This article discusses how you can use the Stories Workbench to review Predictive Insight stories for connectivity and performance issues on your network.
Note
Note: XOps is Cato’s unified analytics layer for security and operations, offering insights and guided remediation. XOps has replaced XDR, for more information, see XOps FAQ.
Cato XOps uses predictive analytics to identify potential performance and availability risks across your network. The Predictive Insight engine analyzes traffic patterns, resource utilization, and configuration context to forecast developing issues before they impact service. For example, if a site’s Socket CPU is expected to exceed acceptable operating levels, a story is triggered with relevant forecast data and suggested actions.
The Stories Workbench page shows the details of each Predictive Insight story to help you assess and address emerging risks. You can filter and group stories to focus on the most urgent forecasts, review trend visualizations, and follow guided remediation steps through the playbook for the story.
The Predictive Insight engine currently generates stories for the following issues:
| Indication | Description | Threshold for Generating a Story |
|---|---|---|
| CPU Usage Nearing Full Capacity |
A Socket for a site is forecasted to exceed acceptable utilization levels. The Forecast graph for this story (see below, Understanding the Story Drill-Down Widgets) is based on the maximum CPU usage recorded for each hour at the site. To smooth short-term spikes and highlight longer-term trends, the graph applies a 7-day rolling average to these hourly maximum values. The rolling average is calculated using up to 90 days of historical data, providing sufficient context for trend analysis and forecasting. |
Socket is forecast to exceed 90% CPU usage in the near future. |
| Event Volume Approaching Quota Limit | Detects when event volume is likely to exceed limits based on the account’s DPA license. Limits are defined per plan and subtype (1 Data Unit = 2.5M events), with terms varying by DPA version. Trends are smoothed over time, and predictions are used to identify potential breaches in advance. | The account event count is forecast to exceed a subtype limit (based on DPA license and data units) in the near future. |
The Stories Workbench page shows a summary of the Predictive Insight stories for your account.
For more about using the Stories Workbench page, see Reviewing Site Operations Stories.
You can click on a story in the Stories Workbench to drill-down and investigate the details in a different page. This page contains a number of widgets that help you evaluate the emerging issue identified by the Predictive Insight engine.
These are the story drill-down widgets:
0 comments
Article is closed for comments.