For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Posture

AI-generated case summaries

Use AI-generated summaries to quickly understand case details.

To gain immediate situational awareness, Cortex Cloud automatically builds a narrative of the case using AI-generated titles and descriptions. This summarized context allows you to quickly grasp the scope of a case and provides a clear starting point for your investigation.

Leveraging LLM-based summarization, the system analyzes complex data to produce a human-readable overview of:

  • The nature of the threat or activity

  • The key issues and artifacts involved

  • The affected assets or identities

View the AI-generated case summary

When you open a case, the case title and summary is automatically generated. As an investigation evolves, the case context is updated. Each time new data or issues are added, the system regenerates the title and description to ensure your situational awareness reflects the most current information available.

The AI-generated title and description is a calculated value that is regenerated each time you open a case.

This value is not a saved static description, therefore it is not reflected in the saved case names in the list of cases in the Split view , or in the Case Name and Case Description columns in the Table view.

System-generated case titles and descriptions

In addition to the AI-generated case titles and summaries, Cortex Cloud automatically generates static case titles and descriptions that are stored in the cases dataset. These are generated at the time of case creation based on correlated issues, behaviors, and contextual data.

These static descriptions are used when AI-generated case summaries are unavailable or disabled. In addition, they are reflected in the case title in the List of cases in the Split view, and the Case Name and Case Description columns in the Table view.

You can manually update these values. From the Actions Actions_icon.png menu select Edit case details.

Single issue cases

For cases that contain a single issue, the case title and description directly reflect the issue’s title and description. In addition, AI-generated case summaries are not available. If more issues are linked to the case, Cortex Cloud generates a case title and description to reflect the issues in the case, and a AI case title and summary is available.

Limitations

Enable AI summarization

To enable AI case summarization on your tenant, go to Configurations → General → Server Settings → AI Configuration and enable the following settings:

  • Agents & LLM Experience

  • AI Case Summarization

You can also turn AI summarization on or off for a specific case. Take the following steps:

  1. Open the case, click the Actions menu.

  2. Select Edit case details.

  3. Switch the Summarize with AI toggle.


Last updated

Was this helpful?