Sysdig Investigate

Investigate and prioritize vulnerable images in a Sysdig-monitored environment via two flows, routed from the user's goal. Plans flow — plan-driven prioritization: pick an admin-configured Plan (or explore ranked jobs under an ad-hoc scope and measure) and walk the prioritized remediation jobs one at a time. Findings flow — ad-hoc findings analysis: filter, regroup, sort, and page vulnerability findings the way the Vulnerability Management UI table does. Hands any chosen image off to /sysdig-remediate, which owns tickets, PRs, job tracking, and job closing. Triggers on: "investigate", "what should I fix", "what should I fix first", "show me my vulnerable images", "prioritize vulnerabilities", "which images are affected by CVE-...", "show me all Critical CVEs in production", "/sysdig-investigate". Not for opening PRs, applying fixes, or creating/updating tickets — use /sysdig-remediate for all of those.

sysdig Updated

File contents

sysdig/skills/tree/main/skills/sysdig-investigate commit 608626d094

Frequently asked questions

npx skillmds@latest add sysdig/sysdig-investigate