7.4 Strata Copilot & AIOps for NGFW
Key Takeaways
- Strata Copilot is a conversational AI assistant integrated into SCM, leveraging a cybersecurity LLM trained on Palo Alto Networks telemetry, Unit 42 threat intelligence, and PAN-OS architecture.
- Strata Copilot translates natural language inquiries into actionable policy optimizations, real-time threat investigations, and guided remediation workflows with automated preview diff generation.
- AIOps for NGFW operates in two tiers: a Free (Standard) tier providing basic health monitoring and BPA checks, and a Premium tier delivering predictive capacity forecasting, ML anomaly detection, and automated TAC case generation.
- The quantitative Posture Score (0–100) measures enterprise security hygiene by continuously evaluating App-ID adoption, SSL/TLS decryption coverage, security profile enforcement, and attack surface reduction.
- Predictive capacity forecasting utilizes machine learning time-series telemetry to calculate sizing runway and forecast the exact timeline when session tables, packet buffers, or CPU resources will face exhaustion.
7.4 Strata Copilot & AIOps for NGFW
Quick Answer: Strata Copilot and AIOps for NGFW represent Palo Alto Networks AI-driven operational paradigm integrated directly into Strata Cloud Manager (SCM). Strata Copilot is a conversational AI assistant powered by a cybersecurity-specialized Large Language Model (LLM) trained on decades of PAN-OS engineering, telemetry data, and Unit 42 threat intelligence. It translates natural language inquiries into actionable policy optimizations, real-time threat investigations, and guided remediation scripts. Operating alongside Copilot, AIOps for NGFW provides continuous operational intelligence across two tiers: a Free (Standard) tier delivering health monitoring and Best Practice Assessment (BPA) posture scoring (0–100), and a Premium tier unlocking machine learning-driven anomaly detection, predictive capacity forecasting (session table, CPU, and packet buffer exhaustion timelines), and proactive automated TAC support case generation.
1. Strata Copilot: Conversational AI Architecture & Capabilities
As enterprise security infrastructures expand across hybrid clouds, managing thousands of security rules and diagnosing transient network issues becomes increasingly complex. Strata Copilot embeds an intelligent conversational assistant directly within the Strata Cloud Manager user interface.
+-----------------------------------------------------------------------------------------+
| STRATA COPILOT ARCHITECTURE |
+-----------------------------------------------------------------------------------------+
[ Security Analyst / Network Engineer ]
│
│ 1. Natural Language Prompt:
│ "Identify all rules allowing SSH from Untrust that had zero hits
│ over the last 60 days, and generate a cleanup change set."
▼
[ Strata Cloud Manager UI: Strata Copilot Interface ]
│
│ 2. Contextual Query Dispatch
▼
+-----------------------------------------------------------------------------------+
| Palo Alto Networks Cybersecurity LLM & Reasoning Engine |
| |
| - Trained on Unit 42 Threat Intel, CVE Databases, and PAN-OS Architecture |
| - Telemetry Semantic Parser & Knowledge Graph Mapping |
| - Enterprise Tenant Boundary & Privacy Guardrails (Zero Customer Data Training) |
+-----------------------------------------┬-----------------------------------------+
│
│ 3. Queries SLS & SCM Configuration Graphs
▼
+-----------------------------------------------------------------------------------+
| Strata Logging Service (SLS) & SCM Policy Graph |
| |
| - Evaluates Rule Hit Counters, Session Logs, and Threat Signatures |
| - Identifies 14 Shadowed / Unused SSH Rules across 6 Branch Leaf Folders |
+-----------------------------------------┬-----------------------------------------+
│
│ 4. Formulates Actionable Remediation Plan
▼
[ Strata Copilot Response: Structured Findings + Pre-Built Push Preview Delta ]
- Lists affected rules with specific Folder paths
- Displays "One-Click Safe Disable" button
- Pre-validates changes through Multi-Policy Validation Engine before Commit
Core Conversational Operational Pillars
- Policy Optimization & Hygiene:
- Administrators query rulebase health using plain English: "Find all rules in the Americas folder that have service set to 'any' instead of application-default."
- Copilot parses the rule graph, highlights security gaps, and provides candidate rule modifications to replace generic port definitions with strict App-ID profiles.
- Security & Incident Investigation:
- During active threat hunting, analysts ask: "Which internal endpoints resolved newly registered domains or triggered C2 DNS Security alerts in the past 24 hours?"
- Copilot correlates DNS Security logs, WildFire verdicts, and GlobalProtect User-ID mappings from Strata Logging Service, delivering an instant timeline of affected devices, source usernames, and external IP destinations.
