View and Manage SLR Reports
Focus
Focus
Prisma AIRS

View and Manage SLR Reports

Table of Contents

View and Manage SLR Reports

View and download the SLR (PDF format) report, delete it, and re-download the existing SLR reports from Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • AI Runtime Security Risk Assessment in AWS
The SLR reports deliver actionable insights into the cloud applications and workloads discovered in your cloud environment.
You can view and download the SLR report (in PDF format), delete it, and re-download the existing SLR reports fromStrata Cloud Manager.
  1. Log in to Strata Cloud Manager.
  2. Navigate to Insights Prisma AIRS Prisma AIRS AI Runtime: Network intercept.
  3. Click the report icon that reads Download SLR Report as indicated in the image below.
    The dashboard stores the report templates, the scheduled reports, and the generated reports.

Report Templates

The "Report Templates" tab view shows a list of SLR reports, with the following details:
  • Report name.
  • Report Category is based on the SLR deployment type you chose while deploying SLR.
  • Description of the report.
  • Actions allow you to:
    • Download the report in PDF format.
    • Share the report in an email. Enter a single email address or a list of comma-separated email addresses and select Share.
    • Schedule automated report sharing:
      • Time Interval: Specify the time range for data (for example, past 24 hours or the past 7 days) to be included in your automated email reports.
      • Start Date: Select a date to start sending the reports.
      • Frequency: Select how frequently you want to send the reports.
      • At: Set the time to send out the report.
      • Share with: Enter the email addresses of the recipients.
      • Click Schedule.

Scheduled Reports

View and manage your scheduled reports in the “Scheduled Reports” tab. You can delete or edit a report schedule, update the start date, frequency of report generation, and the email address with whom you want to share the report.
Click Save to update the report schedule.

History

The reports “History” tab stores a list of reports, along with the time the report was generated, by which user, the report name, and the status, such as if the report was successfully downloaded, if it was shared, or if the report failed to generate.
Use the download button under “Actions” to download an SLR report for analysis.
SLR Report Details
The SLR report summarizes the traffic to and from your discovered workloads, types of content, potential threats, and actionable actions to mitigate the risk.
Key highlights:
  • Breakdown of application workloads based on region.
  • High-risk applications: application workloads communicating with unsafe internet destinations.
  • Application inventory: Graphical representation of the application inventory, including VMs, serverless, and container workloads per hour.
  • Top five or ten applications based on usage and traffic flow (ingress and egress).

SLR Support for Azure

The Security Lifecycle Review (SLR) report gives you a comprehensive view of application workloads, traffic flows, and threats detected across your Azure cloud infrastructure. The table below further describes these enhancements:
EnhancementDetails
Multi-cloud threat coverageSLR covers AWS and Azure — previously only AWS packet mirror mode was supported.
Inline and monitor-mode supportReports include data from AI Runtime firewalls deployed inline or in monitor mode.
VM-Series inline supportVM-Series firewalls deployed inline are included in the report.
Multi-account report structureReports are broken down per cloud and per account for customers with multiple accounts.
Threats blocked vs. detectedInline firewalls exporting logs to Strata Logging Service (SLS) now distinguish between blocked and detected threats.
Protected vs. monitored trafficTraffic inspected by inline firewalls is labeled Protected instead of Monitored.
When viewing SLR reports for Azure, consider the following:
  • Supported regions. East US, East US 2, West US, West US 2, Central US, North Central US, South Central US, West Central US, Canada Central, Canada East, UK South, North Europe, West Europe
  • Supported VM types:
    • D-series only — Dsv3, Dsv4, Dsv5
    • B-series is notsupported
  • Post-deployment VM restart required:
    • All app VMs must be restarted after FW deployment for VTAP activation
    • Allow ~5 minutes after restart for traffic mirroring to begin
  • Dual-NIC VMs:
    • Default route must point to the dataplane (dp) subnet gateway
    • Single-NIC VMs require no route change
  • Throughput: ~1 Gbps per VTAP
  • Deployment Modes:
    • Dedicated (Per App VNet)— single-phase deployment, FW + VTAP deployed together inside the app VNet
    • Centralized— two-phase deployment (security project first, then application project); destroy in reverse order
  • Known Limitations:
    • No cross-region mirroring
    • 13 VTAP-supported regions only (listed above)