Documentation
-
Cortex XSIAM Documentation
- Learn about Cortex XSIAM
-
Onboard Cortex XSIAM
- How to onboard Cortex XSIAM
- Plan and prepare
- Deployment steps
-
Post-deployment
- Cortex XSIAM post-deployment checklist
- Perform health checks
- Cortex Marketplace
- Manage user roles and access management
- Dashboards and reports
- Configure server settings
- Configure security settings
- Data and log forwarding
-
Configure Cortex XSIAM
- Learn how to configure Cortex XSIAM
-
Data management
- Optimize data management in Cortex XSIAM
- Configure Cortex Data Lake tier
-
Broker VM
- What is the Broker VM?
-
Set up and configure Broker VM
-
Broker VM image installations
- Set up Broker VM on Alibaba Cloud
- Set up Broker VM on Amazon Web Services
- Set up Broker VM on Google Cloud Platform (GCP)
- Set up Broker VM on KVM using Ubuntu
- Set up Broker VM on Microsoft Azure
- Set up Broker VM on Microsoft Hyper-V
- Set up Broker VM on Nutanix Hypervisor
- Set up Broker VM on VMware ESXi using vSphere Client
- Broker VM data collector applets
-
Broker VM image installations
-
Manage Broker VM
- Edit Broker VM Configuration
- Increase Broker VM storage allocated for data caching
- Monitor Broker VM using Prometheus
- Collect Broker VM Logs
- Upgrade Broker VM
- Update Broker VM applets independently
- Import Broker VM Configuration
- Open Live Terminal
- Add Broker VM to cluster
- Switchover Primary Node in Cluster
- Remove from Cluster
- Manage Broker VM data collector applets
- Broker VM High Availability Cluster
- Broker VM notifications
- Monitor Broker VM activity
- Troubleshoot Broker VM applet errors
- Dataset management
- Archived data
- Parsing Rules
-
Data Model Rules
- Data Model Rules editor views
- Data Model Rules file structure and syntax
- How to map authentication events for analytics
- Generate data model rules with AI (preview)
- Create Data Model Rules
- Troubleshooting Data Model Rules
- Using data enrichment
- Data Model Rules notifications
- Monitor Data Model Rules activity
- Manage Event Forwarding
- Manage compute units
-
Cortex XSIAM Data Sources and Connectors
- What are Cortex XSIAM data sources and connectors?
- What is the data source and connector catalog?
-
Vendor-specific data sources and connectors
- 1Password
- Abnormal Security
- Absolute
- abuse.ch
- AbuseIPDB
- Accenture
- AdminByRequest
- Aha
- AIOps
- Akamai
- AlgoSec
- Alibaba Cloud
- AlienVault
- Amazon
- Anomali
- Anthropic
- Apache
- API Security
- APIVoid
- Apollo.io
- AppSentinels
- ArcSight
- Arista Networks
- Arkime
- Armis
- Articulate Global
- Asana
- Atlassian
- AttackIQ
- Aurora Endpoint Security
- Automox
- BeyondTrust
- BitSight
- bitwarden
- Blocklist.de
- BloodHound Enterprise
- BlueCat Address Manager
- BMC
- Box
- Broadcom
- BruteForceBlocker
- Businessmap
- C2SEC
- CAPESandbox
- Carbon Black
- Celonis
- Centreon
- ChatGPT Enterprise
- Check Point
- CheckPhish
- CipherTrust
- CIRCL
- CircleCI
- Cisco
- Citrix
- ClickUp
- Cloaken
- CloudConvert
- Cloudflare
- Code42
- Cohesity
- Contentful
- Corelight
- Couchbase
- CounterTack
- Coveo
- Cribl
- CrowdStrike
- CryptoCurrency
- Cuckoo Sandbox
- Cursor
- CybelAngel
- CyberArk
- Cyber Triage
- CYFIRMA
- Darktrace
- Databricks
- DataDog
- DeHashed
- DHS
- digicert
- dnstwist
- Docker
- DocuSign
- Dropbox
- Druva
- EasyVista
- Email Hippo
- Elastic
- Endgame
- Envoy
- Exabeam
- ExtraHop
- F5
- Fastly
- Fidelis
- Filigran
- Forcepoint
- ForeScout
- Fortinet
- Fortra
- FraudWatch
- Freshworks
- Gainsight
- Gamma.AI
- Gemini Enterprise
- Genetec
- Generic
- Genesys
