For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Overview of the Issues page

Learn how to review and manage security issues.

The Issues page consolidates all non-informational issues from your detection sources. By default, the Issues page displays the security issues received over the last seven days. To access the Issues page, go to Cases & IssuesIssues.

Each issue is linked to one or more cases. A case provides the full story of a problem by linking related issues, assets, and artifacts in one place. To make sure that you understand the full picture of how an issue fits into the bigger picture, we recommend that you start your investigation from the Cases page. You can see the issues linked to a case in the Issues & Insights tab of the selected case.

For issues associated with the Health domain, these issues are not linked to cases and should be investigated individually. You can also see Health domain issues on the Health Issues page.

Note

Every 12 hours, the system enforces a cleanup policy to remove the oldest issues once the maximum limit is exceeded. The default issue retention period in Cortex Cloud is 186 days.

Standardized format of user names in issues

Cortex Cloud processes and displays the names of users in the following standardized format, also termed “normalized user”.

<company domain>\<username>

As a result, any issue triggered based on network, authentication, or login events displays the User Name in the standardized format in the Issues and Cases pages.

Deduplicated FW issues

To reduce noise in your environment, if firewall issues with the same name and host are raised within 24 hours, the issues are deduplicated. A label indicates the number of deduplicated issues up to 1,000 issue counts, larger quantities display as 1000+.

Issue fields

To see a full list of issue fields and descriptions, run the following query in the Query Builder:

datamodel dataset = issues

Last updated

Was this helpful?