Configure elephant flow remediation workflow

This task enables you to configure and execute the Elephant flow remediation workflow to address high traffic issues caused by elephant flows through guided analysis and automated policy recommendations.

The Elephant flow agent provides an automated workflow to analyze traffic insights and recommend remediation actions. This process helps network administrators efficiently manage high-impact traffic flows that can affect network performance.

Before you begin

  • Ensure that Cloud-Delivered Firewall Management Center is provisioned in your organization.

  • Ensure that AgenticOps is onboarded in your organization.

  • Ensure that High traffic caused by elephant flow is enabled under Insights & Reports > AgenticOps Insights > Settings > Capacity & Traffic Analysis. For more information, see Capacity and traffic insights.

  • Ensure that valid AgenticOps-generated elephant flow insights exist. Remediation cannot begin without a valid insight.

Follow these steps to configure the Elephant flow remediation workflow:

Procedure


Step 1

In the left pane, click Insights & Reports >Summary.

Step 2

On the AgenticOps Summary page, select the Traffic & Capacity insights category.

Step 3

In the High traffic caused by elephant flow section, select the affected device.

Step 4

Review the detected elephant flow insight details, affected resources, applications, and traffic impact information.

Step 5

Click Review proposed remediation to open the remediation workflow in Agent Workforce > Conversations.

  1. Alternatively, navigate to Insights & Reports > Agent Workforce > Conversations.

  2. Click New Conversation and select View elephant flow insights to start the remediation workflow.

Note

Manual prompt entry is not required to start the workflow.

Step 6

Review the proposed remediation actions, operational warnings, shared policy impact, and success criteria.

Step 7

Approve or cancel the remediation workflow as required.

Step 8

Deploy the generated policy updates to the affected devices.

Note

Elephant flow events displayed in the Unified Event Viewer might not be available to the remediation agent if AgenticOps did not generate a corresponding insight.


The Elephant flow remediation workflow is configured and executed. Policy updates are deployed to the affected devices to address high traffic issues caused by elephant flows.