- Gigamon
- GitGuardian
- GitHub
- GitLab
- Giphy
- GraphQL
- Grouped Example Connector
- GRR
- Grafana
- Halcyon
- Harbor
- Harness
- HashiCorp
- Have I Been Pwnd
- HCL BigFix
- HPE Aruba
- Hostio Solutions
- HTTP log collector
- IBM
- iManage
- Imperva
- InfoArmor
- Infoblox
- Intellum
- Intercom
- IPInfo.io
- IPstack
- Ironscales
- Ivanti
- iZOOlogic
- Jamf
- JFrog
- Joe Security
- JumpCloud
- JSONWhoIs.com
- Kafka
- Kaspersky
- Keeper Security
- KnowBe4
- Koi
- Koodous
- Kubernetes
- Kustomer
- LastPass
- Lastline
- LevelBlue
- LogRhythm
- LOLBAS
- Lookout
- Lumu
- Mail Utilities
- Majestic
- ManageEngine
- Mattermost
- MaxMind
- Menlo Security
- Meta
- Mimecast
-
Microsoft
- Azure DevOps
- Azure Event Hub
- Azure Firewall
- Azure Network Watcher
- Microsoft Azure
- Microsoft Copilot Studio
- Microsoft Defender for Endpoint Events
- Microsoft Entra ID
- Microsoft Office 365
- Microsoft Office 365 (email)
- Microsoft 365 (Posture)
- Microsoft Teams
- Azure Log Analytics
- Azure Services
- Azure WAF
- Microsoft Active Directory
- Microsoft Identity
- Microsoft Intune
- Microsoft Security Automation and Collection
- Microsoft Windows Tools
- M365 Automation and Collection
- MISP
- MITRE
- Monday
- MongoDB
- MuleSoft
- Mural
- MxToolBox
- NetBox
- Netcraft
- Netmiko
- NetQuest
- Netskope
- Nintex Workflow Cloud
- NIST
- nmap
- NAVEX
- Nutanix
- Okta
- OneLogin
- OpenAI
- OpenCVE
- OpenLDAP
- OpenPhish
- OpenText
- OPSWAT
- Oracle
- Orca Security
- PacketMail.net
- PacketSled
- PagerDuty
- PAT Helpdesk Advanced
- PhishLabs
- Ping Identity
- Pipedrive
- Pipl
- Plainview
- Proofpoint
- ProtectWise
- Qualtrics
- Qualys
- Quest KACE
- Radware
- Rapid7
- Razor Group
- Recorded Future
- Red Hat
- Redis Labs
- Redmine
- ReliaQuest
- RemoteAccess
- Retarus
- RSA
- RTIR
- runZero
- Salesforce
- SailPoint
- Samhaus
- SANS DShield
- SAP
- Saviynt
- SecurityScorecard
- Securonix
- Sentry
- SentinelOne
- ServiceNow
- Shopify
- Shodan
- Skyhigh Security
- Slack
- SMB
- SMIME Messaging
- Snowflake
- SolarWinds
- Sonatype Nexus
- Sophos
- Splunk
- Sublime Security
- Sumo Logic
- SysAid
- Syslog Sender
- Tanium
- TAXII
- TeamViewer
- Telegram
- Tenable
- Terraform
- Thales
- TheHive
- Thinkst Canary
- ThreatConnect
- ThreatMiner.org
- ThreatX
- Tidy
- TOPdesk
- Tor Exit Adress
- Trellix
- TrendAI
- Twilio
- Uptycs
- Vectra
- Versa Networks
- VMware
- VulnDB
- WhatsMyBrowser.org
- Whois
- WithSecure
- Workday
- X
- YouTrack
- Zendesk
- Zero Networks
- Zimperium
- Zoom
- Zscaler
- Connectors
- Standard data sources
-
Cloud service provider (CSP) onboarding
- Understand CSP onboarding tiers and licensing
-
Amazon Web Services cloud onboarding
- AWS security capabilities and deployment planning
- AWS resource inventory
- AWS security model and authentication
- Cortex XSIAM and AWS audit log collection architecture
- Onboard Amazon Web Services
- Prerequisites for onboarding AWS
- How to onboard Amazon Web Services
- Deploy the authentication template in AWS
- Post-deployment: Custom (BYOB) and Control Tower audit log collection
- Grant cross-account KMS key access for Control Tower BYOB log collection
- AWS post-deployment verification
- Microsoft Azure cloud onboarding
-
Google Cloud Platform onboarding
- Onboard Google Cloud Platform
- Prerequisites for onboarding GCP
- How to onboard Google Cloud Platform
- How to onboard GCP with foundational configuration
- Deploy the Terraform authentication template in GCP
- Connect Google Workspace with your GCP cloud instance
- Monitor GCP resources inside service perimeters
