Cortex Toolbox Ingest Calculator Platform Changes
Detectors ▾
All detectors Statistics ATT&CK matrix
Analytics Alerts BIOCs Correlation Rules
Content ▾
Packs Integrations MCP Servers Threat Feeds Reputation Commands
Automation
Playbooks Scripts Jobs Automation Rules Lists
Case and Issue Setup
Incident Fields Layouts Layout Rules
Threat Intelligence
Indicator Types Indicator Fields Reputation Commands Threat Feeds
Data Ingestion
Parsing Rules Modeling Rules XDRC Templates
Dashboards & Reports
XSIAM Dashboards XSIAM Reports
Docs ▾
Documentation XDM Explorer Cortex Versions
Settings ▾
Sign in
View Cortex XSIAM Documentation as one page Lite view
  • Cortex XSIAM Documentation
    • Learn about Cortex XSIAM
      • Navigate the Cortex XSIAM docs
      • Get started with Cortex XSIAM
        • Cortex XSIAM architecture
      • Agentic AI in Cortex XSIAM
        • Agentic Assistant use cases
        • Compare Agentic Assistant with Cortex Assistant
        • Agentic Assistant security
      • Cortex XSIAM license tiers and product licenses
        • Data retention
        • Data storage lifecycle
        • License allocation
        • License expiration
        • Upgrade your tenant
      • In-product support ticket creation
      • Supported web browsers
      • Use the Cortex XSIAM interface
      • Manage API keys
    • Onboard Cortex XSIAM
      • How to onboard Cortex XSIAM
      • Plan and prepare
        • Plan your agent deployment
      • Deployment steps
        • Cortex XSIAM onboarding checklist
        • Activate Cortex XSIAM
          • Bring your own keys
          • Cortex XSIAM supported regions and data residency
          • Enable access to required PANW resources
            • Cortex XSIAM regional egress resources
            • Cortex XSIAM engine outbound IP addresses
            • Cortex XSIAM inbound source IP addresses
            • FedRAMP and US federal Cortex XSIAM required resources
        • Set up users, groups, and roles
          • Manage Cortex XSIAM user groups
          • Assign user roles and groups
        • Set up authentication
          • Authenticate users through the Customer Support Portal
          • Authenticate users using SSO
          • Set up Okta as the Identity Provider Using SAML 2.0
          • Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0
        • Configure content
        • Set up Cloud Identity Engine
        • Install Cortex XDR agents
          • Create an agent installation package
          • Deploy installation packages
          • Endpoint data collection
          • Configure global agent settings
          • Define endpoint groups
          • Manage endpoint profiles
          • Guidelines for keeping Cortex XDR agents and content updated
        • Cortex XSIAM - Analytics
          • Configure Cortex XSIAM network parameters
          • Enable the Analytics Engine and Identity Analytics
        • FedRAMP overview
          • Cortex XSIAM FedRAMP compliance for federal agencies
          • Onboard and configure government cloud environments
          • FedRAMP limitations and supported government cloud regions
      • Post-deployment
        • Cortex XSIAM post-deployment checklist
        • Perform health checks
          • Monitor agent operational status in Cortex XSIAM
        • Cortex Marketplace
          • Content packs
          • Install content packs
        • Manage user roles and access management
          • Manage user roles
          • Manage user access
            • User access reference information
          • Manage user scope
          • Manage access to objects
            • Manage access to custom dashboards
            • Manage access to report templates
            • Manage access to playbooks and scripts
            • Manage access to saved queries
        • Dashboards and reports
        • Configure server settings
        • Configure security settings
        • Data and log forwarding
          • Forward logs and data from Cortex XSIAM to external services
            • Configure external applications for forwarding
              • Forward notifications to Amazon SQS
              • Forward notifications to Amazon S3
              • Forward notifications to Splunk
              • Forward notifications to webhook
              • Integrate a syslog receiver
              • Integrate Slack for outbound notifications
            • Configure notification forwarding
            • Set up email notifications for tenant updates
            • Monitor administrative activity
          • Data and log notification formats
            • Management audit log messages
            • Cortex XSIAM issue notification format
            • Agent Audit log notification format
            • Management Audit log notification format
            • Log format for IOC and BIOC issues
            • Analytics log format
    • Configure Cortex XSIAM
      • Learn how to configure Cortex XSIAM
      • Data management
        • Optimize data management in Cortex XSIAM
        • Configure Cortex Data Lake tier
        • Broker VM
          • What is the Broker VM?
          • Set up and configure Broker VM
            • Broker VM image installations
              • Set up Broker VM on Alibaba Cloud
              • Set up Broker VM on Amazon Web Services
              • Set up Broker VM on Google Cloud Platform (GCP)
              • Set up Broker VM on KVM using Ubuntu
              • Set up Broker VM on Microsoft Azure
              • Set up Broker VM on Microsoft Hyper-V
              • Set up Broker VM on Nutanix Hypervisor
              • Set up Broker VM on VMware ESXi using vSphere Client
            • Broker VM data collector applets
          • Manage Broker VM
            • Edit Broker VM Configuration
            • Increase Broker VM storage allocated for data caching
            • Monitor Broker VM using Prometheus
            • Collect Broker VM Logs
            • Upgrade Broker VM
            • Update Broker VM applets independently
            • Import Broker VM Configuration
            • Open Live Terminal
            • Add Broker VM to cluster
            • Switchover Primary Node in Cluster
            • Remove from Cluster
          • Manage Broker VM data collector applets
          • Broker VM High Availability Cluster
            • Configure High Availability Cluster
            • Manage Broker VM clusters
              • View cluster details
              • Edit cluster
              • Add applet to cluster
              • Add Broker VM to cluster
              • Remove cluster
          • Broker VM notifications
          • Monitor Broker VM activity
          • Troubleshoot Broker VM applet errors
        • Dataset management
          • What are datasets?
          • Lookup datasets
            • Import a lookup dataset
            • Download JSON file of lookup dataset
            • Set time to live for lookup datasets
          • Monitor datasets and dataset views activity
        • Archived data
          • Import historical data into cold storage
          • Building XQL archived data queries
          • Success and failure code responses to your HTTP POST requests
        • Parsing Rules
          • Parsing Rules editor views
          • Parsing Rules file structure and syntax
            • INGEST
              • fields
              • parse_cef
              • parse_cisco
              • parse_json
            • COLLECT
            • CONST
            • RULE
            • EXTEND
          • Create Parsing Rules
          • Troubleshooting Parsing rules errors
          • Parsing Rules Raw Dataset
        • Data Model Rules
          • Data Model Rules editor views
          • Data Model Rules file structure and syntax
            • MODEL
            • RULE
            • Field structure
          • How to map authentication events for analytics
          • Generate data model rules with AI (preview)
          • Create Data Model Rules
          • Troubleshooting Data Model Rules
          • Using data enrichment
          • Data Model Rules notifications
          • Monitor Data Model Rules activity
        • Manage Event Forwarding
          • Endpoints Event Forwarding - included/excluded fields by event type
        • Manage compute units
          • Compute units usage
      • Cortex XSIAM Data Sources and Connectors
        • What are Cortex XSIAM data sources and connectors?
        • What is the data source and connector catalog?
        • Vendor-specific data sources and connectors
          • 1Password
            • 1Password
          • Abnormal Security
            • Abnormal Security
          • Absolute
            • Absolute
          • abuse.ch
            • abuse.ch
          • AbuseIPDB
            • AbuseIPDB
          • Accenture
            • Accenture
          • AdminByRequest
            • AdminByRequest
          • Aha
            • Aha!
