Investigate and resolve health issues - You can investigate and take action on health issues from the Health Issues page and the Issues Table. - Administrator Guide - Cortex CLOUD

Cortex Cloud Posture Management Documentation

Product
Cortex Cloud Application Security > Cortex CLOUD
License
Cloud Posture Management
Creation date
2025-01-22
Last date published
2026-06-04
Category
Administrator Guide
Abstract

You can investigate and take action on health issues from the Health Issues page and the Issues Table.

The following tasks explain how to investigate and resolve health issues. You can see health issues on the following pages:

  • Go to Settings Health Issues

  • Go to Cases & IssuesIssues and change the table view to Health Domain.

A data ingestion issue identifies disruption in the data ingestion pipeline. For example, a data source is not sending logs, or there is a significant drop in log collection compared to the calculated ingestion baseline.

  1. Identify the error: Type = Ingestion.

  2. Right-click and select Investigate in XQL query.

    The Query Builder opens and runs a prefilled query to display related data ingestion metrics entries.

  3. Review the query results.

    The results provide context for the issue and the events leading up to it. For more information about data ingestion metrics and setting up correlation rules with your own data ingestion logic, see Monitor data ingestion health.

  4. Investigate data collector errors. Return to the Health Issues page, right-click the issue, and select Pivot to viewsView collector details.

    Depending on the type of collector in error, the relevant data collector settings page opens, filtered by data collector.

Automation issues identify potential misconfigurations in automations, enabling you to take a proactive approach to fixing misconfiguration issues before they affect system performance.

  1. Identify the error: Type = Automation.

  2. Click the automation health issue to view the details of the related case or component.

  3. Based on the details of the automation health issue, review any related automations, such as playbooks and integrations, for possible misconfigurations.