Outpost creation workflow ↗
License type: This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM product that has the Cloud Runtime Security add-on.
This page describes the overall flow for creating outposts for different CSPs.
Important: While outposts provide maximum control over the scanning environment, cloud scan mode is the recommended default for most organizations. For details, see When to choose outpost scan.
Creating an outpost comprises the following phases:
Phase 1: Planning
Determine if an outpost infrastructure meets your security needs.
Review Outpost fundamentals and planning to determine your outpost configuration.
Phase 2: Creating the outpost
Create your outpost running the outpost creation wizard in Cortex XSIAM to create an outpost authentication Terraform template. This template establishes trust with the CSP and grant the necessary permissions to Cortex XSIAM.
At this stage, the outpost is in Pending status.
Phase 3: Deploying the outpost
Deploy your outpost by executing a Terraform template in the CSP.
At this stage, the outpost is still in Pending status.
Phase 4: Onboarding the CSP
Run (or resume) the CSP onboarding wizard in Cortex to generate an authentication template for the relevant CSP.
Execute the authentication template in the CSP to onboard and ingest its data sources, using the outpost you created.
At this stage, the outpost is in Connected status.