            • Aha
          • AIOps
            • AIOps
          • Akamai
            • Akamai
          • AlgoSec
            • AlgoSec
          • Alibaba Cloud
            • Alibaba Cloud
          • AlienVault
            • AlienVault
          • Amazon
            • Amazon Cloud Watch
              • Ingest logs from Amazon CloudWatch
            • Amazon S3
              • Ingest audit logs from AWS CloudTrail
              • Ingest network flow logs from Amazon S3
              • Ingest generic logs from Amazon S3
              • Ingest network Route 53 logs from Amazon S3
              • Create an assumed role
              • Configure data collection from Amazon S3 manually
            • Amazon Web Services
            • AWS Automation and Collection
          • Anomali
            • Anomali
          • Anthropic
            • Claude Automation and Collection
            • Claude
          • Apache
            • Apache
          • API Security
            • Ingest data for API security
              • Ingest AWS API Gateway
              • Ingest Azure APIM
              • Ingest Apigee Proxy
              • Ingest Kong
              • Ingest F5
          • APIVoid
            • APIVoid
          • Apollo.io
            • Apollo.io
          • AppSentinels
            • AppSentinels
          • ArcSight
            • ArcSight
          • Arista Networks
            • Arista Networks
          • Arkime
            • Arkime
          • Armis
            • Armis
          • Articulate Global
            • Articulate Global
          • Asana
            • Asana
          • Atlassian
            • Atlassian
            • Atlassian Automation and Collection
          • AttackIQ
            • AttackIQ
          • Aurora Endpoint Security
            • Aurora Endpoint Security
          • Automox
            • Automox
          • BeyondTrust
            • BeyondTrust Privilege Management Cloud
              • Ingest logs from BeyondTrust Privilege Management Cloud
            • BeyondTrust
          • BitSight
            • BitSight
          • bitwarden
            • bitwarden
          • Blocklist.de
            • Blocklist.de
          • BloodHound Enterprise
            • BloodHound Enterprise
          • BlueCat Address Manager
            • BlueCat Address Manager
          • BMC
            • BMC
          • Box
            • Ingest logs and data from Box
            • Box Automation and Collection
            • Box
          • Broadcom
            • Broadcom
          • BruteForceBlocker
            • BruteForceBlocker
          • Businessmap
            • Businessmap
          • C2SEC
            • C2SEC
          • CAPESandbox
            • CAPESandbox
          • Carbon Black
            • Carbon Black
          • Celonis
            • Celonis Collection
            • Celonis
          • Centreon
            • Centreon
          • ChatGPT Enterprise
            • ChatGPT Enterprise
          • Check Point
            • Check Point FW1/VPN1
            • Checkpoint Firewall
          • CheckPhish
            • CheckPhish
          • CipherTrust
            • CipherTrust
          • CIRCL
            • CIRCL
          • CircleCI
            • CircleCI
          • Cisco
            • Cisco ASA firewalls and AnyConnect
            • Cisco ASA
            • Cisco Duo
            • Cisco DUO Automation and Collection
            • Cisco Firepower
            • Cisco ISE
            • Cisco Meraki
            • Cisco Meraki Automation and Remediation
            • Cisco Security
            • Cisco Umbrella
          • Citrix
            • Citrix
          • ClickUp
            • ClickUp
          • Cloaken
            • Cloaken
          • CloudConvert
            • CloudConvert
          • Cloudflare
            • Cloudflare
          • Code42
            • Code42
          • Cohesity
            • Cohesity
          • Contentful
            • Contentful
          • Corelight
            • Corelight Zeek
          • Couchbase
            • Couchbase
          • CounterTack
            • CounterTack
          • Coveo
            • Coveo
          • Cribl
            • Ingest data from Cribl
              • Disable or delete Cribl integration
              • Data souce UUIDs
              • Collect Windows Event Logs for Cortex XSIAM via Cribl
            • Cribl connector
          • CrowdStrike
            • Crowdstrike APIs
              • Ingest alerts and metadata from Crowdstrike APIs
            • CrowdStrike Falcon Data Replicator
              • Ingest raw EDR events from CrowdStrike Falcon Data Replicator
            • CrowdStrike
          • CryptoCurrency
            • CryptoCurrency
          • Cuckoo Sandbox
            • Cuckoo Sandbox
          • Cursor
            • Cursor
          • CybelAngel
            • CybelAngel
          • CyberArk
            • CyberArk
          • Cyber Triage
            • Cyber Triage
          • CYFIRMA
            • CYFIRMA
          • Darktrace
            • Darktrace
          • Databricks
            • How to onboard Databricks
            • Databricks
          • DataDog
            • DataDog
          • DeHashed
            • DeHashed
          • DHS
            • DHS
          • digicert
            • digicert
          • dnstwist
            • dnstwist
          • Docker
            • Connect Docker Hub registry
              • Manage a Docker Hub connector
            • Connect Docker V2 compliant container registry
              • Manage a Docker V2 connector
          • DocuSign
            • DocuSign
          • Dropbox
            • Ingest logs and data from Dropbox
            • Dropbox
          • Druva
            • Druva
          • EasyVista
            • EasyVista
          • Email Hippo
            • Email Hippo
          • Elastic
            • Elasticsearch Filebeat
              • Ingest logs from Elasticsearch Filebeat
            • Windows DHCP via Elasticsearch Filebeat
              • Ingest logs from Windows DHCP using Elasticsearch Filebeat
            • ElasticSearch
          • Endgame
            • Endgame
          • Envoy
            • Envoy
          • Exabeam
            • Exabeam
          • ExtraHop
            • ExtraHop
          • F5
            • F5 Automation and Remediation
          • Fastly
            • Fastly
          • Fidelis
            • Fidelis
          • Filigran
            • Filigran OpenCTI
          • Forcepoint
            • Forcepoint DLP
            • Forcepoint
          • ForeScout
            • ForeScout
          • Fortinet
            • Fortinet Fortigate
              • Fortinet FortiGate connector
            • Fortinet
            • Fortinet FortiWeb VM
          • Fortra
            • Fortra
          • FraudWatch
            • FraudWatch
          • Freshworks
            • Freshworks
          • Gainsight
            • Gainsight
          • Gamma.AI
            • Gamma.AI
          • Gemini Enterprise
            • Gemini Enterprise
          • Genetec
            • Genetec Security Center
          • Generic
            • Generic Intel Feed
            • Generic API Event Collector
            • Generic MCP
            • Generic SQL
          • Genesys
            • Genesys
          • Gigamon
            • Gigamon
          • GitGuardian
            • GitGuardian
          • GitHub
            • GitHub
          • GitLab
            • Connect GitLab container registry
              • Manage a GitLab Container Registry connector
            • GitLab Automation and Collection
            • GitLab
          • Giphy
            • Giphy
          • Google
            • Google AI
            • Google Cloud
            • Google Cloud Platform
              • Ingest logs and data from a GCP Pub/Sub
            • Google Kubernetes Engine
              • Ingest logs from Google Kubernetes Engine
            • Google SecOps
            • Google Services
            • Google Workspace
              • Ingest logs and data from Google Workspace
              • Google Workspace connector
              • Google Workspace Automation and Collection
          • GraphQL
            • GraphQL
          • Grouped Example Connector
            • Grouped Example Connector
          • GRR
            • GRR
          • Grafana
            • Grafana
          • Halcyon
            • Halcyon
          • Harbor
            • Connect Harbor registry
              • Manage a Harbor connector
          • Harness
            • Harness
          • HashiCorp
            • HashiCorp
          • Have I Been Pwnd
            • Have I Been Pwnd
          • HCL BigFix
            • HCL BigFix
          • HPE Aruba
            • HPE Aruba
          • Hostio Solutions
            • Hostio Solutions
          • HTTP log collector
            • Set up an HTTP log collector to receive logs
          • IBM
            • IBM Storage Scale
            • IBM QRadar
            • IBM Security
          • iManage
            • iManage
          • Imperva
            • Imperva
          • InfoArmor
            • InfoArmor
          • Infoblox
            • Infoblox
          • Intellum
            • Intellum
          • Intercom
            • Intercom
          • IPInfo.io
            • IPInfo.io
          • IPstack
            • IPstack
          • Ironscales
            • Ironscales
          • Ivanti
            • Ivanti
          • iZOOlogic
            • iZOOlogic
          • Jamf
            • Jamf
            • Jamf Pro
          • JFrog
            • Connect JFrog container registry
              • Manage a JFrog connector
          • Joe Security
            • Joe Security
          • JumpCloud
            • JumpCloud
          • JSONWhoIs.com
            • JSONWhoIs.com
          • Kafka
            • Kafka
          • Kaspersky
            • Kaspersky
          • Keeper Security
            • Keeper Security
          • KnowBe4
            • KnowB4
          • Koi
            • Koi
          • Koodous
            • Koodous
          • Kubernetes
            • Onboard the Kubernetes connector
            • What's new in Kubernetes connector
            • Supported Kubernetes distributions
          • Kustomer
            • Kustomer
          • LastPass
            • LastPass
          • Lastline
            • Lastline
          • LevelBlue
            • LevelBlue
          • LogRhythm
            • LogRhythm
          • LOLBAS
            • LOLBAS
          • Lookout
            • Lookout
          • Lumu
            • Lumu
          • Mail Utilities
            • Mail Utilities
          • Majestic
            • Majestic
          • ManageEngine
            • ManageEngine
          • Mattermost
            • Mattermost
          • MaxMind
            • MaxMind
          • Menlo Security
            • Menlo Security
          • Meta
            • Meta
          • Mimecast
            • Mimecast
          • Microsoft
            • Azure DevOps
            • Azure Event Hub
              • Ingest logs from Microsoft Azure Event Hub
            • Azure Firewall
            • Azure Network Watcher
              • Ingest network flow logs from Microsoft Azure Network Watcher
            • Microsoft Azure
            • Microsoft Copilot Studio
            • Microsoft Defender for Endpoint Events
              • Ingest raw EDR events from Microsoft Defender for Endpoint
            • Microsoft Entra ID
            • Microsoft Office 365
              • Ingest logs from Microsoft Office 365
              • Microsoft 365 (new)
                • Create a Microsoft Entra ID
              • Microsoft365 (legacy)
                • Migrate to new Microsoft 365 connector
              • Microsoft 365 Copilot
              • Microsoft Graph
            • Microsoft Office 365 (email)
              • Ingest logs and data from Microsoft 365
            • Microsoft 365 (Posture)
              • How to onboard Microsoft 365
            • Microsoft Teams
            • Azure Log Analytics
            • Azure Services
            • Azure WAF
            • Microsoft Active Directory
            • Microsoft Identity
            • Microsoft Intune
            • Microsoft Security Automation and Collection
            • Microsoft Windows Tools
            • M365 Automation and Collection
          • MISP
            • MISP
          • MITRE
            • MITRE
          • Monday
            • Monday
            • Monday.com
          • MongoDB
            • How to onboard MongoDB Atlas (Posture)
            • MongoDB
            • MongoDB Atlas
