For the complete documentation index, see llms.txt. This page is also available as Markdown.

Search and Investigate

Your cloud security teams perform in-depth analysis and investigation of security issues within your cloud applications and infrastructure. Use Investigate to get answers to questions related to security risks and incidents from Code to Cloud with a simple and intuitive point-and-click interface that is powered by Natural Language Processing (NLP). The keyword search provides a curated list of results with rich visualization. You can then drill down the results to explore data, modify and save the query, and create custom policies to receive alerts within minutes of a policy violation.

search overview 1

Use Investigate > Search to find the latest security incidents identified in your cloud environment and explore what risk factors could have contributed to the incident, for example:

  • Which are the EC2 instances that have risky ports open to the internet, have overly permissive IAM permissions, and contain critical vulnerabilities?

  • Are there any S3 buckets with encryption disabled?

  • Are there any virtual machines that are directly accessible from the internet?

  • Which cloud resources have exploitable vulnerabilities that need to be patched?

  • Which assets in your cloud environment are impacted by the latest log5j vulnerability?

You can use Prisma Cloud Copilot to search and investigate using natural language queries.

What do you want to do?

Start here

Launch your query and search using keywords

Understand Prisma Cloud findings and finding types

Build and modify your query using simple or advanced modes

Explore data and findings in graph and table views and create custom policies

Save your query for future use after exploring data and run background jobs

Get started with code to cloud tracing for vulnerabilities

What’s next?

Review attributes and examples for the query types using advanced mode

Appendix

Built a query you think would be useful to other customers? Contribute using Edit on Github link provided on each page.

Last updated

Was this helpful?