- Oracle Cloud Infrastructure cloud onboarding
- Alibaba Cloud cloud onboarding
- Outpost onboarding
- Introduction to Terraform for Cloud service provider (CSP) onboarding
- Manually connect a cloud instance
- Manage cloud instances
- Pending cloud instances
- Edit your onboarded CSP configuration
- Update cloud permissions after Cortex XSIAM release updates
- Troubleshoot errors on cloud instances
- Cloud service provider permissions
-
Generic on-premise data collectors
-
Broker VM data collector applets
- Activate Apache Kafka Collector
- Activate Cortex Network Scanner
- Activate CSV Collector
- Activate Database Collector
- Activate DSPM Database
- Activate DSPM Fileshare
- Activate Files and Folders Collector
- Activate FTP Collector
- Activate Local Agent Settings
- Activate NetFlow Collector
- Activate Network Mapper
- Activate Registry Scanner
- Syslog Collector applet
- Activate Transporter
- Activate Windows Event Collector
-
XDR Collectors
- XDR Collector audit logs
- XDR Collector machine requirements and supported operating systems
- Resources required to enable access to XDR collectors
-
Manage XDR Collectors
- XDR Collectors installation resource for Windows and Linux
- Create an XDR Collector installation package
- Install the XDR Collector installation package for Windows
- Install the XDR Collector installation package for Linux
- Configure XDR Collector upgrade scheduler
- Set an application proxy for XDR Collectors
- Set an alias for an XDR Collector machine
- Upgrade XDR Collectors
- Uninstall the XDR Collector
- Define XDR Collector machine groups
- About Cortex XDR Collector content updates
- XDR Collector profiles
- Apply profiles to collection machine policies
- XDR Collector datasets
-
Broker VM data collector applets
-
Palo Alto Networks integrations
- Cloud Next-Generation Firewall
- Next-Generation Firewall
- Prisma Access
- Prisma Access Browser
- Ingest detection data from Strata Logging Service
- IoT Security
- Cortex Attack Surface Management
- Cortex Automation Developer Tools
- Cortex Data Lake
- Cortex Internals
- Cortex XDR
- Enterprise DLP
- Palo Alto Networks Cortex
- PAN PSIRT Advisories
- Prisma Cloud Compute
- Prisma Cloud CSPM
- SaaS Security (Aperture)
- Threat Vault
- WildFire Cloud
- Log type filtering
- Collecting URL and File log types
- Cloud Posture and Runtime Security data sources
- External alerts using External Issue Mapping
- Administration and troubleshooting
- Marketplace
- Configure the Cortex Agentic Assistant
- Cortex MCP server
-
Automations
- Automation in Cortex XSIAM
- Quick Actions
- Automation Exclusion Center
-
Playbooks
- Playbooks overview
- Access to playbooks
- Playbook development checkli
- Plan your playbook
- Manage playbooks
-
Build your playbook
- Choose from existing playbooks or create your own
- Configure playbook settings
- Add objects from the Task Library
-
Customize your playbook
- Configure a sub-playbook loop
- Filter and transform Cortex XSIAM playbook data
- Create custom filters and transformers
- Filter considerations, categories, and built-in filters
- Transformer considerations, categories, and built-in transformers
- Extend context in playbooks
- Extract indicators in playbooks
- Update issue fields with playbook tasks
- Test your playbook
- Manage playbook content
- Accelerate playbook development using the Automation Engineer agent (preview)
- Best practices for playbooks
- Autonomous playbooks
- AI Prompts
- Agentic Response (Preview)
- Create an automation rule
- Scripts
- Context data
- Lists
- Jobs
-
Engines
- What is an engine?
