Create SLAs for case and issue resolution

Create Cortex XSIAM resolution SLAs to set time-based goals for case and issue resolution. Service Level Agreements (SLAs) define expected service levels between teams or service providers. Resolution timers track the time required to resolve cases and issues.

Why use Cortex XSIAM resolution SLAs?

Resolution SLAs give analyst teams a framework for prioritizing remediation. Key benefits include:

  • Meet compliance requirements: Regulatory frameworks, such as PCI or HIPAA, mandate timely issue resolution. For example, PCI may require critical issues be fixed within a month, while HIPAA sets a 15-day limit for critical findings.
  • Manage risk for critical assets: Organizations set SLAs based on the sensitivity and criticality of assets. For example, a hospital would prioritize fixing issues impacting patient medical records or payment systems over non-essential displays.
  • Report and measure remediation efforts: SLAs allow leadership to track the effectiveness of security programs and report progress toward the goal of zero SLA violations.

Create a Cortex XSIAM resolution SLA rule

To configure a resolution SLA for cases or issues, create an SLA rule that defines:

  • A time-based goal.
  • The specific cases or issues the goal applies to.

Once created, the SLA rule is automatically applied to all matching existing and future cases or issues.

Create a resolution SLA rule

  1. Select SettingsConfigurationsObject SetupCases or Issues.
  2. Select the SLA Rules tab.
  3. Select Create SLA Rule.
  4. Provide the following information, and then click Next.
    • SLA Rule Name
    • Description (optional)
    • SLA Goal: Define the SLA goal, which is the maximum time allowed to resolve issues. SLAs must be at least 30 minutes.
  5. Define criteria to identify the cases or issues that the SLA will apply to.
    1. Select the filter icon to define which cases or issues this SLA rule applies to.

      Warning

      If no criteria are defined, the rule doesn’t match any cases or issues.

    2. Review the list of cases or issues that match your filtering criteria. If the list is correct, select Next.

  6. On the Summary page, review the information about the new SLA rule. If it is correct, click Done.

    The new SLA rule will appear in the table on the SLA Rules tab.

  7. Set the order of evaluation for the new SLA rule. The first SLA rule that matches a case or issue will be the rule that applies to the relevant (case or issue) Resolution SLA.

    By default new SLA rules are added to the bottom of the list. To move a rule up or down in the list, click and hold the arrows in the Name column and drag the rule to the desired position in the list.

Reorder Cortex XSIAM resolution SLA rules

SLA rule order is important. Rules use a stop-on-first-match evaluation. The first rule matching an issue determines its SLA. When you reorder rules, existing issues matching a higher-priority rule use the new SLA.

  1. Navigate to SettingsConfigurationsObject SetupCases or Issues and select the SLA Rules tab.
  2. Change the order of the SLA rules by dragging the table rows into place. To drag a table row, click and hold an arrow in the Name column and drag the row to the desired position in the table.

Monitor Cortex XSIAM resolution SLA status

Use the following resolution SLA fields on the Cases and Issues pages to filter and sort issues:

  • Resolution SLA: Indicates the amount of time left to meet the SLA deadline. Also indicates the amount of time past the SLA deadline for issues that are overdue.
  • Resolution Timer: Indicates how long it took to resolve the issue. The timer starts when the issue status is New, and stops when the issue status is changed to Resolved.

Monitor case resolution SLA status

Monitor case resolution SLA status in a case header or the cases table.

Tip

The case header shows all active SLAs. In addition to the built-in resolution SLA, you can create SLAs for separate milestones. For more information, see create-case-timers-and-slas.

  1. Navigate to Cases & Issues → Cases, click Display and select Table.
  2. Filter on Resolution SLA > 0 or Resolution Timer > 0 to find cases that are within the SLA.\
    These filters support filtering of whole days only, for example Resolution SLA > 1 filters for cases that have a Resolution SLA of greater than one day.
  3. Filter on Resolution SLA < 0 or Resolution Timer < 0 to find cases that have exceeded the SLA.

Monitor issue resolution SLA status

  1. Navigate to Cases & IssuesIssues.
  2. Filter on Resolution SLA > 0 or Resolution Timer > 0 to find issues that are within the SLA.

    Note

    These filters support filtering of whole days only, for example Resolution SLA > 1 filters for issues that have a Resolution SLA of greater than one day.

  3. Filter on Resolution SLA < 0 or Resolution Timer < 0 to find issues that have exceeded the SLA.

You can also view the issue resolution SLA widgets on the Vulnerability Management dashboard.

Resolution SLA and resolution timer are filterable XQL fields. Their XQL schemas include derived fields. Use them to build queries, correlation rules, and dashboards that track SLA compliance.