Skip to main content
Demo session – your progress won't be saved.Create Free Account
HAIEC
ConsoleD
Skip to monitoring content

Slice Map

What persisted evidence establishes about your network slices — activity observed, structure declared, and detector findings attached. This is an evidence view, not an isolation verdict.

Last updated: Not refreshed

What network slicing is

In 5G, a network slice is an isolated logical network running on shared physical infrastructure — an operator can dedicate one slice to emergency services, another to IoT sensors, another to consumer broadband. Each slice has its own RAN subnets, isolation policy, SLA thresholds, and resource quota. The security question is whether those boundaries actually hold: traffic appearing on a second slice, a device attaching outside its slice's RAN subnet, quota overruns, SLA breaches, cross-tenant access, or a modified isolation policy.

HAIEC checks this via rules SLICE-001…006 (detector AR-42…AR-46), fed by slice_flow and o1.pm intake markers. Hard locks apply: cross-slice traffic is not automatically an isolation breach, and an SLA breach is not an isolation failure — findings are review facts for you to adjudicate.

How this view was projected

  1. Ingested records land as evidence envelopes (status=active, structured_ingress) with caller-declared target ids, correlation keys, metric observations, and declared relations. Raw record bodies are hash-preserved, not queryable — this page can only show fields that survived normalization.
  2. The ingest sweep routes marked records into the slice detector, which persists findings into the detection-finding partition (status=detection_finding).
  3. This projection reads all tenant-scoped SLICE findings (no triage or evaluation filter drops them) and joins each finding back to its source record via the persisted ingest://nativeRecordId evidence reference.
  4. A slice is FINDING_PRESENT when a detector finding resolves to it, OBSERVED when activity was ingested, DECLARED_ONLY when it appears only in adapter-declared relations or topology snapshots. Nothing here is inferred from timing or naming.

No organization context

The slice map requires an active organization membership. Missing context does not establish that slice evidence is absent – only that it cannot be read here.