          • MuleSoft
            • MuleSoft
          • Mural
            • Mural
          • MxToolBox
            • MxToolBox
          • NetBox
            • NetBox
          • Netcraft
            • Netcraft
          • Netmiko
            • Netmiko
          • NetQuest
            • NetQuest
          • Netskope
            • Netskope
          • Nintex Workflow Cloud
            • Nintex Workflow Cloud
          • NIST
            • NIST
          • nmap
            • nmap
          • NAVEX
            • NAVEX
          • Nutanix
            • Nutanix
          • Okta
            • Ingest logs and data from Okta
            • Okta Automation and Collection
            • Okta connector
          • OneLogin
            • Ingest logs and data from OneLogin
            • OneLogin
          • OpenAI
            • OpenAI
          • OpenCVE
            • OpenCVE
          • OpenLDAP
            • OpenLDAP
          • OpenPhish
            • OpenPhish
          • OpenText
            • OpenText EnCase Endpoint Security
            • OpenText Service Manager
            • OpenText Vertica
          • OPSWAT
            • OPSWAT MetaDefender
          • Oracle
            • Oracle Cloud Infrastructure
            • Oracle
          • Orca Security
            • Orca Security
          • PacketMail.net
            • PacketMail.net
          • PacketSled
            • PacketSled
          • PagerDuty
            • PagerDuty Automation and Collection
            • PagerDuty
          • PAT Helpdesk Advanced
            • PAT Helpdesk Advanced
          • PhishLabs
            • PhishLabs
          • Ping Identity
            • PingFederate
            • PingOne
              • Ingest authentication logs and data from PingOne
              • Ping Identity
          • Pipedrive
            • Pipedrive
          • Pipl
            • Pipl
          • Plainview
            • Plainview
          • Proofpoint
            • Proofpoint Targeted Attack Protection
              • Ingest logs from Proofpoint Targeted Attack Protection
            • Proofpoint
          • ProtectWise
            • ProtectWise
          • Qualtrics
            • Qualtrics
          • Qualys
            • Qualys
          • Quest KACE
            • Quest KACE
          • Radware
            • Radware
          • Rapid7
            • Rapid7
          • Razor Group
            • Razor Group
          • Recorded Future
            • Recorded Future
          • Red Hat
            • Red Hat Ansible
          • Redis Labs
            • Redis Labs
          • Redmine
            • Redmine
          • ReliaQuest
            • ReliaQuest
          • RemoteAccess
            • RemoteAccess
          • Retarus
            • Retarus
          • RSA
            • RSA
          • RTIR
            • RTIR
          • runZero
            • runZero
          • Salesforce
            • Ingest logs and data from Salesforce
            • Salesforce connector
          • SailPoint
            • SailPoint
          • Samhaus
            • Samhaus
          • SANS DShield
            • SANS DShield
          • SAP
            • SAP
            • SAP Ariba
          • Saviynt
            • Saviynt
          • SecurityScorecard
            • SecurityScorecard
          • Securonix
            • Securonix
          • Sentry
            • Sentry
          • SentinelOne
            • SentinelOne DeepVisibility
              • Ingest raw EDR events from SentinelOne DeepVisibility
            • SentinelOne
          • ServiceNow
            • ServiceNow CDMB
              • Ingest data from ServiceNow CMDB
            • ServiceNow Automation and Collection
            • ServiceNow
          • Shopify
            • Shopify
          • Shodan
            • Shodan
          • Skyhigh Security
            • Skyhigh Security
          • Slack
            • Slack Automation and Collection
            • Slack Enterprise
          • SMB
            • SMB
          • SMIME Messaging
            • SMIME Messaging
          • Snowflake
            • How to onboard Snowflake
            • Snowflake Automation and Collection
          • SolarWinds
            • SolarWinds
          • Sonatype Nexus
            • Connect Sonatype Nexus registry
              • Manage a Sonatype connector
          • Sophos
            • Sophos
          • Splunk
            • Splunk Automation and Collection
            • Splunk
          • Sublime Security
            • Sublime Security
          • Sumo Logic
            • Sumo Logic Automation and Collection
            • Sumo Logic
          • SysAid
            • SysAid
          • Syslog Sender
            • Syslog Sender
          • Tanium
            • Tanium
          • TAXII
            • TAXII
          • TeamViewer
            • TeamViewer
          • Telegram
            • Telegram
          • Tenable
            • Tenable
          • Terraform
            • Terraform
          • Thales
            • Thales
          • TheHive
            • TheHive
          • Thinkst Canary
            • Thinkst Canary
          • ThreatConnect
            • ThreatConnect
          • ThreatMiner.org
            • ThreatMiner.org
          • ThreatX
            • ThreatX
          • Tidy
            • Tidy
          • TOPdesk
            • TOPdesk
          • Tor Exit Adress
            • Tor Exit Adress
          • Trellix
            • Trellix Database Security
            • Trellix Email Security (ETP)
            • Trellix Email Security
            • Trellix Endpoint (HX)
            • Trellix ePO
            • Trellix Network
            • Trellix Sandbox
            • Trellix SIEM
            • Trellix Threat Intel
          • TrendAI
            • TrendAI
          • Twilio
            • Twilio
          • Uptycs
            • Uptycs
          • Vectra
            • Vectra
          • Versa Networks
            • Versa Networks
          • VMware
            • VMware Automation and Collection
            • VMWare
          • VulnDB
            • VulnDB
          • WhatsMyBrowser.org
            • WhatsMyBrowser.org
          • Whois
            • Whois
          • WithSecure
            • WithSecure
          • Workday
            • Ingest report data from Workday
            • Workday Automation and Collection
            • Workday
          • X
            • X Automation and Remediation
          • YouTrack
            • YouTrack
          • Zendesk
            • Zendesk
          • Zero Networks
            • Zero Networks
          • Zimperium
            • Zimperium
          • Zoom
            • Zoom
          • Zscaler
            • Zscaler Internet Access
            • Zscaler Private Access
            • Zscaler
        • Connectors
        • Standard data sources
        • Cloud service provider (CSP) onboarding
          • Understand CSP onboarding tiers and licensing
          • Amazon Web Services cloud onboarding
            • AWS security capabilities and deployment planning
            • AWS resource inventory
            • AWS security model and authentication
            • Cortex XSIAM and AWS audit log collection architecture
            • Onboard Amazon Web Services
            • Prerequisites for onboarding AWS
            • How to onboard Amazon Web Services
            • Deploy the authentication template in AWS
            • Post-deployment: Custom (BYOB) and Control Tower audit log collection
            • Grant cross-account KMS key access for Control Tower BYOB log collection
            • AWS post-deployment verification
          • Microsoft Azure cloud onboarding
            • Onboard Microsoft Azure
            • Prerequisites for onboarding Azure
            • How to onboard Microsoft Azure
            • Finalize Microsoft Azure onboarding by executing the authentication template
            • Microsoft Azure offboarding overview
              • Offboard Terraform-based Azure deployments (all scopes)
              • Offboard Azure subscription (ARM)
              • Offboard Azure management group or tenant scope (ARM)
              • Offboard Azure tenant with Entra ID only
          • Google Cloud Platform onboarding
            • Onboard Google Cloud Platform
            • Prerequisites for onboarding GCP
            • How to onboard Google Cloud Platform
            • How to onboard GCP with foundational configuration
            • Deploy the Terraform authentication template in GCP
            • Connect Google Workspace with your GCP cloud instance
            • Monitor GCP resources inside service perimeters
          • Oracle Cloud Infrastructure cloud onboarding
            • Onboard Oracle Cloud Infrastructure
            • Prerequisites for onboarding OCI
            • How to onboard Oracle Cloud Infrastructure
            • How to onboard Oracle Cloud Infrastructure with foundational configuration
            • Deploy the Terraform authentication template in OCI
          • Alibaba Cloud cloud onboarding
            • Alibaba security capabilities and deployment planning
            • Alibaba Cloud resource inventory
            • Alibaba Cloud security model and authentication
            • Onboard Alibaba Cloud
            • Prerequisites for onboarding Alibaba Cloud
            • How to onboard Alibaba Cloud
            • Alibaba Cloud post-deployment verification
          • Outpost onboarding
            • Outpost fundamentals and planning
            • Outpost creation workflow
            • Working with standard outposts
              • Create a standard outpost
            • Working with Bringing your own Azure app (BYOA) outposts
              • Task 1: Meet the prerequisites for Azure BYOA outposts
              • Task 2: Create the app registration for the Azure BYOA outpost
              • Task 3: Deploy the Azure BYOA outpost
              • Task 4: Verify the BYOA outpost deployment
              • The shell script for Azure app registration
            • Outpost troubleshooting
            • Outpost Cloud Service Provider (CSP) permissions
              • Amazon Web Services (AWS) outpost permissions
              • Microsoft Azure outpost permissions
              • Google Cloud Platform (GCP) outpost permissions
          • Introduction to Terraform for Cloud service provider (CSP) onboarding
          • Manually connect a cloud instance
          • Manage cloud instances
          • Pending cloud instances
          • Edit your onboarded CSP configuration
          • Update cloud permissions after Cortex XSIAM release updates
          • Troubleshoot errors on cloud instances
          • Cloud service provider permissions
            • Amazon Web Services (AWS) provider permissions
            • Microsoft Azure provider permissions
            • Google Cloud Platform (GCP) provider permissions
            • Oracle Cloud Infrastructure (OCI) provider permissions
        • Generic on-premise data collectors
          • Broker VM data collector applets
            • Activate Apache Kafka Collector
            • Activate Cortex Network Scanner
            • Activate CSV Collector
            • Activate Database Collector
            • Activate DSPM Database
            • Activate DSPM Fileshare
            • Activate Files and Folders Collector
            • Activate FTP Collector
            • Activate Local Agent Settings
            • Activate NetFlow Collector
            • Activate Network Mapper
            • Activate Registry Scanner
            • Syslog Collector applet
              • Activate Syslog Collector
              • Ingest logs from a Syslog receiver
              • Check Point FW1 VPN1
                • Ingest logs from Check Point firewalls
              • Cisco ASA firewalls and AnyConnect
                • Ingest logs from Cisco ASA firewalls and AnyConnect
              • Corelight Zeek
                • Ingest logs from Corelight Zeek
              • Forcepoint DLP
                • Ingest logs from Forcepoint DLP
              • Fortinet Fortigate
                • Ingest logs from Fortinet Fortigate firewalls
              • Next Generation Firewall
                • Ingest Next-Generation Firewall logs using the Syslog Collector
              • PingFederate
                • Ingest authentication logs from PingFederate
              • Zscaler Internet Access
                • Ingest logs from Zscaler Internet Access
              • Zscaler Private Access
                • Ingest logs from Zscaler Private Access
            • Activate Transporter