- Operational Troubleshooting & Packet Path Diagnostics:
- When users report application access failures, engineers query: "Why was traffic from 10.200.4.15 to 192.168.100.50 dropped at 14:15 UTC yesterday?"
- Copilot cross-references session end reasons (e.g.,
policy-deny,threat,tcp-rst-from-server), identifying the exact rule or security profile responsible without requiring manual log filtering.
2. AIOps for NGFW: Architecture & Service Tiers
AIOps for NGFW (Artificial Intelligence for IT Operations) is a cloud-delivered analytics engine that continuously ingests streaming device telemetry to anticipate failures, detect anomalies, and enforce configuration hardening.
Free (Standard) vs. Premium Tier Comparison
| Functional Capability | AIOps Free (Standard) Tier | AIOps Premium Tier |
|---|---|---|
| Availability & Licensing | Included with every active PAN-OS device and SCM subscription. | Add-on subscription per managed hardware NGFW / VM-Series. |
| Telemetry Data Retention | 7 days of rolling telemetry history. | Up to 365 days (1 year) of longitudinal historical data. |
| Health & Availability Monitoring | Basic online/offline status, interface link state, HA failover events. | Deep component monitoring (optical transceivers, fan speed, power redundancy). |
| Best Practice Assessment (BPA) | Full automated BPA analysis across Security, NAT, Decryption rules. | Automated BPA analysis with trend tracking and compliance drift alerting. |
| Posture Scoring (0–100) | Global and per-device Posture Scoring across security and operations. | Posture Scoring with peer industry benchmarking and guided remediation. |
| Machine Learning Anomaly Detection | Not supported. | Full ML Anomaly Detection: Traffic volume, session spikes, DNS anomalies. |
| Predictive Capacity Forecasting | Not supported. | Time-Series Runway Analysis: Predicts session table, buffer, and CPU exhaustion. |
| Automated Root Cause Analysis (RCA) | Not supported. | Multi-event correlation graph linking symptom to root cause. |
| Proactive TAC Support Integration | Not supported (manual ticket creation). | Automated TAC Case Creation: Auto-opens cases with attached tech-support bundles. |
3. Quantitative Posture Scoring (0–100) & Best Practice Assessment (BPA)
A cornerstone of AIOps is the Posture Score, a normalized numerical rating from 0 to 100 that quantifies how effectively an organization's configuration adheres to Palo Alto Networks hardening guidelines.
+-----------------------------------------------------------------------------------------+
| AIOPS POSTURE SCORE BREAKDOWN |
+-----------------------------------------------------------------------------------------+
OVERALL POSTURE SCORE: 88 / 100
│
┌──────────────────────────────┼──────────────────────────────┐
▼ ▼ ▼
[ Prevention Posture ] [ Decryption Posture ] [ Operational Posture ]
Score: 92 / 100 Score: 74 / 100 Score: 98 / 100
│ │ │
├─ App-ID Adoption (94%) ├─ Outbound Forward Proxy ├─ Logging at Session End
├─ Threat Prevention Profiles │ (SSL Decryption: 72%) ├─ Zone Protection Profiles
├─ Inline Cloud WildFire └─ Decryption Exclusions ├─ Packet Buffer Protection
└─ DNS Security / Sinkhole Audit (Compliant) └─ Secure Admin Access
The Four Posture Dimensions
- Prevention Posture: Evaluates whether traffic is governed by modern Layer 7 controls rather than legacy Layer 4 port rules. Assesses the percentage of rules utilizing App-ID, application-default service constraints, and attached Cloud-Delivered Security Services (Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, DNS Security).
- Decryption Posture: Evaluates the percentage of enterprise outbound and inbound SSL/TLS sessions inspected. Because over 90% of enterprise web traffic is encrypted, uninspected SSL sessions blind security profiles to embedded threats.
- Operational Posture: Analyzes device resilience settings, including Zone Protection Profiles (SYN cookies, flood thresholds), Packet Buffer Protection, and secure management profiles (disabling Telnet, HTTP, and open SNMP).
- Logging Posture: Confirms that rules have Log at Session End enabled, reference valid Log Forwarding Profiles, and forward events to Strata Logging Service.
Automated Best Practice Assessment (BPA) Engine
In legacy Panorama, administrators had to manually generate offline HTML BPA reports. In SCM, AIOps executes BPA evaluations continuously in real time. Whenever a configuration is staged, SCM calculates the delta impact on the Posture Score, warning administrators if a proposed change will degrade overall enterprise hygiene.
