Skip to main content

Getting Started with Illumio Insights

Insights Agent Findings

Insights Agent Findings helps you accelerate threat detection in multi-cloud environments by summarizing the malicious threats, tactics, and techniques sourced from all the Insights pages that appear in left navigation.

To focus the page on specific information, you can:

  • Add, remove, and sort columns.

  • Rearrange columns by dragging and dropping.

  • Refine the list of summaries by showing or hiding any combination of column types, personas, attention level, tags, and generation types.

Reports Tab

The Reports tab displays a sortable, historical list of past investigation analyses. Selecting a report opens a slideout panel with the full results.

If the Agent Context tab lists context when an investigation runs (either automatically according to a preset schedule or triggered manually by the user), that context appears in the slideout under Agent Context Used. This preserves a record of what Insights Agent was instructed to ignore at the time the report was generated.

Slideout Panel

Clicking a report in the Reports tab opens a slideout panel on the right side of the page. The slideout presents rich detail about the selected report, including:

  • Overview: A summary of the investigation and its key outcomes.

  • Findings: The full list of findings identified during the investigation, with options to act on individual findings.

  • Recommended Actions: Suggested steps for addressing the findings and reducing risk.

  • Agent Context Used (described above).

If you click a second report while the slideout is already open, a new tab is added at the top of the slideout. Each additional report you select adds another tab, allowing you to review and compare multiple reports within a single slideout.

From the slideout you can also:

  • Click + to either launch a new investigation immediately or schedule a future investigation using the Calendar.

  • Click Assign Tags to attach metadata tags to the report, making it easier to organize and filter reports across your environment.

  • Add comments to the report to capture notes, share context with teammates, or document decisions made in response to the findings.

Agent Context Tab

The Agent Context feature lets you exclude expected behaviors or findings from Insights Agent analysis, such as known false positives, routine network activity, or items you have already reviewed and accepted. Providing this context helps ensure that subsequent investigation reports focus on only what matters to your organization.

The Agent Context tab lists user-added context that informs all Insights Agent investigations. All context in the tab remains available across investigations and is applied to each investigation, whether launched manually or triggered automatically by the Calendar. Context is only removed from the tab and investigations if you delete it.

The context applied to a completed investigation is preserved in the Agent Context Used section of that report's slideout, providing a full audit trail of what was in effect when the analysis ran.

Adding Agent Context

Caution

When adding context, either from a finding or as a custom entry, make sure you are confident the described behavior poses no security risk in your environment. Because context is applied to future investigations, an incorrect or overly broad entry could prevent the Insights Agent from surfacing genuine threats in subsequent reports.

You can add Agent Context in two ways:

Note

Both methods can be used independently or together.

Option 1: From the Findings Section of the Slideout

When reviewing findings in an investigation report, you can mark an individual finding directly as context for the next investigation.

  1. Click a finding in the Reports tab.

  2. In the slideout that opens, go to the Findings section and click the badge icon in the Action column.

    mark-for-context.png

    The context is queued in the Agent Context to inform the next investigation.

Option 2: In Your Own Words from the Agent Context Tab

You can enter custom context manually.

  1. Click Add in the Agent Context tab.

  2. In the slideout, enter your custom context in the Context Description field.

  3. Click Validate and Generate.

    If the Duplicate message appears, see Replacing Duplicate Context.

  4. Select the checkbox in the Agent Generated Context.

  5. Click Confirm and Add. The context is added to the Agent Context tab.

When writing context, follow these guidelines:

  • Review the cautionary note above.

  • Write naturally, as you would when prompting any AI assistant. The more specific and detailed your description, the more accurately the Insights Agent can apply it.

  • Your context must communicate the intent to exclude. Include a phrase such as "can be ignored," "you can ignore," "is considered safe," or "should not be included in findings for the next report." Without this signal, the Insights Agent may not interpret the entry as an exclusion instruction.

Replacing Duplicate Context

If the Insights Agent detects that newly added context duplicates or closely resembles context used in a previous investigation, a message appears providing an option to either replace the existing context with your new entry or retain the existing content.

  1. To substitute the earlier context with your new entry, click Replace.

  2. To discard the new entry and retain the existing context, click Cancel.