            • Activate Windows Event Collector
              • Activate Windows Event Collector on Windows Core
              • Renew WEC certificates
          • XDR Collectors
            • XDR Collector audit logs
            • XDR Collector machine requirements and supported operating systems
            • Resources required to enable access to XDR collectors
            • Manage XDR Collectors
              • XDR Collectors installation resource for Windows and Linux
              • Create an XDR Collector installation package
              • Install the XDR Collector installation package for Windows
                • Install the XDR collector on Windows using the MSI
                • Install the XDR Collector on Windows using Msiexec
              • Install the XDR Collector installation package for Linux
              • Configure XDR Collector upgrade scheduler
              • Set an application proxy for XDR Collectors
              • Set an alias for an XDR Collector machine
              • Upgrade XDR Collectors
              • Uninstall the XDR Collector
              • Define XDR Collector machine groups
              • About Cortex XDR Collector content updates
            • XDR Collector profiles
              • Add an XDR Collector profile for Windows
                • How to configure XDR Collector profiles
                • Additional XDR Collector profile management options
                • Query Windows Event Log records
              • Ingest logs from Windows DHCP using Elasticsearch Filebeat
              • Ingest Windows DNS debug logs using Elasticsearch Filebeat
              • Add an XDR Collector profile for Linux
            • Apply profiles to collection machine policies
            • XDR Collector datasets
        • Palo Alto Networks integrations
          • Cloud Next-Generation Firewall
            • Ingest data from Cloud Next-Generation Firewall
          • Next-Generation Firewall
            • Ingest data from Next-Generation Firewall
            • Ingest Next-Generation Firewall logs using the Syslog collector
            • Panorama
          • Prisma Access
            • Ingest data from Prisma Access
            • Palo Alto Networks Prisma
          • Prisma Access Browser
            • Ingest logs from Prisma Access Browser
          • Ingest detection data from Strata Logging Service
          • IoT Security
            • Ingest alerts and assets from IoT Security (Deprecated)
            • Ingest alerts and assets from Device Security
            • IoT Security
          • Cortex Attack Surface Management
          • Cortex Automation Developer Tools
          • Cortex Data Lake
          • Cortex Internals
          • Cortex XDR
          • Enterprise DLP
          • Palo Alto Networks Cortex
          • PAN PSIRT Advisories
          • Prisma Cloud Compute
          • Prisma Cloud CSPM
          • SaaS Security (Aperture)
          • Threat Vault
          • WildFire Cloud
          • Log type filtering
          • Collecting URL and File log types
            • Detectors connected to URL and File log types
        • Cloud Posture and Runtime Security data sources
          • Activate AppSec Transporter
          • Container Registries
            • Registry Components
            • How Container Registry Scanning Works
            • Configure registry scanning for cloud accounts
            • Modify the container registry scanning scope
            • Scan re-evaluation process
        • External alerts using External Issue Mapping
          • Ingest external alerts
        • Administration and troubleshooting
          • Manage instances
            • Add a new data source or instance
            • How to configure the scanning settings for supported services
            • Manage cloud instances
            • Update cloud permissions after Cortex release updates
            • Pending cloud instances
            • Troubleshoot errors on cloud instances
            • Manage Kubernetes Connector instances
          • Integrations
            • Integration use cases
            • Add an integration instance
            • Configure integration permissions
            • Fetch issues from an integration instance
              • Map fields to issue types
              • Classify events using a classifier for issue types
            • Manage credentials
            • Troubleshoot Integrations
            • Forward Requests to Long-Running Integrations
          • Verify collector connectivity
          • Overview of data ingestion metrics
            • Creating correlation rules to monitor data ingestion health
            • Measuring data freshness
          • Health issues in Cortex XSIAM
            • Investigate and resolve health issues
            • Monitor data ingestion health (BETA)
            • Monitor Correlation rules
      • Marketplace
        • Cortex Marketplace
        • Content packs
        • Content Pack Support Types
        • Manage content packs
        • Marketplace FAQs
        • Content changes when upgrading Cortex XSIAM versions
        • Content pack contributions
      • Configure the Cortex Agentic Assistant
        • Agentic Assistant components and concepts
        • Agentic Assistant Hub
          • Manage actions
          • Register actions
          • Manage agents
          • Build agents
          • Manage knowledge sources (preview)
          • Expand agent capabilities with MCP integrations
        • Agentic Assistant role-based access control
      • Cortex MCP server
        • Install the Cortex MCP server
        • Configure the MCP client
        • Use the Cortex MCP server
        • Create custom Cortex MCP server tools
      • Automations
        • Automation in Cortex XSIAM
        • Quick Actions
        • Automation Exclusion Center
          • Manage automation exclusion policies
        • Playbooks
          • Playbooks overview
          • Access to playbooks
          • Playbook development checkli
          • Plan your playbook
          • Manage playbooks
          • Build your playbook
            • Choose from existing playbooks or create your own
            • Configure playbook settings
            • Add objects from the Task Library
              • Add commands and scripts
              • Add sub-playbooks
              • Add AI Prompt tasks
              • Add manual tasks and blank tasks
                • Create a standard task
                • Create a conditional task
                • Create a communication task
              • Create a section header
              • Configure script error handling in a playbook
            • Customize your playbook
              • Configure a sub-playbook loop
              • Filter and transform Cortex XSIAM playbook data
              • Create custom filters and transformers
              • Filter considerations, categories, and built-in filters
              • Transformer considerations, categories, and built-in transformers
              • Extend context in playbooks
              • Extract indicators in playbooks
              • Update issue fields with playbook tasks
            • Test your playbook
              • Troubleshoot playbook performance
            • Manage playbook content
          • Accelerate playbook development using the Automation Engineer agent (preview)
            • Automation Engineer prompt examples
          • Best practices for playbooks
        • Autonomous playbooks
          • Enable autonomous playbooks
          • Manage autonomous playbooks
          • Manage autonomous automation rules
          • Work Plan for autonomous playbooks
        • AI Prompts
          • AI prompts role-based access control
          • Use existing prompts
          • Create a prompt
          • Write effective prompts
        • Agentic Response (Preview)
        • Create an automation rule
        • Scripts
          • Access to scripts
          • Use existing scripts
          • Create a script
          • Accelerate script development using the Automation Engineer agent
          • Change the Docker image in an integration or script
        • Context data
          • Issue context data
          • Case context data
          • Search context data
          • Add context data to an issue
          • Add context data to a case
          • Delete context data from a case
          • Use context data in a playbook
        • Lists
          • Create a list
          • List commands
          • Use cases: JSON lists
            • Extract data from a JSON object
            • Extract a subset of the data
            • Filter extracted data
          • Transform a list into an array
        • Jobs
          • Access to Jobs
          • Manage jobs
          • Create a time-triggered job
          • Create a job triggered by a delta in a feed
      • Engines
        • What is an engine?
        • Engine requirements
        • Install an engine
          • Docker
            • Install Docker
            • Install Docker distribution for Red Hat
            • Docker image security
            • Docker FAQs
            • Troubleshoot Docker Issues
            • Configure Docker pull rate limit
            • Change the Docker Installation folder
            • Docker hardening guide
              • Docker network hardening
              • Configure Docker images
              • Run Docker with non-root internal users
              • Configure the memory limit support without swap capabilities
              • Configure the memory limitation
              • Configure the CPU, PIDs, and open the file descriptors limit
              • Check Docker hardening configurations
          • Podman
            • Change the Container storage
            • Install Podman
            • Migrate from Docker to Podman
            • Troubleshoot Podman
        • Manage engines
        • Upgrade an engine
        • Remove an engine
        • Configure engines
          • Configure the engine to use a web proxy
          • Configure the engine to call the server without using a proxy
          • Use NGINX as a reverse proxy
          • Configure an engine to use custom certificates
        • Use an engine in an integration
        • Run a script using an engine
        • Troubleshoot engines
        • Troubleshoot integrations running on engines
      • Remote repository management
        • Cortex XSIAM development tenant
        • Set up a remote repository
          • Set up a built-in remote repository
          • Set up a Private Remote Repository
        • Push and pull content
        • Remote repository troubleshooting
      • Customize cases and issues
        • External integrations
        • Set up case scoring
        • Create a starring configuration
        • Create custom case statuses and resolution reasons
        • Create a sync profile
        • Create a case domain
        • Customize case fields and layouts
          • Case fields
            • Case field types
            • Create custom case fields
            • Create a grid field for a case
            • Update case fields
          • Case layouts
            • Create custom layouts
            • Create rules for case layouts
        • Customize issue fields and layouts
          • Manage Cortex XSIAM issue fields
            • Issue field types
            • Create custom issue fields
            • Create a grid field for an issue
            • Configure issue timer fields
            • Issue field-triggered scripts
            • Configure issue timer fields
            • Configure a playbook to run timers
            • Automate changes to issue fields using timer scripts
            • Use issue timer field commands in the CLI
          • Issue layouts
            • Create custom issue layouts
            • Add a custom widget to an issue layout
            • Create issue layout rules
        • Create SLAs for case and issue resolution
          • Create additional case timers and SLAs
            • Update case timer and SLA fields
        • Create issue exceptions
          • Configure the issue exception approval workflow
          • Create issue exception rules
          • Create an exception rule from an issue
          • View issue exception rules
          • Disable issue exception rules
          • View excepted issues
        • Optimize case grouping in correlations
        • Run indicator extraction in the CLI
      • XQL query management
      • Multi-Tenant
        • What is Cortex XSIAM multi-tenant?
