For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex Cloud Runtime

Cloud Workload Rules page

Use the Cloud Workload Rules page to view and manage rules.

The Cloud Workload Rules page allows users to manage rules. Users can create, edit, filter, and manage rules.

Note

Keep the following caveats in my mind when working with Rules:

  • Instance Administrators are able to view all facets of Rules without restrictions, even if Scope Based Access Control (SBAC) roles are in effect. Learn more about SBAC.

  • If you’ve been assigned a custom role with View/Edit permissions limited by SBAC, you may not be able to view specific Rules.

  • You can further narrow your search in a Rules table by using SBAC to limit the scope of the finding, issues, and case counts.

The Widget section enables the users to get 'at-a-glance' based on Platform, Rule type and Scanner type.

The Cloud Workload Rules page displays both the default rules and user-configured rules, with the following fields.

Rules table columns

Column Name

Description

Rule ID

A unique identifier assigned to each rule.

Rule Name

The name of the rule, typically defined by the user or system.

Description

A brief summary of the rule's purpose and functionality.

Policies

Lists the policies in which the rule is included.

Controls

Compliance controls associated with the rule for regulatory adherence.

Platform

Specifies the platform or environment the rule applies to. For example: Linux, Windows or Kubernetes.

Scanner

The tool or method used to evaluate findings, such as Inventory Scanner, Agentless Disk Scan, Host Scanner, Kubernetes Connector or Kubernetes File System Scanner .

Severity

Defines the severity of the rule.

Data Type

The type of data the rule evaluates. For example: Hosts or Kubernetes Resources

Created By

The user who created the rule.

Last Modified

The date and time the rule was last updated.

Rule Type

Indicates whether the rule is a Built-in or Custom rule.

Remediation

Defines the remediation steps to address the detected misconfiguration.

Applicable assets

Supported applicable asset types.

Available actions

Indicates whether the available action is Prevent and Create an Issue or Create an Issue

Standards

Associated compliance standards or controls

Open issue

No. of open issue related to this rule.

Filter page results

You can use Show filter Panel button in the upper-right corner of the Rules page to filter the existing rules based on different filter criteria, as described below:

Table 6. Rule Filter table

Filter

Allowed Values

Rule Name

Rule names and empty values

Description

Rule description and empty values

Policies

No. of policies

Controls

No. of controls

Platform

Linux, Windows and Kubernetes

Scanner

Agentless Disk Scan, Host Scanner, Kubernetes Connector, Kubernetes File System Scanner and Inventory Scanner

Data type

Hosts, Kubernetes Resources

Severity

Informational, Low, Medium, High and Critical

Created by

System or specific username

Last modified

Selected date and time

Rule type

Built-in and Custom

Remediation

Remediation values

Applicable assets

Supported applicable asset types

Available actions

Prevent and Create an Issue and Create an Issue

Standards

Associated compliance standards or controls

Open Issues

No. of open issue

Rule ID

Unique Id of a rule

Change the layout of the rules table

  1. Navigate to Posture Management > Rules > Cloud Workload.

  2. In the Cloud Workload Rules page, click the More Options icon ().

  3. In the Layout tab, do the following:

    • To add or remove columns, search for a specific column and:

      • Click + to add it to the table.

      • Click - to remove it from the table.

    • To reorder columns, go to the In View section and click and drag columns up or down.

    • To add new columns, go to the Add Columns section and click + to include them in the table.

  4. The table layout updates automatically based on your selections.

Rule details panel

The rule panel displays the following details related to the selected rule:

  • Details of the rule like scanner details, remediation details and more.

  • Compliance Controls for the rule.

This panel enables you to:

  • Edit the rule

  • Save as new

  • Delete the rule

Last updated

Was this helpful?