Cortex XSIAM provides health alerts to help you monitor the health and integrity of supported Cortex XSIAM resources. Health alerts comprise ingestion, collection, correlation, and event forwarding errors.
Prerequisite
For Cortex XSIAM to monitor data ingestion health and create health issues, you must enable the following settings under Configurations:
Cortex - Analytics: Go to → . For more information, see Enable the Analytics Engine and Identity Analytics.
Data Ingestion Monitoring: Go to → → → . For more information, see Set up your environment.
Cortex XSIAM provides health alerts to help you monitor the health and integrity of supported Cortex XSIAM resources. Health alerts provide insights into health drifts, such as failure events or status changes. The alerts help you stay on top of your health related errors and ensure optimal performance in Cortex XSIAM. In addition, you can set up notifications on health alerts.
Health alerts are associated with the Health Domain. When setting up notification forwarding or other configurations for health alerts, use the filter Alert Domain = Health.
To view health alerts, go to → , or on the Alerts page select the Health Domain table view. Click an alert to see more details in the alert card, or right-click to take actions and investigate an alert. For more information, see Investigate and resolve health alerts.
Note
The Health Alerts page displays alerts that were triggered after July 2024. To see health alerts that were triggered before this date, click Legacy Health Alerts.
Note
Cortex XSIAM enforces the dedup logic to health alerts. This logic reduces the likelihood of identical health alerts from flooding the alerts dataset.