          • MSSP multi-tenant
          • Enterprise multi-tenant
        • Multi-tenant central licensing management
        • Onboard Cortex multi-tenant
          • Onboarding checklist for multi-tenant central licensing deployments
            • Step 1. Activate Cortex XSIAM (main account)
            • Create a child tenant
          • Onboarding checklist for multi-tenant customer-owned license deployments
            • Step 1. Active Cortex XSIAM (parent and child tenants)
            • Step 2. Define access configuations and role permissions
            • Step 3. Pair a parent tenant with a child tenant
        • Dynamic license allocation
        • Child tenant management
          • Track your tenant management
          • Investigate child tenant data
          • Create and allocate configurations
          • Create a security managed action
        • About managed threat hunting
          • Set up Managed Threat Hunting
          • Investigate Managed Threat Hunting reports
      • Managed Services configuration in Cortex
        • Managed Services configuration
        • Configure report forwarding
        • Configure actions permissions
        • Manage escalation contacts
    • Protect your endpoints
      • Endpoint security
        • Endpoint protection
          • Malware protection
          • Exploit protection
          • File analysis and protection flow
          • Endpoint protection capabilities
          • Processes protected by exploit security policy
          • File Integrity Monitoring (FIM)
          • CaaS Workloads
          • WildFire analysis concepts
          • Guidelines for keeping Cortex XDR agents and content updated
          • About content updates
          • Endpoint data collection
        • Install and manage endpoints
          • Set up endpoint protection
            • Set up endpoint profiles and exception rules
              • Set up malware prevention profiles
              • Set up exploit prevention profiles
              • Set up agent settings profiles
              • Set up restrictions prevention profiles
              • Set up exception profiles and rules
                • Exception configuration
                • Issue exclusions
                  • Add an issue exclusion rule
                • Add an IOC or BIOC rule exception
                • Add a disable prevention rule for endpoints
                • Add a disable injection and prevention rule
                • Add a support exception rule for endpoints
                • Add a legacy exception rule for endpoints
                  • Add a new exceptions security profile
                  • Add a global endpoint policy exception
              • Set up Identity profiles
          • Define endpoint groups
          • Configure global agent settings
          • Apply profiles to endpoints
          • Create an agent installation package
            • Manage an agent installation package
          • Harden endpoint security
            • Device control
            • Host firewall
              • Host firewall for Windows
              • Host firewall for macOS
            • Disk encryption
            • Host Inventory
            • Vulnerability Assessment
            • Set a Cortex XDR agent Critical Environment version
          • Manage endpoint protection
            • Move agents between managing servers
            • Manage endpoint tags
              • Create an endpoint tag
              • Remove an endpoint tag
              • Track your endpoint tags
              • Permanently remove Endpoint tags from the system
              • Set an alias for an endpoint
            • Manage endpoint prevention profiles
            • Create a new prevention policy rule for serverless function
            • View information about your endpoint prevention profiles
            • Upgrade Cortex XDR agents
            • Restart agent
            • Uninstall the Cortex XDR agent
            • Clear agent database
            • Delete Cortex XDR agents
            • Manage agent tokens
            • Retrieve support file password
            • Send push notifications to iOS
            • Monitor agent operational status
            • Monitor agent activity
            • Monitor agent upgrade status
      • Endpoint DLP
        • Cortex Data Loss Prevention (DLP) module overview
          • Archive file classification
          • True-file type detection
        • Personas workflow for DLP
        • Best Practices
        • Configure DLP end-to-end
        • DLP status in all endpoints
        • Cortex DLP threat detection and issues
    • Detect, Investigate, and respond to threats
      • Monitor dashboards and reports
        • Overview of dashboards and reports
          • Dashboard interface basics
          • Dashboard types
          • Report basics
          • Widget Library
        • Access and visibility for dashboards and reports
          • Visibility settings
          • Access to widgets
          • Sharing icons
          • Access and sharing cheat sheet
        • Manage dashboards and reports
          • Dashboard Manager
          • Reports
          • Duplicate dashboards and reports
          • Share custom dashboards and report templates
          • Change ownership to dashboards and report templates
          • Import and export dashboards and report templates
          • Configure the notification rule for a failed report
          • Deleted content
        • Create dashboards
          • Create a dashboard
        • Create reports
          • Create a report template from scratch
        • Advanced configuration
          • Create custom widgets
            • Create widgets using AI
            • Create XQL widgets
            • Add parameters to a custom XQL widget
            • Create script-based widgets
          • Configure global filters
          • Configure drilldowns
        • Dashboard reference
          • Command Center reference
            • Cortex Command Center
            • Cortex Agentic Assistant dashboard
            • XSIAM Command Center
              • Data Inventory
              • Dynamic View
              • Cases Overview
            • Cloud Detection and Response (CDR) Command Center
            • Cortex Cloud Command Center
          • System dashboards
            • Cortex Cloud Consumption
            • Cloud Security Operations
            • Data Ingestion
      • Investigation and response
        • Overview of cases
          • What are cases?
          • Resolving cases with AI
          • Case lifecycle
          • Case thresholds
          • Case scope and impact
          • Case and issue domains
          • Overview of case teams and roles
        • Case concepts
          • Issues, findings, and events
          • Case grouping
          • Case scoring
          • Case starring
          • SLAs and tracking
          • What is Causality?
        • Analyze and resolve cases
          • Review all cases
          • Start case analysis
            • Agentic Assistant- Case Investigation agent
          • Establish case context
            • AI-generated case summaries
            • Assess case severity and score
            • Update case attributes
          • Analyze case details
            • Grouping graph
            • Evidence
            • Issue feed
            • Associated assets and artifacts
            • MITRE ATT&CK tactics and techniques
            • Compliance standards and controls
            • Case timeline
            • Detailed View
          • Resolve the case
            • Resolution Center
            • Collaborative notes and comments
            • How to resolve a case
            • Resolution reasons for cases and issues
            • Monitor and track resolution times
            • Cortex Response and Remediation content pack
              • Investigate an issue using Cortex Response and Remediation playbooks
              • Example use cases
          • Additional case actions
            • Create a case
            • Merge a case
            • Assign a case team and restrict access
              • Playbook examples
            • Unified case view
        • Investigate issues
          • Overview of the Issues page
          • Issue card
          • Resolution actions
          • Link or unlink issues from a case
          • Run an automation on an issue
          • Use the War Room in an investigation
          • Use the Work Plan in an investigation
          • Issue syncing
          • Issue deduplication
          • Causality view
            • Network causality view
            • Cloud causality view
            • Cloud causality view for audit log issues
            • SaaS causality view
            • Timeline
            • Causality icons key
          • Issue investigation actions
            • Copy issues
            • Analyze an issue
            • Update issue fields
            • Query case and issue data
            • Exclude an issue
            • Create a featured field
            • Export issue details to a file
            • Investigate contributing events
            • Retrieve additional issue details
            • View generating BIOC or IOC rule
            • Create profile exceptions
            • Add a file path to a malware profile allow list
            • Close an issue
        • Review findings
          • Findings card
        • Investigate artifacts and assets
          • Investigate an IP address
          • Investigate an asset
          • Investigate a host
          • Investigate a file and process hash
          • Investigate a user
        • Investigate endpoints
          • Overview of the Action Center
            • Initiate and monitor endpoint actions
            • Action Center reference information
          • Manage endpoints
          • Retrieve files from an endpoint
          • Retrieve support logs from an endpoint
          • Retrieve support file password
          • Scan an endpoint for malware
        • Investigate files
          • Manage file execution
          • Manage quarantined files
          • Review WildFire analysis details
          • Import file hash exceptions
        • Cortex Assistant
          • Cortex Assistant layout
          • Cortex Assistant capabilities
        • Response actions
          • Initiate a Live Terminal session
          • Isolate an endpoint
          • Pause endpoint protection
          • Run agent scripts on an endpoint
          • Remediate changes from malicious activity
          • Search and destroy malicious files
          • Manage external dynamic lists
          • Collect a memory image
        • Forensics
          • Forensic investigations
          • Manage an investigation
            • Create a new investigation
            • Edit an investigation
            • Close an investigation
            • User permissions
          • Data collection
            • Hunting
              • Create a hunt
              • Hunt results
              • Hunt status
            • Triage
              • Create a triage
              • Upload an offline triage package
              • Offline triage collection
              • Triage results
              • Triage status
            • Configure collection
          • Analysis and documentation
          • Export
        • Notebooks
          • Manage datasets in Notebooks
          • Notebooks scheduler
        • Build XQL queries
          • About the Query Builder
          • How to build XQL queries
            • Get started with XQL queries
            • Useful XQL user interface features
            • XQL Query best practices
            • Expected results when querying fields
            • Create XQL query
            • Review XQL query results
            • Translate to XQL
            • Graph query results
          • Query Builder templates
            • Get started with Query Builder templates
            • Considerations for using Query Builder templates
            • Create a query from a template
            • Run a free text query
            • Query Builder template examples
          • Overview of the Query Center
            • Edit and run queries in Query Center
            • Query Center reference information
          • Manage scheduled queries
            • Scheduled Queries reference information
          • Manage your personal query library
          • XQL macros
          • Manage your macros
          • Federated Search
            • Federated Search configuration
            • Query using Federated Search
            • Manage external datasets
          • Legacy Query Builder
            • Create authentication query
            • Create event log query
            • Create file query
            • Create image load query
            • Create network connections query
            • Create network query
            • Create process query
            • Create registry query
            • Query across all entities
        • Research a known threat
      • Agentic Assistant chat
        • Get started with Agentic Assistant chat
        • Choose an Agentic Assistant agent
        • Chat with an Agentic Assistant agent
        • Chat with the Agentic Assistant from Slack
        • Create and run XQL queries with Agentic Assistant chat
        • Use natural language to query and visualize your data
        • Manage chat history
      • Asset management
        • Asset inventory overview
        • All assets
        • All cloud assets
          • Discovery Engine
          • Asset hierarchy
        • Asset classes
          • AI assets
          • API assets
          • Application assets
          • Code and Supply Chain Security assets
            • IaC resources assets
            • Repository assets
            • VCS organization assets
            • CI/CD pipeline assets
            • CI/CD instances assets
            • Software package assets
          • Compute assets
            • Container image assets
            • Serverless functions assets
            • VM images assets
          • Data assets
          • Device assets
          • External Surface assets
            • Website assets
            • Service assets
            • Domain assets
            • Certificate assets
            • External Surface attribution evidence
          • Identity assets
          • Network assets
          • Security services assets
        • Asset groups
        • Manage Risk Scores
        • Asset configurations
          • Network configurations
          • Application criteria
          • Asset Roles
            • Manage Asset Roles for Endpoints
            • Manage Asset Roles for Users
              • Honey user
        • Vulnerability Assessment
        • Query the asset inventory via XQL
      • Threat management
        • Detection rules
          • What are detection rules?
