Launch Your Query
Investigate provides a quick and simple option to launch your queries. You get out-of-the-box visibility and risk prioritization filtering with minimal learning.
Before you write a custom query, you can view the queries you recently searched or use one of the top saved queries that allow you to take advantage of the rich set of AI-powered security research provided by Prisma Cloud. You can choose to either create a new search or directly load a query from the Query Library (search suggestions) and view the search results in the interactive graph view (default, when available depending on the query type) or the table view.

You can launch a query using any of the following methods:
Select Investigate > Search.
Choose from the Recent Searches that display the most recent query search results along with the query title and the timestamp for when it was run.

You can view up to 5 pages and each page lists 10 recent searches.
Saved Searches displays the top 10 most popular queries along with query title, who created it (author), and a description of the query.
Select any query listed under Recent Searches or Saved Queries to see the details in a graph or table format.
Irrespective of the number of assets displayed in the Table view, the Graph view displays only up to 50 assets. For example, if your
asset wherequery search displayed 75 assets in the table view, when you switch to the graph view you will only see the first 50 assets.Select any query type, such as Asset, Asset Configuration, Application Asset, Vulnerability, Permissions, Network Configuration, Network, or Audit Event, to view queries specific to that query type. You cannot change the query type of a saved query.
With additional keywords you get more details on what you want to investigate. The blinking asset node guides you to view the asset. You can then expand your query by adding additional findings.

Click in the Search bar.
Enter your query, for example
reachable from untrusted internet sources.As you start typing the query in plain English, Prisma Cloud uses AI assisted semantic matching to retrieve previous top saved queries and displays the most relevant results. For instance, typing “public facing” as a query, returns results with “reachable from untrusted internet sources” as well, because the saved search matches the meaning of the query "public facing". AI assisted search can be toggled on and off as needed. Hover over a result to view additional details.

Select any query to see the details in a graph or table format.

Select Search to build a query from scratch.
Select a query type from the dropdown, for example Asset.

Filter further by selecting additional sub-types such as, Asset Class, Finding Type in, or more.
Select Search to view the results in a graph. Search is enabled only when you enter a valid query, for invalid queries it is grayed out.
Select +Add to select more options and click Search again.
After viewing the results, you can enter a name and description for your custom query and Save it.

Last updated
Was this helpful?

