Execution time of the causality chain
   * Number of issues that include the CGO according to severity.

   **Expand** the causality chain to investigate and perform available Causality View actions. For more information, see [Causality view](/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/causality-view.md).

</details>

**Issue card**

The Issue card provides a full breakdown of an issue, helping you understand the root cause and take action through relevant evidence, remediation guidance, and response options.

The issue card supports full case investigation by retaining case context. Once you have finished reviewing an issue, close the card to return to the initial case investigation.

Each issue card adapts to the type of issue you’re investigating, surfacing the most relevant information and tools at every stage of the workflow. While layouts may vary, most issues share a common set of tabs designed to support triage, investigation, and resolution.

| Tab                   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Overview              | <p>Displays a description of the issue and provides key information, including:</p><ul><li>Assignee</li><li>Status</li><li>Time at which the issue was created and updated</li><li>Suggested automations to run on the issue. Click the automation to open to the Work Plan tab with details of the automation.</li><li>Affected Assets with links to the affected asset cards</li><li>Cases linked to the issue</li><li>If an automation rule triggered an automation (Quick Action, playbook, or agentic agent) to run on the issue, the name of the last automation to run on the issue is displayed.</li></ul><p>The Evidence section contains information to help you investigate the issue, such as the causality chain.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This section is context-specific and shows data according to the issue context.</p></div>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Resolution            | Displays recommended remediation actions, and pending, in progress, and completed actions. For more information, see [Resolution actions](/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/resolution-actions.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Issue Information     | <p>Displays a summary of the issue, such as issue details , indicators, and outstanding tasks. Some fields are informational and some can be edited. Includes the following sections (depending on the layout):</p><ul><li><strong>ISSUE DETAILS</strong>: A summary of the issue, such as type, severity, and when the issue occurred. You can update these fields as required.</li><li><strong>COMMAND AND TASK RESULTS</strong>: Lists any manual commands and playbook task results.</li><li><p><strong>WORK PLAN</strong>: View or take action on the following:</p><ul><li><strong>Playbook tasks</strong>: When a playbook runs, any outstanding tasks appear. You can take various actions here or in the Work Plan tab.</li><li><strong>To-Do Tasks</strong>: An ad-hoc item that is not attached to the Work Plan. Create tasks for users to complete as part of an investigation. These are like a To-Do list that you keep in an investigation on an ad-hoc basis, rather than the Work Plan, which follows a pre-defined process. You can view or create To-Do tasks.</li></ul></li><li><strong>NOTES:</strong> Helps you understand specific actions taken, and allows you to view conversations between analysts to see how they arrived at a certain decision. You can see the thought process behind identifying key evidence and identifying similar cases.</li><li><p><strong>MALICIOUS OR SUSPICIOUS INDICATORS:</strong> A list of any malicious or suspicious indicators. If you have the Threat Intel add-on, you can pivot to the Indicators page, where you can take further action on the indicator.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>Requires the TIM add-on.</p></div></li><li><strong>INDICATORS HANDLING:</strong> Take actions on indicators from the displayed options.</li></ul> |
| Technical Information | Displays an overview of the information collected about the investigation, such as indicators, email information, URL screenshots, etc. When you run a playbook, the sections are automatically completed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Investigation Tools   | Enables you to take action on the issue, such as converting a JSON file to CSV and checking if the IP address is in CIDR.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| War Room              | A comprehensive collection of all investigation actions, artifacts, and collaboration. It is a chronological journal of the issue investigation. Each issue has a unique War Room. For information, see [Use the War Room in an investigation](/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-war-room-in-an-investigation.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Work Plan             | A visual representation of the running playbook that is assigned to the issue. For more information, see [Use the Work Plan in an investigation](/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/investigate-issues/use-the-work-plan-in-an-investigation.md).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-agentix/detect-investigate-and-respond-to-threats/investigation-and-response/analyze-and-resolve-cases/analyze-case-details/detailed-view.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