            • What's an IOC?
              • IOC rule details
              • Create an IOC rule
            • What's a BIOC?
              • BIOC rule details
              • Create a BIOC rule
              • Manage Global BIOC Rules
            • What's a correlation rule?
              • Correlation rule details
              • Create a correlation rule
              • Field replacement syntax in correlation rules
              • Manage correlation rules
              • Monitor correlation rules
              • Troubleshoot server errors in scheduled correlation rules
            • Manage IOC and BIOC rules
        • Analytics
          • Analytics overview
          • Analytics engine
          • Analytics sensors
          • Coverage of MITRE Attack tactics
          • Review MITRE ATT&CK framework coverage
          • Analytics detection time intervals
          • Analytics issues and Analytics BIOCs
          • Identity Analytics
          • View and manage Analytics rules
          • AI Detection & Response in Cortex XSIAM
            • Data sources and supported services
            • Collect prompt logs
              • Prompt log collection in AWS
              • Enable prompt log collection in Azure
                • Configure the Azure Event Hub collection in Cortex XSIAM
                • Set up prompt logging
                • Log HTTP data
                • Configure diagnostic settings
        • Extended Threat Intelligence
          • XTI Threat Intel Library
          • XTI Indicators
          • Threat intel context in cases and issues
          • XTI indicator rules
          • Threat intel investigation through XQL
          • Threat Intel Dashboard
          • Using XTI with Threat Intel Agent
          • Using XTI in playbooks
        • Threat Intel Management
          • Get started with Threat Intel Management
            • What is Threat Intel Management?
            • Threat Intel Management use cases
            • Roles and responsibilities in Threat Intel Management
            • Indicator concepts
            • Indicator lifecycle
          • Indicator configuration
            • Configure Threat Intelligence feed integrations
            • Customize indicator fields and types
              • Create an indicator type
                • Indicator type profile
                • Formatting scripts
                • Enhancement scripts
                • Reputation scripts
                • Reputation commands
                • Map custom indicator fields
              • Create an indicator field
                • Indicator field structure
                • Indicator field trigger scripts
            • Indicator classification and mapping
            • Indicator extraction
              • Set the indicator extraction mode for a playbook task
              • Disable indicator extraction for scripts or integrations
            • Configure Threat Intelligence feed integrations
            • Exclude indicators from enrichment
            • Generate issues from indicators using indicator rules for prevention and detection
            • Export indicators
          • Indicator management
          • Indicator investigation
            • Indicator verdict
            • Extract and enrich an indicator
            • Expire an indicator
            • Manage indicator relationships
            • Delete and exclude indicators
      • Attack surface management
        • Learn about Attack Surface Management
          • Network mapping
          • Scanning
          • GeoIP data collection
        • Attack Surface Management detections
          • Attack surface rules
          • Attack Surface Testing
          • Externally inferred CVEs
          • Digital Risk Protection
        • Attack surface assets
        • Deploy ASM and Exposure Management enrichment and remediation automation
        • ASM enrichment of cloud assets
        • Emerging Vulnerabilities
        • Global Lookup
      • Vulnerability management
        • Vulnerability management in Cortex XSIAM
        • Cortex Vulnerability Risk Score
        • Vulnerability policies
        • Investigate and remediate vulnerabilities
        • Vulnerability Intelligence
        • Emerging Vulnerabilities
        • Recast CVSS scores and CVSS severities
      • Exposure management
        • Learn about Exposure Management
        • Get started with Exposure Management
        • Ingest assets and vulnerabilities from third-party applications
        • Security controls
        • Cortex Network Scanner
        • Exposure Management Command Center
      • Cortex Advanced Email Security
        • Cortex Advanced Email Security module overview
        • Cortex Advanced Email Security module architecture and data flow
        • Getting started with the Cortex Advanced Email Security module
        • Deploy and configure the Email Security module
        • Cortex Advanced Email Security threat detection and issues
          • Email Security Analytics Rules
        • Investigate and respond to email security issues
        • Automate remediation for the Cortex Advanced Email Security module
          • Email Remediation Response Rules
          • Email Security Remediation Action Center
        • Email Command Center
        • Malicious Email Inventory
        • Mailbox Inventory
        • Advanced Email Security module security and compliance
      • Identity Threat Detection and Response (ITDR)
        • Get started with ITDR
        • Manage role based access control (RBAC) in ITDR
        • Monitor user risk exposure
        • Investigate user risk
        • Manage user asset roles
        • Improve Active Directory posture with AD-SPM
        • Enforce dynamic access control with CAP
        • Prevent malicious LDAP queries
    • Cloud Security
      • Monitor and track compliance adherence
        • Choose compliance standards from the compliance catalog
          • Standards catalog
          • Controls catalog
          • Use a built-in or custom standard
          • Use a built-in or custom control
          • Create a new custom detection rule
        • Use an assessment profile to run compliance checks on your assets
          • Configuring assessments for custom compliance standards based on custom cloud security rules
        • View and manage compliance assessments and reports
          • Review assessments
          • Review reports
        • Compliance Overview Dashboard
      • Cloud security rules and policies
        • Cloud security rules
        • Cloud security policies
        • Create and manage cloud security rules
          • Create a graph rule
          • Create a configuration rule
          • Create a data rule
          • Create an identity rule
          • Create a network exposure rule
          • Create an AI rule
          • Create an attack path (legacy) rule
          • View cloud security rule status
          • Edit a cloud security rule
          • Enable or disable a rule
          • Use an existing rule to create a new one
          • Delete a custom cloud security rule
        • Create and manage cloud security policies
          • Create a cloud security policy
          • Edit a cloud security policy
          • Enable or disable a policy
          • Use an existing policy to create a new one
          • Delete a custom cloud security policy
      • Cloud Data Classification
        • How to create and validate a custom data pattern
          • Custom data patterns: Guardrails and syntax guide
        • How to disable and enable data patterns in Data Classification
        • How to create and validate a custom data profile
        • How to disable and enable data profiles in Cloud Data Classification
        • How to report a false positive in Cloud Data Classification
        • Topic classification
      • Cloud Identity Security
        • What is Cloud Identity Security?
        • Review and improve your Identity Security posture
        • How does Effective Permission Calculation work?
        • Cloud Identity Security functionality
        • Configure Cloud Identity Security
        • Unified Human Identities
        • Achieve the principle of least privilege access
        • Explore permissions using the simple and advanced access tables
        • Create a custom detection rule in Cloud Identity Security
        • Perform advanced Identity Security investigations using XQL
        • Ingest logs and data from Okta
        • Enable inactive human identity logs on Azure in Cloud Identity Security
        • Manage RBAC and SBAC in Cloud Identity Security
      • Network exposure detection
        • What is Cloud Network Analyzer?
        • Internet exposure detection
        • Outbound exposure detection
        • East-west exposure detection
        • Investigate an internet exposure
        • Configure trusted IPs
      • Cortex Cloud SaaS Security
        • Setup SaaS Security
        • Connect a SaaS application
          • Onboard Asana
          • Onboard Atlassian
          • Onboard Automox
          • Onboard Businessmap
          • Onboard Celonis
          • Onboard Cisco Duo
          • Onboard Cisco Meraki
          • Onboard ClickUp
          • Onboard Contentful
          • Onboard Couchbase
          • Onboard Coveo
          • Onboard Databricks
          • Onboard Datadog
          • Onboard Gainsight PX
          • Onboard Grammarly
          • Onboard Harness
          • Onboard Intercom
          • Onboard Jamf Pro
          • Onboard JumpCloud
          • Onboard Kustomer
          • Onboard Microsoft Entra ID
          • Onboard Monday.com
          • Onboard MongoDB Atlas
          • Onboard MuleSoft
          • Onboard Mural
          • Onboard Office 365
          • Onboard Okta
          • Onboard PagerDuty
          • Onboard Redis Labs
          • Onboard Salesforce
          • Onboard SAP Ariba
          • Onboard Sentry
          • Onboard ServiceNow
          • Onboard Shopify
          • Onboard Slack Enterprise
          • Onboard Sumo Logic
          • Onboard Workday
          • Onboard Wrike
          • Onboard YouTrack
        • SaaS Security Overview
        • SaaS Security Checks
        • Provider Instances Security Check
        • Detection Rules
        • Remediation Actions
        • Create and monitor tickets
        • SaaS AI Agent Security
          • Setup SaaS Security for AISPM
          • Onboard SaaS AI Agents
            • Onboard Atlassian Rovo
            • Onboard Box AI Agents
            • Onboard ChatGPT Enterprise
            • Onboard Cursor Enterprise
            • Onboard Gemini Enterprise
            • Onboard M365 Copilot
            • Onboard Microsoft Copilot Studio
            • Onboard Service Now
          • Manage SaaS AI Agents
            • View AI Agents
            • View Datasets
            • View Agent Tools
      • Cortex Cloud AI Security
        • What is Cortex Cloud AI Security?
