> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/is_sla_breached.md).

# is\_sla\_breached

Use the `is_sla_breached()` function to return a boolean value indicating whether an SLA has breached its goal. The function wraps the same time-tracking logic used by [`sla_time_remaining`](/xql-command-reference-guide/readme/functions/sla_time_remaining.md)—accounting for active, paused, and completed SLAs and time spent paused—so that you can quickly filter and flag cases that are out of SLA.

## Syntax

```sql
is_sla_breached (<sla_timer_field>)
```

## Parameters

| Name              | Type | Required | Description                                                                                                         |
| ----------------- | ---- | -------- | ------------------------------------------------------------------------------------------------------------------- |
| `sla_timer_field` | JSON | Yes      | An SLA field exposed in the `cases` dataset, such as `resolution_sla`, or a user-defined SLA under `custom_fields`. |

## Returns

The `is_sla_breached()` function returns a boolean:

* **True** when the SLA has exceeded its goal—that is, when the equivalent `sla_time_remaining()` value is negative.
* **False** when the SLA is still within its goal.
* **NULL** when the SLA has no active or completed timing information.

## Usage notes

* Time spent paused does not count toward a breach, so a case that is paused does not continue to lose remaining time.
* The function can be used in the `filter` ,  `sort`,  and `comp`  stages. It is especially useful for quick filtering, for example `filter is_sla_breached(resolution_sla) = true`.
* Use `is_sla_breached()` when you only need a yes/no breach flag; use [`sla_time_remaining` ](/xql-command-reference-guide/readme/functions/sla_time_remaining.md)when you need the numeric duration for ranking or aggregation.
* The function is available to XQL widgets in dashboards and reports, and can be executed through PAPI (for example, `POST /public_api/v1/xql/get_query_results/`).

## Examples

### Example 1: Flag breached cases

**Goal**: Add a boolean column that indicates whether each case has breached its resolution SLA.

**XQL code**:

```sql
dataset = cases // Query the cases dataset
| alter breached = is_sla_breached(resolution_sla) // true if past SLA goal
| fields case_id, status, resolution_sla, breached
| limit 5
```

**Explanation**: For each case, `is_sla_breached()` computes the net elapsed time and compares it against the SLA goal. Cases whose elapsed time (minus pauses) exceeds the goal return **true**; all others return **false**.

**Output**:

| CASE\_ID | STATUS       | RESOLUTION\_SLA                                 | BREACHED |
| -------- | ------------ | ----------------------------------------------- | -------- |
| 23339    | in\_progress | {"goal":"02:00:00","status":"within\_sla", ...} | false    |
| 23340    | in\_progress | {"goal":"01:00:00","status":"within\_sla", ...} | false    |
| 23341    | in\_progress | {"goal":"01:00:00","status":"breached", ...}    | true     |
| 23342    | resolved     | {"goal":"02:00:00","status":"within\_sla", ...} | false    |
| 23343    | resolved     | {"goal":"01:00:00","status":"breached", ...}    | true     |

### Example 2: Filter to only breached cases

**Goal**: Return only the cases that have breached their resolution SLA.

**XQL code**:

```sql
dataset = cases
| filter is_sla_breached(resolution_sla) = true // Keep only breached cases
| fields case_id, severity, assignee
| sort desc severity
```

**Explanation**: The `filter` stage keeps only rows where `is_sla_breached()` evaluates to **true**, producing a focused list of cases that are out of SLA and need escalation.

**Output**:

| CASE\_ID | SEVERITY | ASSIGNEE |
| -------- | -------- | -------- |
| 23341    | critical | alice    |
| 23360    | high     | bob      |
| 23343    | medium   | carol    |

### Example 3: Count breaches by severity

**Goal**: Summarize how many cases have breached their SLA, grouped by severity, to measure operational performance.

**XQL code**:

```sql
dataset = cases
| alter breached = is_sla_breached(resolution_sla)
| filter breached = true
| comp count(case_id) as breached_count by severity
| sort desc breached_count
```

**Explanation**: After flagging each case, the query filters to breached cases and aggregates the count per severity. Because `is_sla_breached()` output flows into standard `filter` and `comp` stages, it integrates cleanly with statistical reporting.

**Output**:

| SEVERITY | BREACHED\_COUNT |
| -------- | --------------- |
| high     | 12              |
| critical | 8               |
| medium   | 5               |
| low      | 1               |

### Example 4: Combine breach status with a custom SLA

**Goal**: Evaluate breach status against a user-defined SLA stored under `custom_fields`, alongside the standard resolution SLA.

**XQL code**:

```sql
dataset = cases
| alter resolution_breached = is_sla_breached(resolution_sla),
        triage_breached = is_sla_breached(custom_fields -> triage_sla)
| filter resolution_breached = true or triage_breached = true
| fields case_id, resolution_breached, triage_breached
| limit 5
```

**Explanation**: Because custom SLAs use the same JSON structure as the resolution SLA, `is_sla_breached()` works identically on them. The query flags cases that have breached either the resolution SLA or the custom triage SLA.

**Output**:

| CASE\_ID | RESOLUTION\_BREACHED | TRIAGE\_BREACHED |
| -------- | -------------------- | ---------------- |
| 23341    | true                 | true             |
| 23360    | true                 | false            |
| 23372    | false                | true             |
| 23380    | true                 | false            |

## Related articles

* **Functions**: [`sla_time_remaining`](/xql-command-reference-guide/readme/functions/sla_time_remaining.md)
* **Stages**: [`alter`](file:///0960011/Cortex_XQL_Command_Reference/Stages/alter.md), [`filter`](file:///0960011/Cortex_XQL_Command_Reference/Stages/filter.md), [`sort`](file:///0960011/Cortex_XQL_Command_Reference/Stages/sort.md), [`comp`](file:///0960011/Cortex_XQL_Command_Reference/Stages/comp.md), [`config`](file:///0960011/Cortex_XQL_Command_Reference/Stages/config.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xql-command-reference-guide/readme/functions/is_sla_breached.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