- Engine requirements
- Install an engine
- Manage engines
- Upgrade an engine
- Remove an engine
- Configure engines
- Use an engine in an integration
- Run a script using an engine
- Troubleshoot engines
- Troubleshoot integrations running on engines
- Remote repository management
-
Customize cases and issues
- External integrations
- Set up case scoring
- Create a starring configuration
- Create custom case statuses and resolution reasons
- Create a sync profile
- Create a case domain
- Customize case fields and layouts
- Customize issue fields and layouts
- Create SLAs for case and issue resolution
- Create issue exceptions
- Optimize case grouping in correlations
- Run indicator extraction in the CLI
- XQL query management
-
Multi-Tenant
- What is Cortex XSIAM multi-tenant?
- Multi-tenant central licensing management
- Onboard Cortex multi-tenant
- Dynamic license allocation
- Child tenant management
- About managed threat hunting
- Managed Services configuration in Cortex
-
Protect your endpoints
-
Endpoint security
-
Endpoint protection
- Malware protection
- Exploit protection
- File analysis and protection flow
- Endpoint protection capabilities
- Processes protected by exploit security policy
- File Integrity Monitoring (FIM)
- CaaS Workloads
- WildFire analysis concepts
- Guidelines for keeping Cortex XDR agents and content updated
- About content updates
- Endpoint data collection
-
Install and manage endpoints
-
Set up endpoint protection
-
Set up endpoint profiles and exception rules
- Set up malware prevention profiles
- Set up exploit prevention profiles
- Set up agent settings profiles
- Set up restrictions prevention profiles
- Set up exception profiles and rules
- Set up Identity profiles
-
Set up endpoint profiles and exception rules
- Define endpoint groups
- Configure global agent settings
- Apply profiles to endpoints
- Create an agent installation package
- Harden endpoint security
-
Manage endpoint protection
- Move agents between managing servers
- Manage endpoint tags
- Manage endpoint prevention profiles
- Create a new prevention policy rule for serverless function
- View information about your endpoint prevention profiles
- Upgrade Cortex XDR agents
- Restart agent
- Uninstall the Cortex XDR agent
- Clear agent database
- Delete Cortex XDR agents
- Manage agent tokens
- Retrieve support file password
- Send push notifications to iOS
- Monitor agent operational status
- Monitor agent activity
- Monitor agent upgrade status
-
Set up endpoint protection
-
Endpoint protection
- Endpoint DLP
-
Endpoint security
-
Detect, Investigate, and respond to threats
- Monitor dashboards and reports
-
Investigation and response
- Overview of cases
- Case concepts
- Analyze and resolve cases
-
Investigate issues
- Overview of the Issues page
- Issue card
- Resolution actions
- Link or unlink issues from a case
- Run an automation on an issue
- Use the War Room in an investigation
- Use the Work Plan in an investigation
- Issue syncing
- Issue deduplication
- Causality view
-
Issue investigation actions
- Copy issues
- Analyze an issue
- Update issue fields
- Query case and issue data
- Exclude an issue
- Create a featured field
- Export issue details to a file
- Investigate contributing events
- Retrieve additional issue details
- View generating BIOC or IOC rule
- Create profile exceptions
- Add a file path to a malware profile allow list
- Close an issue
- Review findings
- Investigate artifacts and assets
- Investigate endpoints
- Investigate files
- Cortex Assistant
- Response actions
- Forensics
- Notebooks
- Build XQL queries
- Research a known threat
- Agentic Assistant chat
-
Asset management
