zdx-investigate-alerts

List ZDX alerts, retrieve details, and correlate device impact with application metrics.

44|24|Updated May 29, 2025
One-click install
npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zdx-investigate-alerts
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: zdx-investigate-alerts
Source: https://github.com/zscaler/zscaler-mcp-server/tree/main/skills/zdx/investigate-alerts
Command: npx skills add https://github.com/zscaler/zscaler-mcp-server --skill zdx-investigate-alerts

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill enables administrators to systematically investigate active and historical ZDX alerts, determine scope and impact, and correlate alerts with application metrics to identify patterns across time. It provides a structured workflow to drill into affected devices, assess root causes, and prepare actionable remediation plans.

Core Features & Use Cases

  • Triage active alerts across multiple locations and applications.
  • Correlate alerts with PFT, DNS, and availability metrics to pinpoint bottlenecks.
  • Generate HTML/CSV-style reports for rapid incident communication and post-mortems.

Quick Start

To begin an alert investigation, list active alerts, fetch details, determine impacted scope, and start historical pattern checks to guide remediation.

Frequently Asked Questions about zdx-investigate-alerts

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate ZDX alerts to find the root cause of application bottlenecks?

Investigating ZDX alerts involves listing current incidents, retrieving alert details, and mapping affected devices and locations to application metrics for root-cause analysis. This correlation reveals scope, bottlenecks, and patterns for structured remediation.

Can I correlate ZDX alerts with PFT and DNS metrics to pinpoint network issues?

You can correlate ZDX alerts with PFT, DNS, and availability metrics to pinpoint bottlenecks. This helps identify patterns across time and assess root causes for structured remediation planning and escalation.

What is the best way to triage active alerts across multiple locations and applications?

Triaging active alerts across multiple locations and applications requires sequencing alert discovery, device impact assessment, and metric correlation. This workflow produces actionable insights and documented next steps.

How do I generate incident reports from historical ZDX alert data for post-mortems?

Generating incident reports from historical ZDX alert data involves creating HTML or CSV-style reports for rapid incident communication and post-mortems. This allows you to document scope, impact, and remediation plans.

Does alert investigation work for both active and recent historical incidents?

Alert investigation applies to both active and recent historical alerts to reveal scope, bottlenecks, and patterns. It systematically maps affected devices and locations to application metrics for actionable insights.