> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards.md).

# System dashboards

System dashboards help you monitor and evaluate various aspects of your environment. You can access your default view by navigating to **Dashboards & Reports → Dashboard**. To change the displayed dashboard, click the dashboard name and select from the dashboard menu.

Because system dashboards are managed by the platform and cannot be edited or deleted, you can duplicate any dashboard in the **Dashboard Manager**. This creates a customizable version you can modify freely while keeping the original template intact.

<table><thead><tr><th width="135">Dashboard</th><th>Improved Description</th></tr></thead><tbody><tr><td><strong>Agent Management</strong></td><td><p><strong>Track</strong> the status, content versions, and OS distribution of all deployed agents across your organization.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires Cortex XSIAM Premium, Enterprise, or any license with the Enterprise Runtime or Cloud Runtime Security add-on.</p></div></td></tr><tr><td><strong>AI Security</strong></td><td><p><strong>Assess</strong> your organization’s AI ecosystem and security posture to guide governance decisions and prioritize risk-mitigation steps.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/ikqDZ6VAvmd1Bq9ACCxM">What is Cortex Cloud AI Security?</a>.</p></div></td></tr><tr><td><strong>API Security Management</strong></td><td><strong>Identify</strong> and mitigate threats and vulnerabilities across cloud services by monitoring risky API funnels, regional attack patterns, attack traffic trends, and sensitive data exposure.</td></tr><tr><td><strong>Application Security</strong></td><td><strong>Evaluate</strong> your application security posture through targeted insights into exposed assets, code vulnerabilities, and CI/CD pipeline issues.</td></tr><tr><td><strong>Attack Surface Management</strong></td><td><p><strong>Pinpoint</strong> internet-exposed assets and analyze related exposure cases to reduce your external attack vector.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires Cortex XSIAM Premium or any license with the Attack Surface Management (ASM) add-on.</p></div></td></tr><tr><td><strong>Automation Insights</strong></td><td><strong>Review</strong> high-level automation performance, tracking automatically closed issues and execution trends over time.</td></tr><tr><td><strong>Cloud Inventory</strong></td><td><p><strong>Audit</strong> and manage your organization's cloud-based assets across all environments.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires a Cortex XSIAM Enterprise Plus license.</p></div></td></tr><tr><td><strong>Compliance Overview</strong></td><td><p><strong>Review</strong> your organization’s compliance performance against industry standards and internal security frameworks.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/FZxsm5wwqQA9voBn3ZZH">Compliance Overview Dashboard</a>.</p></div></td></tr><tr><td><strong>Cortex Cloud Consumption</strong></td><td><p><strong>Track</strong> your cloud consumption with a detailed breakdown by workload type, date range, and other usage details across all your cloud accounts.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/IztappaFB1TJcai1KgDH">Cortex Cloud Consumption</a>.</p></div></td></tr><tr><td><strong>Cloud Security Operations</strong></td><td><p><strong>Assess</strong> and resolve high-impact cloud security issues quickly to maintain a strong security operational posture.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/M9XY4PhX905g7rycSvYk">Cloud Security Operations</a>.</p></div></td></tr><tr><td><strong>Data Ingestion</strong></td><td><p><strong>Monitor</strong> data ingestion rates, vendor/product breakdowns, and daily quota consumption across your system.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Data prior to July 2023 is inaccessible on this dashboard due to metric updates, but remains queryable via XQL on the metrics_center dataset.</p></div></td></tr><tr><td><strong>Data Security</strong></td><td><p><strong>Discover</strong> and visualize all your data assets across the different cloud services, which will help you understand where the sensitive data is, how it is used and how it is moving across the organization.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/vZWKJaw4TeaUtcclE2Yo">Cortex Data Security</a>.</p></div></td></tr><tr><td><strong>Identity Security</strong></td><td><p><strong>Secure</strong> your identity estate by monitoring your identity inventory, detecting critical findings, identifying the top critical issues and findings in your environment, detecting risky identities, discovering admins and admins at risk, and analyzing 3rd-party access.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/LQrzNDEQj1jzeys4GN5t">What is Cloud Identity Security?</a>.</p></div></td></tr><tr><td><strong>IT Metrics</strong></td><td><p><strong>Analyze</strong> Cortex XDR agent performance metrics—including CPU/memory utilization, connectivity status, hard reboots, and application crashes.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>The Applications Crashing widget is supported for Windows agents only. Requires Cortex XSIAM Premium, Enterprise, or an Enterprise Runtime add-on.</p></div></td></tr><tr><td><strong>KSPM (Kubernetes Security Posture Management)</strong></td><td><p><strong>Investigate</strong> Kubernetes clusters, assets, and resources to locate unprotected areas, vulnerabilities, malware, and exposed secrets.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Full access requires 'All assets' scoping or Instance Administrator privileges. Restricted access applies under granular SBAC scoping. For details, see <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/m85ZJbCDYA3pgEaSotok">Onboard the Kubernetes connector</a> and <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/9AFGTx70crw2n7sT6yFu">Manage user scope</a>.</p></div></td></tr><tr><td><strong>MITRE ATT&#x26;CK Framework Coverage</strong></td><td><p><strong>Review</strong> Cortex XSIAM's content and detection capabilities against the techniques and tactics of the MITRE ATT&#x26;CK framework.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/yC4KrssEkiWXbmYnNXIs">Review MITRE ATT&#x26;CK framework coverage</a>.</p></div></td></tr><tr><td><strong>My Dashboard</strong></td><td><strong>Manage</strong> personal case assignments and monitor individual Mean Time to Respond (MTTR) performance.</td></tr><tr><td><strong>Network Traffic Analysis (NTA)</strong></td><td><strong>Analyze</strong> network traffic patterns and anomalies to highlight potential threats and unusual network behavior.</td></tr><tr><td><strong>NGFW Ingestion</strong></td><td><strong>Track</strong> Next-Generation Firewall (NGFW) log ingestion statuses, daily quota consumption, and individual log type breakdowns.</td></tr><tr><td><strong>Risk Management</strong></td><td><p><strong>Evaluate</strong> risk exposure by investigating compromised accounts and insider threats. The issues displayed in this dashboard are tagged by the research as Identity Threat issues or Identity Analytics issues. A case is displayed if any of its associated issues are tagged as an Identity threat or an Identity Analytics threat.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires the ITDR add-on.</p></div></td></tr><tr><td><strong>Security Manager</strong></td><td><strong>Supervise</strong> operational case management and agent health across your environment. Monitor 30-day open cases by severity, top 10 open cases, and workload distribution by assignee (aged vs. total open cases), alongside top 5 agent version distributions and overall agent status breakdowns.</td></tr><tr><td><strong>Threat Intel Management</strong></td><td><p><strong>Investigate</strong> malicious or suspicious indicators linked to active security cases.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires the Cortex XSIAM Premium license or any other XSIAM license with the Threat Intel Management (TIM) add-on.</p></div></td></tr><tr><td><strong>Troubleshooting Instances</strong></td><td><strong>Diagnose</strong> integration failures by analyzing command and execution errors at the individual instance level.</td></tr><tr><td><strong>Troubleshooting Playbooks</strong></td><td><strong>Debug</strong> playbook and task execution errors using focused runtime metrics and failure analysis.</td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboards.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