- Asset inventory overview
- All assets
- All cloud assets
- Asset classes
- Asset groups
- Manage Risk Scores
- Asset configurations
- Vulnerability Assessment
- Query the asset inventory via XQL
-
Threat management
- Detection rules
- Analytics
- Extended Threat Intelligence
-
Threat Intel Management
- Get started with Threat Intel Management
-
Indicator configuration
- Configure Threat Intelligence feed integrations
- Customize indicator fields and types
- Indicator classification and mapping
- Indicator extraction
- Configure Threat Intelligence feed integrations
- Exclude indicators from enrichment
- Generate issues from indicators using indicator rules for prevention and detection
- Export indicators
- Indicator management
- Indicator investigation
- Attack surface management
- Vulnerability management
- Exposure management
-
Cortex Advanced Email Security
- Cortex Advanced Email Security module overview
- Cortex Advanced Email Security module architecture and data flow
- Getting started with the Cortex Advanced Email Security module
- Deploy and configure the Email Security module
- Cortex Advanced Email Security threat detection and issues
- Investigate and respond to email security issues
- Automate remediation for the Cortex Advanced Email Security module
- Email Command Center
- Malicious Email Inventory
- Mailbox Inventory
- Advanced Email Security module security and compliance
- Identity Threat Detection and Response (ITDR)
-
Cloud Security
- Monitor and track compliance adherence
-
Cloud security rules and policies
- Cloud security rules
- Cloud security policies
-
Create and manage cloud security rules
- Create a graph rule
- Create a configuration rule
- Create a data rule
- Create an identity rule
- Create a network exposure rule
- Create an AI rule
- Create an attack path (legacy) rule
- View cloud security rule status
- Edit a cloud security rule
- Enable or disable a rule
- Use an existing rule to create a new one
- Delete a custom cloud security rule
- Create and manage cloud security policies
-
Cloud Data Classification
- How to create and validate a custom data pattern
- How to disable and enable data patterns in Data Classification
- How to create and validate a custom data profile
- How to disable and enable data profiles in Cloud Data Classification
- How to report a false positive in Cloud Data Classification
- Topic classification
-
Cloud Identity Security
- What is Cloud Identity Security?
- Review and improve your Identity Security posture
- How does Effective Permission Calculation work?
- Cloud Identity Security functionality
- Configure Cloud Identity Security
- Unified Human Identities
- Achieve the principle of least privilege access
- Explore permissions using the simple and advanced access tables
- Create a custom detection rule in Cloud Identity Security
- Perform advanced Identity Security investigations using XQL
- Ingest logs and data from Okta
- Enable inactive human identity logs on Azure in Cloud Identity Security
- Manage RBAC and SBAC in Cloud Identity Security
- Network exposure detection
-
Cortex Cloud SaaS Security
- Setup SaaS Security
-
Connect a SaaS application
- Onboard Asana
- Onboard Atlassian
- Onboard Automox
- Onboard Businessmap
- Onboard Celonis
- Onboard Cisco Duo
- Onboard Cisco Meraki
- Onboard ClickUp
- Onboard Contentful
- Onboard Couchbase
- Onboard Coveo
- Onboard Databricks
- Onboard Datadog
- Onboard Gainsight PX
- Onboard Grammarly
- Onboard Harness
- Onboard Intercom
- Onboard Jamf Pro
- Onboard JumpCloud
- Onboard Kustomer
- Onboard Microsoft Entra ID
- Onboard Monday.com
- Onboard MongoDB Atlas
- Onboard MuleSoft
- Onboard Mural
