> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/search-and-investigate/search-and-investigate.md).

# Search and Investigate

Your cloud security teams perform in-depth analysis and investigation of security issues within your cloud applications and infrastructure. Use **Investigate** to get answers to questions related to security risks and incidents from **Code to Cloud** with a simple and intuitive point-and-click interface that is powered by Natural Language Processing (NLP). The keyword search provides a curated list of results with rich visualization. You can then drill down the results to explore data, modify and save the query, and create custom policies to receive alerts within minutes of a policy violation.

<figure><img src="/files/5AXvKMlIMYDL25PA1mfZ" alt="search overview 1"><figcaption></figcaption></figure>

Use **Investigate > Search** to find the latest security incidents identified in your cloud environment and explore what risk factors could have contributed to the incident, for example:

* Which are the EC2 instances that have risky ports open to the internet, have overly permissive IAM permissions, and contain critical vulnerabilities?
* Are there any S3 buckets with encryption disabled?
* Are there any virtual machines that are directly accessible from the internet?
* Which cloud resources have exploitable vulnerabilities that need to be patched?
* Which assets in your cloud environment are impacted by the latest log5j vulnerability?

You can use [Prisma Cloud Copilot](https://docs.prismacloud.io/en/enterprise-edition/content-collections/prisma-cloud-copilot/prisma-cloud-copilot-benefits#explore-cloud-assets) to search and investigate using natural language queries.

| **What do you want to do?**                                                                      | **Start here**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Launch your query and search using keywords                                                      | [Launch Your Query](/content-collections/search-and-investigate/launch-your-query.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Review query types                                                                               | [Query Types and Required Permissions](/content-collections/search-and-investigate/query-types.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Understand Prisma Cloud findings and finding types                                               | [Prisma Cloud Findings](/content-collections/search-and-investigate/prisma-cloud-findings.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Build and modify your query using simple or advanced modes                                       | [Build and Modify Queries](/content-collections/search-and-investigate/build-modify-queries.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Explore data and findings in graph and table views and create custom policies                    | [Explore Data and Create Custom Attack Path Policies](/content-collections/search-and-investigate/explore-data.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Save your query for future use after exploring data and run background jobs                      | [Query Library and Background Jobs](/content-collections/search-and-investigate/query-library.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Get started with code to cloud tracing for vulnerabilities                                       | [Code to Cloud Tracing for Vulnerabilities](https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/search-and-investigate/c2c-tracing-vulnerabilities/c2c-tracing-vulnerabilities.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p>What’s next?</p><p>Review attributes and examples for the query types using advanced mode</p> | <ul><li><a href="https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/search-and-investigate/asset-queries/asset-queries.md">Asset</a></li><li><a href="https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/search-and-investigate/asset-config-queries/asset-config-queries.md">Asset Configuration</a></li><li><a href="https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/search-and-investigate/application-asset-queries/application-asset-queries.md">Application Asset</a></li><li><a href="https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/search-and-investigate/vulnerability-queries/vulnerability-queries.md">Vulnerability</a></li><li><a href="https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/search-and-investigate/application-queries/application-queries.md">Application</a></li><li><a href="https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/search-and-investigate/permissions-queries/permissions-queries.md">Permissions</a></li><li><a href="/pages/6B8sENxrcDMygukaTXRg">Network Configuration</a></li><li><a href="/pages/vTGxioG4d5sZUIW4qwvo">Network Flow</a></li><li><a href="https://github.com/PaloAltoNetworks/pc-docs-md/tree/main/enterprise-edition/content-collections/search-and-investigate/audit-event-queries/audit-event-queries.md">Audit Event</a></li></ul> |
| Appendix                                                                                         | <ul><li><a href="/pages/UuSS9eoycMEzzZZovWB9">RQL Operators</a></li><li><a href="/pages/PhJsxwT8xK1sF2wgchgc">RQL Examples</a></li><li><a href="/pages/KpEDaFRA9CQLWPyAXRBw">RQL FAQs</a></li></ul><p>Built a query you think would be useful to other customers? Contribute using <strong>Edit on Github</strong> link provided on each page.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/search-and-investigate/search-and-investigate.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
