Search and Investigate
Your cloud security teams perform in-depth analysis and investigation of security issues within your cloud applications and infrastructure. Use Investigate to get answers to questions related to security risks and incidents from Code to Cloud with a simple and intuitive point-and-click interface that is powered by Natural Language Processing (NLP). The keyword search provides a curated list of results with rich visualization. You can then drill down the results to explore data, modify and save the query, and create custom policies to receive alerts within minutes of a policy violation.

Use Investigate > Search to find the latest security incidents identified in your cloud environment and explore what risk factors could have contributed to the incident, for example:
Which are the EC2 instances that have risky ports open to the internet, have overly permissive IAM permissions, and contain critical vulnerabilities?
Are there any S3 buckets with encryption disabled?
Are there any virtual machines that are directly accessible from the internet?
Which cloud resources have exploitable vulnerabilities that need to be patched?
Which assets in your cloud environment are impacted by the latest log5j vulnerability?
You can use Prisma Cloud Copilot to search and investigate using natural language queries.
What do you want to do?
Start here
Launch your query and search using keywords
Review query types
Understand Prisma Cloud findings and finding types
Build and modify your query using simple or advanced modes
Explore data and findings in graph and table views and create custom policies
Save your query for future use after exploring data and run background jobs
Get started with code to cloud tracing for vulnerabilities
What’s next?
Review attributes and examples for the query types using advanced mode
Appendix
Built a query you think would be useful to other customers? Contribute using Edit on Github link provided on each page.
Last updated
Was this helpful?