        • Supported services in Cortex Cloud AI Security
        • Cortex Cloud AI Security concepts
        • Cortex Cloud AI Security use cases
        • How to perform advanced AI Security investigations using XQL
      • Serverless function posture security
        • Onboard cloud providers for serverless functions
        • Serverless function posture rules
          • Manage serverless function rules
          • Create serverless function rules
          • Create an attack path rule for serverless functions
          • Create a configuration rule for serverless functions
          • Create a network exposure rule for serverless functions
        • Serverless function posture policies
          • Manage serverless function policies
          • Create serverless function policies
        • Serverless function usage
      • Cortex Cloud Application Security
      • Cloud workload policies and rules
        • How policies and rules work together
        • Cloud workload policies
          • Types of cloud workload policies
            • Trusted image cloud workload policies
          • Cloud Workload Policies page
          • Enable or disable a cloud workload policy
          • Create a cloud workload policy
          • Use an existing policy to create a new cloud workload policy
          • Edit a cloud workload policy
          • Delete a cloud workload policy
          • Cloud workload preventive action
        • Cloud workload rules
          • Default (pre-defined) rules
          • Custom (user-defined) rules
          • Cloud Workload Rules page
          • Create a new custom detection rule
          • Use an existing rule to create a new custom detection rule
          • Edit a custom detection rule
          • Delete a custom detection rule
      • Base image rules
        • Create a base image rule
        • Find the base image for an asset
      • Web and API Security (WAAS)
        • Personas workflow
        • Secure your API landscape
          • Gain visibility and assess risk of API endpoints
          • Monitor and investigate API threats
          • Configure API security from end to end
            • Ingest AWS API Gateway
            • Ingest Azure APIM
            • Ingest Apigee Proxy
            • Ingest Kong
            • Ingest F5
            • Agent-based protection
              • Set up Web and API Security profiles
              • Apply Web and API Security profiles to workloads
              • Manage Web and API Security prevention profiles
              • Add a disable prevention rule for cloud workloads
              • Add a support exception rule for cloud workloads
              • Add a legacy exception rule for cloud workloads
              • Additional workload management tasks
          • API specification inventory
      • Serverless function runtime security
        • Set up serverless function protection
        • Serverless runtime issues
    • Data Security
      • Cortex Data Security
    • Reference and developer docs
      • Cortex XSIAM XQL
        • Get started with XQL
          • XQL language features
          • XQL Language Structure
          • Supported operators
          • Datasets and presets
          • About examples
          • JSON functions
          • How to filter for empty values in the results table
          • Understanding string manipulation in XQL
        • Build XQL queries
          • About the Query Builder
          • How to build XQL queries
            • Get started with XQL queries
            • Useful XQL user interface features
            • XQL Query best practices
            • Expected results when querying fields
            • Create XQL query
            • Review XQL query results
            • Translate to XQL
            • Graph query results
          • Query Builder templates
            • Get started with Query Builder templates
            • Considerations for using Query Builder templates
            • Create a query from a template
            • Run a free text query
            • Query Builder template examples
          • Overview of the Query Center
            • Edit and run queries in Query Center
            • Query Center reference information
          • Manage scheduled queries
            • Scheduled Queries reference information
          • Manage your personal query library
          • XQL macros
          • Manage your macros
          • Federated Search
            • Federated Search configuration
            • Query using Federated Search
            • Manage external datasets
          • Legacy Query Builder
            • Create authentication query
            • Create event log query
            • Create file query
            • Create image load query
            • Create network connections query
            • Create network query
            • Create process query
            • Create registry query
            • Query across all entities
        • Cortex XQL syntax, parameters, and examples
      • Graph Search
        • What is Graph Search?
        • Get started with Graph Search queries
        • How to build Graph Search queries?
        • Understand Graph Search query results
        • Create Graph Search query
        • Graph Search examples
        • Manage the Graph Search Query Library
        • Edit and run queries in Query Center
        • Supported assets and findings
        • FAQ on Graph Search
        • Create detection rules based on graph search
      • About Cortex CLI
        • Connect Cortex CLI
          • Installation workflows
          • Manage the CLI after installation
          • Authenticate credentials
          • Self-service API keys for CLI scans
        • Cortex CLI usage
        • Cortex CLI common command line reference guide
        • Cortex CLI for Code Security
          • Cortex CLI usage for Cortex Cloud Application Security
          • Cortex CLI Cortex Cloud Application Security command line reference
            • Custom Cortex checks and signature verification
          • Cortex CLI pre-commit hooks
            • Pre-commit hook usage
          • Cortex CLI pre-receive hooks
            • Pre-receive hook usage
        • Cortex CLI for Cloud Workload Protection
          • Cloud Workload Protection command line reference
        • Cortex CLI for API Security
          • Cortex CLI API Security command line reference guide
            • API Security scan report schema
            • API Security scan output example
      • Role-Based Access Control
        • Role permissions by component
        • Core tenant and administrative permissions
        • Configuration permissions
          • Auditing permissions
          • Alert Notifications permissions
          • General Configuration permissions
          • Cortex XDR Analytics permissions
          • Access management permissions
          • Data Broker permissions
          • Log Collection permissions
          • Data Sources permissions
          • External Issues Mapping permissions
          • Integrations - instance permissions
          • Integrations Permissions
          • Data Management permissions
          • Public API
          • Threat Intelligence permission - API configuration
          • Long-running HTTP Integrations configuration
          • Credentials permissions
          • Network Scanners permissions
          • Apps - Instance permissions
          • Object Setup permissions
            • Case Properties permissions
            • Exclusion List permissions
            • Fields and Types permissions
            • Layout permissions
            • Sync Profile permissions
        • Marketplace permissions
        • Help permissions
        • SOC Operations, Investigation & Response permissions
        • Dashboards and Reports permissions
          • Dashboards permissions
          • Command Center Dashboard permissions
          • Ingestion Monitoring dashboard permissions
          • Reports permissions
          • Email Command Center permissions
          • Cloud Security Command Center permissions
        • Cases and Issues permissions
        • Investigation and Response permissions
          • Search permissions
            • Query Library permissions
            • Query Center permissions
            • Forensics permissions
            • Host Insights permissions
            • Graph Search permissions
          • Response permissions
            • Action Center permissions
            • EDL permissions
            • Agent Scripts Library permissions
            • Live Terminal permissions
          • Automation permissions
            • Playbook permissions
            • Script permissions
            • Jobs permissions
            • Playground permissions
            • Automation Exclusion Center permissions
        • Jupyter and Observability apps permissions
        • Threat Management permissions
          • Detection Rules permissions
          • Threat Intelligence permissions
        • Exceptions Configuration permissions
          • Issue Exclusions permissions
          • Exception Management Admin permissions
          • Exception Approver Admin permissions
        • Managed Services permissions
        • Cortex Agentic Assistant permissions
          • AI Prompts
          • Cortex Agentic Assistant Agents
        • Agents and endpoint protection
        • Inventory - Agent permissions
          • Agent Administrations
          • Agent Groups
          • Agent Prevention Policies
          • Global Exceptions
          • Agent Profiles
          • Agent Extension Policies
          • Agent Installations
          • Host Firewall
          • Device Control
        • Data Security - Endpoint DLP permissions
          • Data-in-Motion Rules
          • Endpoint Applications
          • Endpoint Applications Groups
          • Endpoint DLP Settings
        • Inventory - Assets permissions
          • Network Configuration permissions
          • Compliance (Legacy) permissions
          • Asset Inventory permissions
          • Asset Roles configuration permissions
          • Asset Groups permissions
        • Exposure and Vulnerability Management permissions
          • Attack Surface permissions
          • Vulnerability Management permissions
          • Exposure Management permissions
        • Cloud Security and Posture Management permissions
          • CLI Tool permissions
          • Application Security permissions
            • Application Security - Generic Collector permissions
            • Application Security - Issues permissions
            • Application Security - Scans permissions
            • Application Security - Policy Management permissions
            • Application Security - 3rd Party tools permissions
            • Configurations - Application Security permissions
          • Policies - Cloud Workload permissions
          • Cloud Security permissions
