How Elephant flow remediation works

Before you begin

  • Ensure that Cloud-Delivered Firewall Management Center is provisioned in your organization.

  • Ensure that AgenticOps is onboarded in your organization.

  • Ensure that High traffic caused by elephant flow is enabled under Insights & Reports > AgenticOps Insights > Settings > Capacity & Traffic Analysis. For more information, see Capacity and traffic insights.

  • Ensure that valid AgenticOps-generated elephant flow insights exist. Remediation cannot begin without a valid insight.

Procedure


Step 1

In the left pane, click Insights & Reports >Summary.

Step 2

On the AgenticOps Summary page, select the Traffic & Capacity insights category.

Step 3

In the High traffic caused by elephant flow section, select the affected device.

Step 4

Review the detected elephant flow insight details, affected resources, applications, and traffic impact information.

Step 5

Click Review proposed remediation to open the remediation workflow in Agent Workforce > Conversations.

  1. Alternatively, navigate to Insights & Reports > Agent Workforce > Conversations.

  2. Click New Conversation and select View elephant flow insights to start the remediation workflow.

Note

Manual prompt entry is not required to start the workflow.

Step 6

Review the proposed remediation actions, operational warnings, shared policy impact, and success criteria.

Step 7

Approve or cancel the remediation workflow as required.

Step 8

Deploy the generated policy updates to the affected devices.

Note

Elephant flow events displayed in the Unified Event Viewer might not be available to the remediation agent if AgenticOps did not generate a corresponding insight.