Configure Cortex XSIAM network parameters ↗
Define your internal IP address ranges and domain names to enable Cortex XSIAM to identify, track, and analyze network assets.
Define internal IP address ranges
The IP Address Ranges page displays the address ranges that Cortex XSIAM Analytics monitors. Addresses are pre-populated with the default IPv4 and IPv6 address spaces. The names you define appear when investigating the network-related events in Cortex XSIAM.
You can add a new IP address range manually or upload IP address ranges from a CSV file.
How to define internal IP address ranges
- Select Inventory → Assets → Network Configuration → Internal IP Address Ranges.
-
Do one of the following:
To Do this Add a new IP address manually <p>1. Click Add New Range → Create New, and then enter the IP address name and IP address range or CIDR values.</p><p>By default, Cortex XSIAM creates Private Network ranges that specify reserved industry-approved ranges. Private Network ranges are marked with a
icon and you can only edit the name.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>You can add a range that is fully contained in an existing range; however, you cannot add a new range that partially intersects with another range.</p></div><p>2. Click Save.</p>Upload IP address ranges from a CSV file <p>1. Select Inventory+Assets → Network Configuration → IP Address Ranges.</p><p>2. Click Add New Range → Upload from File.</p><p>3. Locate the CSV file you want to upload, and then click Add.</p>
Define internal domain names
- Select Inventory → Assets → Network Configuration → Internal Domain Suffixes.
- Type the domain suffix you want to include as part of your internal network, for example,
acme.com. - Select
to add the suffix to the Domains List.