          • Compliance - Cloud permissions
          • Data Security permissions
          • AI Security permissions
          • Data Classification permissions
          • Identity Security permissions
      • API documentation
      • Reference
        • Cloud service provider permissions
        • Microsoft Windows security auditing setup
          • Enable security auditing event IDs
            • Enable security auditing event IDs with GPO
            • Set up local machine security auditing without GPO
            • Additional setup for Active Directory Certificate Services (ADCS) events
            • Enable auditing access to AD domain objects - 4662
          • Enable additional event logs using Event Viewer
          • Enable LDAP server events logging (1644)
            • Enable LDAP server events logging using RegEdit
            • Enable LDAP server events logging using GPO
            • Validate log collection for LDAP Server events
        • XDM fields for mapping authentication events
        • Cortex Network Scanner OSS
        • Fair Usage policy for Cortex XSIAM
    • Migrating to a new Broker VM image
      • Learn more about migrating to the latest broker VM image
      • Standalone Broker VM
      • Broker VM high availability cluster node
  • Cortex XQL Command Reference
    • Reference overview
    • Browse the reference
    • Functions
      • Functions overview
      • Functions list
      • acos
      • add
      • approx_count
      • approx_quantiles
      • approx_top
      • array_all
      • array_any
      • array_length
      • arrayconcat
      • arraycreate
      • arraydistinct
      • arrayfilter
      • arrayindex
      • arrayindexof
      • arraymap
      • arraymerge
      • arrayrange
      • arraystring
      • asin
      • avg (comp)
      • avg (windowcomp)
      • bitwise_and
      • bitwise_or
      • bitwise_sleft
      • bitwise_sright
      • bitwise_xor
      • cbrt
      • ceil
      • coalesce
      • concat
      • convert_from_base_64
      • convert_to_base_64
      • cos
      • cosine_distance
      • cot
      • count_distinct
      • count (comp)
      • count (windowcomp)
      • csc
      • current_time
      • date_floor
      • div
      • divide
      • earliest
      • euclidean_distance
      • exp
      • extract_time
      • extract_url_host
      • extract_url_pub_suffix
      • extract_url_registered_domain
      • first
      • first_value
      • floor
      • format_string
      • format_timestamp
      • greatest
      • hierarchy_match
      • if
      • incidr
      • incidr6
      • incidrlist
      • int_to_ip
      • ip_to_int
      • is_ipv4
      • is_ipv6
      • is_known_private_ipv4
      • is_known_private_ipv6
      • json_extract
      • json_extract_array
      • json_extract_scalar
      • json_extract_scalar_array
      • XQL JSON Functions Reference
      • json_path_extract
      • lag
      • last
      • last_value
      • latest
      • least
      • len
      • list (comp)
      • ln
      • log
      • log10
      • lowercase
      • ltrim
      • max (comp)
      • max (windowcomp)
      • md5
      • median (comp)
      • median (windowcomp)
      • min (comp)
      • min (windowcomp)
      • mod
      • multiply
      • object_create
      • object_merge
      • parse_epoch
      • parse_timestamp
      • pow
      • power
      • rand
      • range_bucket
      • rank (windowcomp)
      • regexcapture
      • regextract
      • replace
      • replex
      • round
      • row_number (windowcomp)
      • rtrim
      • safe_add
      • safe_divide
      • safe_multiply
      • safe_negate
      • safe_subtract
      • sec
      • sha1
      • sha256
      • sha512
      • sign
      • sin
      • split
      • sqrt
      • stddev_population (comp)
      • stddev_population (windowcomp)
      • stddev_sample (comp)
      • stddev_sample (windowcomp)
      • string_count
      • subtract
      • sum (comp)
      • sum (windowcomp)
      • tan
      • time_frame_end
      • timestamp_diff
      • timestamp_seconds
      • to_boolean
      • to_epoch
      • to_float
      • to_integer
      • to_json_string
      • to_number
      • to_string
      • to_timestamp
      • trim
      • trunc
      • uppercase
      • values
      • var
      • wildcard_match
    • Stages
      • Stages overview
      • Stages list
      • alter
      • arrayexpand
      • bin
      • call
      • comp
      • config
      • dataset
      • dedup
      • fields
      • filter
      • iploc
      • join
      • limit
      • pivot
      • preset
      • replacenull
      • search
      • sort
      • tag
      • target
      • top
      • transaction
      • transpose
      • union
      • view
      • windowcomp
  • Cortex XQL Schema Reference
    • Cortex XQL Schema Reference Guide
    • XDR_DATA Fields by Actor
      • Action Actor
      • Actor Actor
      • Causality Actor
      • DST Action Actor
      • DST Causality Actor
      • DST OS Actor
      • OS Actor
    • XDR_DATA Fields
  • Cortex XDR Agent Administrator Guide 9.3
    • Introduction
    • Cortex XDR agent for Windows
      • Cortex XDR agent for Windows requirements
      • Install the Cortex XDR agent for Windows
      • Install the Cortex XDR Agent with Installer and Content Update Package
      • Cortex XDR agent for virtual environments and desktops
      • Use Cortex XDR Agent for Windows
      • Upgrade the Cortex XDR Agent
      • Uninstall the Cortex XDR agent for Windows
      • Troubleshooting resources for Windows
        • Cytool for Windows
        • Cortex XDR Agents Deployed in Advertise Mode
    • Cortex XDR Agent for MacOS
      • Cortex XDR Agent for Mac Requirements
      • Install the Cortex XDR Agent for Mac
        • Install with a unified configuration profile for MDMs
        • macOS 15 Sequoia system extensions configuration file
        • MacOS Bluetooth MDM profile
        • Install the Cortex XDR Agent Using JAMF
        • Install the Cortex XDR Agent Manually
      • Configure Cortex XDR Agent for Mac
      • Use the Cortex XDR Agent for Mac
      • Uninstall the Cortex XDR Agent for Mac
      • Manage the Agent Deployment Notifications for Mac
      • Troubleshooting Resources for Mac
        • Cytool for Mac
    • Cortex XDR Agent for Linux
      • Cortex XDR supported Kernel Module versions by distribution
      • Cortex XDR Agent for Linux Requirements
      • Install the Cortex XDR agent for Linux
      • Install the Cortex XDR Agent for Kubernetes Hosts
      • Use the Cortex XDR agent for Linux
      • Uninstall the Cortex XDR Agent for Linux
      • Troubleshooting Resources for Linux
        • Cytool for Linux
  • Cortex XSIAM Developer Guide
    • Getting Started
      • Design
        • Use Case Design for Cortex XSIAM
        • Development scope
        • Integration design
        • Design best practices
      • Content development environments
        • IDE for script development
        • Set up a local development environment
        • Set up a GitHub Codespace environment
        • Set up a containerized development environment
        • Demisto SDK
        • Visual Studio Code extension
      • Frequently asked questions
    • Integrations and scripts
      • Components
        • Integration directory structure
        • Integration metadata YAML file
        • Integration and script parameter types
        • Integration description file
        • Integration Logo Requirements
      • Developing
        • Python code conventions
        • PowerShell
        • General naming conventions
        • Integration Parameters
        • Context and outputs
        • Context standards
        • Generic commands
        • Reputation and DBot score
        • Integration commands
        • Using Docker
      • Advanced topics
        • Fetching credentials
        • Event collector integrations
        • Feed Integrations
        • Long Running Containers
        • Transform Language (DT)
        • Integration cache
        • OpenAPI (Swagger) Codegen
        • Postman code generator
        • Generate Integration Python Code from JSON
        • Generate YAML from Python
        • Scheduled Commands
        • Fetch missing incidents with generic lookback methods
      • Create a sample integration
        • Define sample integration settings
        • Write integration code
        • Test the integration
    • Playbooks
      • Add a Playbook to a Content Pack
      • Playbook conventions
      • Generic playbooks
    • Lists
    • Issues
    • Data modeling rules
      • Create data model rules
        • Test Data Model Rules
    • Indicators
      • URL extraction
      • Domain extraction
      • Relationships
    • Documentation
      • Documentation best practices
      • Content pack metadata file
      • Content pack release notes
      • Content Pack README
      • README files for content entities
      • Images in documentation
      • Videos in documentation
      • Documentation Contributions
    • Testing
      • Linting
      • Unit testing
      • Test playbooks
      • Debugging
    • Contributing content
      • Contribution requirements
      • File checklist
      • Content pack structure
      • Content pack dependencies
      • Pull request conventions
      • Contribution demo preparation
      • Contribution SLA
  • Cortex XDR Compatibility Matrix
    • Where can I install the Cortex XDR agent?
      • Endpoint operating systems supported
        • Mac
        • Windows
        • Linux
      • Cloud platforms supported with Cortex XDR agent
      • Kubernetes platforms supported
      • Virtual applications supported
      • Mobile operating systems supported with Cortex XDR
    • Cortex XDR agent compatibility with third-party security products
      • Third-party Windows security applications
      • Third-party Mac security applications
      • Third-party Linux security applications
  • Linux Kernel Versions
    • Linux Kernel Versions
    • AlmaLinux
    • Amazon Linux
    • Amazon Linux 2
    • Amazon Linux 2023
    • CentOS
    • CentOS Stream
    • Debian
    • OpenSUSE
    • Oracle Linux
    • Red Hat Enterprise Linux (RHEL)
    • Rocky Linux
    • SUSE Linux Enterprise Server
    • Ubuntu
  • Cortex XDR Agent Releases
    • Cortex XDR Agent Releases
    • Cortex XDR Hotfix Releases
    • Cortex XDR Mobile Patch Releases
    • Cortex XDR Agent Past Releases Archive
Cortex XSIAM Documentation / Configure Cortex XSIAM / Cortex XSIAM Data Sources and Connectors / Vendor-specific data sources and connectors / Hostio Solutions

Hostio Solutions ↗

Here are the articles in this section:

  • hostio-solutions

← HPE Aruba Hostio Solutions →
Cortex Toolbox v0.1.0 — a community tool, not an official Palo Alto Networks product. Estimates are indicative; validate sizing with your Palo Alto Networks representative.