- Onboard Office 365
- Onboard Okta
- Onboard PagerDuty
- Onboard Redis Labs
- Onboard Salesforce
- Onboard SAP Ariba
- Onboard Sentry
- Onboard ServiceNow
- Onboard Shopify
- Onboard Slack Enterprise
- Onboard Sumo Logic
- Onboard Workday
- Onboard Wrike
- Onboard YouTrack
- SaaS Security Overview
- SaaS Security Checks
- Provider Instances Security Check
- Detection Rules
- Remediation Actions
- Create and monitor tickets
- SaaS AI Agent Security
- Cortex Cloud AI Security
- Serverless function posture security
- Cortex Cloud Application Security
-
Cloud workload policies and rules
- How policies and rules work together
- Cloud workload policies
- Cloud workload rules
- Base image rules
-
Web and API Security (WAAS)
- Personas workflow
-
Secure your API landscape
- Gain visibility and assess risk of API endpoints
- Monitor and investigate API threats
-
Configure API security from end to end
- Ingest AWS API Gateway
- Ingest Azure APIM
- Ingest Apigee Proxy
- Ingest Kong
- Ingest F5
-
Agent-based protection
- Set up Web and API Security profiles
- Apply Web and API Security profiles to workloads
- Manage Web and API Security prevention profiles
- Add a disable prevention rule for cloud workloads
- Add a support exception rule for cloud workloads
- Add a legacy exception rule for cloud workloads
- Additional workload management tasks
- API specification inventory
- Serverless function runtime security
- Data Security
-
Reference and developer docs
-
Cortex XSIAM XQL
- Get started with XQL
- Build XQL queries
- Cortex XQL syntax, parameters, and examples
-
Graph Search
- What is Graph Search?
- Get started with Graph Search queries
- How to build Graph Search queries?
- Understand Graph Search query results
- Create Graph Search query
- Graph Search examples
- Manage the Graph Search Query Library
- Edit and run queries in Query Center
- Supported assets and findings
- FAQ on Graph Search
- Create detection rules based on graph search
- About Cortex CLI
-
Role-Based Access Control
- Role permissions by component
- Core tenant and administrative permissions
-
Configuration permissions
- Auditing permissions
- Alert Notifications permissions
- General Configuration permissions
- Cortex XDR Analytics permissions
- Access management permissions
- Data Broker permissions
- Log Collection permissions
- Data Sources permissions
- External Issues Mapping permissions
- Integrations - instance permissions
- Integrations Permissions
- Data Management permissions
- Public API
- Threat Intelligence permission - API configuration
- Long-running HTTP Integrations configuration
- Credentials permissions
- Network Scanners permissions
- Apps - Instance permissions
- Object Setup permissions
- Marketplace permissions
- Help permissions
- SOC Operations, Investigation & Response permissions
- Dashboards and Reports permissions
- Cases and Issues permissions
- Investigation and Response permissions
- Jupyter and Observability apps permissions
- Threat Management permissions
- Exceptions Configuration permissions
- Managed Services permissions
- Cortex Agentic Assistant permissions
- Agents and endpoint protection
- Inventory - Agent permissions
- Data Security - Endpoint DLP permissions
- Inventory - Assets permissions
- Exposure and Vulnerability Management permissions
- Cloud Security and Posture Management permissions
- API documentation
-
Reference
- Cloud service provider permissions
- Microsoft Windows security auditing setup
- XDM fields for mapping authentication events
- Cortex Network Scanner OSS
- Fair Usage policy for Cortex XSIAM
-
Cortex XSIAM XQL
- Migrating to a new Broker VM image
-
Cortex XQL Command Reference