4. Machine Learning-Driven Anomaly Detection Across Traffic & System Health
AIOps Premium employs unsupervised machine learning algorithms to establish dynamic, mathematical baselines for every managed firewall. Unlike static thresholds (which trigger false positives during normal traffic surges), AIOps learns diurnal, weekly, and seasonal usage patterns.
+-----------------------------------------------------------------------------------------+
| ML DYNAMIC BEHAVIORAL ANOMALY DETECTION |
+-----------------------------------------------------------------------------------------+
Session Rate (cps)
▲
│ Upper Dynamic Baseline Threshold
│ . - - - - - - - - - - - - - - - - - - - - - .
│ / \ [ ANOMALY SPIKE! ]
│ / Normal Expected Range \ ▲ (Alert!)
│ /\ / \ /│\
│ / \ / \ / │ \
│ ────/────\───/───────────────────────────────────────────────────────X──┼──\────
│ / \ / │ \
│ / ' - - - - - - - - - - - - - - - - - - - - - - - - - - - - - .│ \
│ Lower Dynamic Baseline Threshold │
└──────────────────────────────────────────────────────────────────────────┴──────► Time
08:00 10:00 12:00 14:00 16:00 18:00 20:00 22:00
Core Anomaly Detection Categories
- Traffic Flow Anomalies: Identifies sudden deviations in application throughput, unexplained spikes in embryonic TCP sessions (potential SYN flood), anomalous UDP volume (DNS amplification attacks), or sudden surges in session drops.
- System Health & Resource Anomalies: Detects subtle degradation patterns before hardware fails:
- Packet Descriptor Depletion: Identifies micro-burst traffic saturating on-chip descriptor rings.
- Data Plane Memory Leaks: Tracks gradual, non-recovering memory growth in packet processing daemons.
- Interface CRC Error Surges: Alerts to physical cable degradation, transceiver misalignment, or switch port flapping.
- Correlated Incident Graphing: When a network disruption occurs, a single failure often generates dozens of simultaneous secondary alerts (e.g., BGP neighbor drop, OSPF state change, interface down, IPsec tunnel failure). AIOps correlates these alerts into a single Root Cause Incident, preventing alert fatigue and isolating the physical link failure as the primary trigger.
5. Predictive Capacity Forecasting & Sizing Runway
Hardware replacement and capacity planning traditionally rely on guesswork or retrospective post-mortems following an outage. AIOps Premium introduces Predictive Capacity Forecasting, utilizing linear and non-linear regression models to project hardware resource exhaustion timelines.
+-----------------------------------------------------------------------------------------+
| PREDICTIVE CAPACITY RUNWAY FORECASTING |
+-----------------------------------------------------------------------------------------+
Active Sessions
▲
│ MAX HARDWARE CAPACITY (PA-3220)
500K ──────────────────────────────────────────────────────[ CRITICAL LIMIT: 500,000 ]──
│ /
400K / <-- Projected Growth Curve
│ / (Exhaustion in 42 Days!)
300K . - - -'
│ . - - - '
200K . - - - - '
│ . - - - - '
100K ────────'
│ Historical Telemetry (Last 180 Days)
└─────────────────────────────────────────────┬───────────────────────────┬────────►
Day 1 Today (Day 180) Day 222
Monitored Hardware Metrics & Runway Calculations
- Session Table Capacity: Tracks active concurrent session growth. If a branch PA-440 approaches 85% of its maximum concurrent session limit (200,000 sessions), AIOps calculates the exact date when the table will be saturated based on trailing 30-day and 90-day growth trajectories.
- Data Plane & Management Plane CPU: Separates transient CPU spikes (e.g., heavy file downloads) from structural CPU exhaustion, projecting when baseline utilization will breach 80%.
- Packet Buffer & Queue Depth: Analyzes buffer occupancy trends, alerting network engineers before bursty traffic patterns induce packet discards on ingress queues.
- Hardware Lifecycle & Refresh Advisory: When a firewall model approaches capacity or vendor End-of-Sale / End-of-Support milestones, SCM generates a proactive sizing recommendation, modeling required throughput and suggesting target replacement platforms (e.g., upgrading from a PA-3250 to a PA-3420).
6. Predictive Maintenance & Proactive Automated Support
A major cause of enterprise downtime is silent component failure—such as a secondary power supply losing input voltage or an optical transceiver's laser signal fading until an optical link collapses.
Hardware Component Telemetry
AIOps continuously tracks physical telemetry parameters:
- Optical Transceiver (SFP/SFP+) Health: Monitors optical receive (Rx) and transmit (Tx) power levels (measured in dBm). If signal attenuation crosses degradation thresholds, AIOps alerts engineers to clean or replace the fiber link before bit errors trigger link flapping.
