Skip to main content
The Command Center in Palo Alto Networks Cortex XCOR provides a high-level overview of alert activity and SLO performance for the groups configured for your tenant. The page also shows a summary of how ingested metrics move through the pipeline.

View the Command Center

On the home page, click the Command Center tab. The page contains the following panels: Command Center displays data for a fixed 24-hour window ending now.

Business Observability Overview

The Business Observability Overview panel shows SLO health for your Command Center groups. By default, the panel hides healthy SLOs to surface issues first. If no SLOs are configured, the panel displays No SLOs configured. Tenant admins can configure Command Center groups.

SLO summary

Four summary boxes appear at the top of the panel:
  • Total: The total number of SLOs across all groups.
  • Critical: SLOs in a critical state.
  • Warning: SLOs in a warning state.
  • Good: SLOs meeting their objective.
Click a state box to toggle visibility of SLOs in that state. The Good box is dimmed by default because healthy SLOs are hidden on load. A dimmed box means those SLOs are currently hidden.

Groups and SLOs

Each Command Center group appears with its name and the count of SLOs it contains. Use the density toggle in the panel header to switch how SLOs are displayed:
  • Show compact view: SLOs appear as rows. Each row shows a colored state indicator, the SLO name, and its availability percentage. Click the SLO name to open the SLO detail page.
  • Show low density view (default when your tenant has six or fewer assigned SLOs): SLOs appear as SLO cards. For standard SLOs, each SLO card shows the availability percentage and a state icon. For signal-based SLOs, the SLO card shows state counts for the underlying signals (individual tracked conditions that make up the SLO) instead of a single percentage. In the upper right corner of an SLO card, click the arrow icon to open the SLO detail page in a new tab.
A group in which every SLO is healthy shows a green state indicator next to the group name. If a group has no visible SLOs in the active state filter, it displays a message that identifies which states are hidden.

Globally triggered alerts

The Globally triggered alerts panel shows critical alert activity across your tenant for the last 24 hours.

Triggered alerts chart

The triggered alerts chart plots the number of critical monitor_triggered change events in time buckets. Hold the pointer over the chart to open a tooltip showing up to ten alerts that triggered during that bucket. When an alert ID is available, the alert title links to its alert details page. If the bucket contains no alerts, the tooltip displays No triggered alerts. If the alert list fails to load, the tooltip displays Failed to load triggered alerts. Click the chart to pin the tooltip open. Click Unpin to dismiss it. The chart includes only critical monitor_triggered events for the active time window. The Triggered alerts count is the sum of the chart buckets for that same window.

Triggered alerts

The Triggered alerts count displays the total number of critical alerts that triggered during the last 24 hours. The count is the sum of all chart buckets. Click the count to open the alerts list filtered to critical status for the last 24 hours.

Cost optimization

The Cost optimization panel shows how your ingested metrics volume is distributed across pipeline stages. Each stage appears as a funnel card in pipeline order. The Ingested funnel card shows total metric volume entering the pipeline, in DPPS (data points per second). Each subsequent funnel card shows that stage’s share as a percentage of the ingested total. Hold the pointer over any non-total funnel card to see its volume in DPPS. Stages with no volume in the current time window are hidden from the funnel. The funnel includes the following stages:
  • Ingested: Total ingested volume.
  • Reduced by aggregation: Volume removed by your aggregation rules.
  • Dropped by your rules: Volume removed by your drop rules.
  • Rate limited: Volume removed by Cortex XCOR rate limits. For more information, see Quotas.
  • Dropped, invalid: Volume that failed validation and was discarded.
  • Persisted: Volume written to storage. Links to the Consumption page.
If no ingestion data is available, the panel displays No ingestion reported for this tenant.