- Reference overview
- Browse the reference
-
Functions
- Functions overview
- Functions list
- acos
- add
- approx_count
- approx_quantiles
- approx_top
- array_all
- array_any
- array_length
- arrayconcat
- arraycreate
- arraydistinct
- arrayfilter
- arrayindex
- arrayindexof
- arraymap
- arraymerge
- arrayrange
- arraystring
- asin
- avg (comp)
- avg (windowcomp)
- bitwise_and
- bitwise_or
- bitwise_sleft
- bitwise_sright
- bitwise_xor
- cbrt
- ceil
- coalesce
- concat
- convert_from_base_64
- convert_to_base_64
- cos
- cosine_distance
- cot
- count_distinct
- count (comp)
- count (windowcomp)
- csc
- current_time
- date_floor
- div
- divide
- earliest
- euclidean_distance
- exp
- extract_time
- extract_url_host
- extract_url_pub_suffix
- extract_url_registered_domain
- first
- first_value
- floor
- format_string
- format_timestamp
- greatest
- hierarchy_match
- if
- incidr
- incidr6
- incidrlist
- int_to_ip
- ip_to_int
- is_ipv4
- is_ipv6
- is_known_private_ipv4
- is_known_private_ipv6
- json_extract
- json_extract_array
- json_extract_scalar
- json_extract_scalar_array
- XQL JSON Functions Reference
- json_path_extract
- lag
- last
- last_value
- latest
- least
- len
- list (comp)
- ln
- log
- log10
- lowercase
- ltrim
- max (comp)
- max (windowcomp)
- md5
- median (comp)
- median (windowcomp)
- min (comp)
- min (windowcomp)
- mod
- multiply
- object_create
- object_merge
- parse_epoch
- parse_timestamp
- pow
- power
- rand
- range_bucket
- rank (windowcomp)
- regexcapture
- regextract
- replace
- replex
- round
- row_number (windowcomp)
- rtrim
- safe_add
- safe_divide
- safe_multiply
- safe_negate
- safe_subtract
- sec
- sha1
- sha256
- sha512
- sign
- sin
- split
- sqrt
- stddev_population (comp)
- stddev_population (windowcomp)
- stddev_sample (comp)
- stddev_sample (windowcomp)
- string_count
- subtract
- sum (comp)
- sum (windowcomp)
- tan
- time_frame_end
- timestamp_diff
- timestamp_seconds
- to_boolean
- to_epoch
- to_float
- to_integer
- to_json_string
- to_number
- to_string
- to_timestamp
- trim
- trunc
- uppercase
- values
- var
- wildcard_match
- Stages
- Cortex XQL Schema Reference
-
Cortex XDR Agent Administrator Guide 9.3
- Introduction
-
Cortex XDR agent for Windows
- Cortex XDR agent for Windows requirements
- Install the Cortex XDR agent for Windows
- Install the Cortex XDR Agent with Installer and Content Update Package
- Cortex XDR agent for virtual environments and desktops
- Use Cortex XDR Agent for Windows
- Upgrade the Cortex XDR Agent
- Uninstall the Cortex XDR agent for Windows
- Troubleshooting resources for Windows
- Cortex XDR Agent for MacOS
-
Cortex XDR Agent for Linux
- Cortex XDR supported Kernel Module versions by distribution
- Cortex XDR Agent for Linux Requirements
- Install the Cortex XDR agent for Linux
- Install the Cortex XDR Agent for Kubernetes Hosts
- Use the Cortex XDR agent for Linux
- Uninstall the Cortex XDR Agent for Linux
- Troubleshooting Resources for Linux
-
Cortex XSIAM Developer Guide
- Getting Started
-
Integrations and scripts
- Components
- Developing
-
Advanced topics
- Fetching credentials
- Event collector integrations
- Feed Integrations
- Long Running Containers
- Transform Language (DT)
- Integration cache
- OpenAPI (Swagger) Codegen
- Postman code generator
- Generate Integration Python Code from JSON
- Generate YAML from Python
- Scheduled Commands
- Fetch missing incidents with generic lookback methods
- Create a sample integration
- Playbooks
- Lists
- Issues
- Data modeling rules
- Indicators
- Documentation
- Testing
- Contributing content
- Cortex XDR Compatibility Matrix
- Linux Kernel Versions
- Cortex XDR Agent Releases