- Fan & Thermal Sensors: Monitors fan RPM deviations and internal ASIC temperatures, detecting cooling failures before thermal shutdown triggers.
- Storage Media Endurance: Tracks flash storage (eMMC/SSD) write endurance cycles and bad block reallocation counts, predicting storage exhaustion before disk corruption occurs.
Proactive TAC Case Integration (AIOps Premium)
When AIOps Premium identifies a critical hardware fault (e.g., redundant PSU failure) or matches a known PAN-OS software defect signature:
- SCM automatically generates a Palo Alto Networks TAC Support Case on behalf of the customer.
- The firewall automatically compiles and securely uploads a diagnostic Tech Support Bundle (TSB) and relevant telemetry logs directly to the case.
- The customer receives an email notification with the active TAC case number, preliminary root cause analysis, and instructions for Return Material Authorization (RMA) hardware dispatch—often before on-site network operations staff notice the issue.
7. Operational Diagnostics & CLI Verification Workflows
Security administrators can inspect AIOps telemetry streaming health, check local posture metrics, and verify support bundle generation directly from the PAN-OS CLI:
# Verify the operational status of the AIOps telemetry collector daemon
admin@PA-1410> show telemetry collector-status
AIOps Telemetry Service:
Collector Daemon: RUNNING (PID: 3412)
Cloud Telemetry Status: STREAMING (mTLS Established)
Ingested Metric Categories: Health, Capacity, Performance, SessionStats, BPA
Buffer Queue Length: 0 entries (Healthy)
Last Transmission: 2026-09-02 12:55:00 UTC (1.8 MB transmitted)
# Display real-time hardware health and optical transceiver telemetry
admin@PA-1410> show system state filter-like sfp
sys.sfp.ethernet1/1.present: True
sys.sfp.ethernet1/1.rx-power: -4.2 dBm (Normal Range: -10.0 to -2.0 dBm)
sys.sfp.ethernet1/1.tx-power: -3.8 dBm (Normal Range: -9.0 to -1.5 dBm)
sys.sfp.ethernet1/1.temp: 34.5 C (Normal Range: 0 to 70 C)
sys.sfp.ethernet1/1.status: OPTICAL_LINK_HEALTHY
# Display local session table capacity metrics
admin@PA-1410> show session info
Session Table Capacity:
Allocated Sessions: 48,912
Maximum Supported Sessions: 400,000
Session Table Utilization: 12.2%
Session Creation Rate: 340 sessions/sec
Throughput: 1.45 Gbps
8. Exam Traps & Architectural Distinctions
[!WARNING] EXAM TRAP 1: Free vs. Premium AIOps Feature Boundaries Exam questions frequently test which capabilities require the paid AIOps Premium subscription. Remember: Best Practice Assessment (BPA) checks, basic health monitoring, and standard Posture Scoring are included in the FREE (Standard) tier. However, Predictive Capacity Forecasting (runway analysis), ML-driven anomaly detection, root cause analysis (RCA), and automated proactive TAC case generation strictly require the AIOps PREMIUM tier. Do not assume all AI features require a paid add-on!
[!WARNING] EXAM TRAP 2: Strata Copilot Guardrails & Administrative Authority Can Strata Copilot automatically push configuration changes to production firewalls without human intervention? NO. SCM enforces strict guardrails: Copilot can analyze configs, generate change recommendations, and prepare candidate configuration deltas, but an authorized human administrator must explicitly review the Push Preview diff, initiate the Commit to SCM, and trigger the Push to Devices. Copilot does not possess autonomous write access to production data planes.
[!WARNING] EXAM TRAP 3: Posture Score vs. System Performance A common trap confuses the AIOps Posture Score with firewall throughput or hardware utilization. A firewall running at 95% CPU utilization during peak hours can still achieve a perfect Posture Score of 100 if all security best practices (App-ID, full threat inspection, SSL decryption, logging at session end, zone protection) are properly configured. The Posture Score measures security configuration hardening and hygiene, not hardware resource headroom!
An enterprise security operations team wants to identify all security policy rules that have not matched any active network traffic over the past 90 days across 150 firewalls, and receive recommendations on how to safely consolidate them. How can the team accomplish this most efficiently using Strata Cloud Manager?
Which capability is exclusively available in the AIOps for NGFW Premium tier and NOT included in the Free (Standard) tier?
An organization's SCM Posture Score dropped from 88 to 64 following a major network migration. Upon reviewing the AIOps dashboard, which finding would be the primary contributor to this reduction in Posture Score?