Configure Cortex XSIAM
Sub-topics
- Learn how to configure Cortex XSIAM
-
Data management
- Optimize data management in Cortex XSIAM
- Configure Cortex Data Lake tier
-
Broker VM
- What is the Broker VM?
-
Set up and configure Broker VM
-
Broker VM image installations
- Set up Broker VM on Alibaba Cloud
- Set up Broker VM on Amazon Web Services
- Set up Broker VM on Google Cloud Platform (GCP)
- Set up Broker VM on KVM using Ubuntu
- Set up Broker VM on Microsoft Azure
- Set up Broker VM on Microsoft Hyper-V
- Set up Broker VM on Nutanix Hypervisor
- Set up Broker VM on VMware ESXi using vSphere Client
- Broker VM data collector applets
-
Broker VM image installations
-
Manage Broker VM
- Edit Broker VM Configuration
- Increase Broker VM storage allocated for data caching
- Monitor Broker VM using Prometheus
- Collect Broker VM Logs
- Upgrade Broker VM
- Update Broker VM applets independently
- Import Broker VM Configuration
- Open Live Terminal
- Add Broker VM to cluster
- Switchover Primary Node in Cluster
- Remove from Cluster
- Manage Broker VM data collector applets
- Broker VM High Availability Cluster
- Broker VM notifications
- Monitor Broker VM activity
- Troubleshoot Broker VM applet errors
- Dataset management
- Archived data
- Parsing Rules
-
Data Model Rules
- Data Model Rules editor views
- Data Model Rules file structure and syntax
- How to map authentication events for analytics
- Generate data model rules with AI (preview)
- Create Data Model Rules
- Troubleshooting Data Model Rules
- Using data enrichment
- Data Model Rules notifications
- Monitor Data Model Rules activity
- Manage Event Forwarding
- Manage compute units
-
Cortex XSIAM Data Sources and Connectors
- What are Cortex XSIAM data sources and connectors?
- What is the data source and connector catalog?
-
Vendor-specific data sources and connectors
- 1Password
- Abnormal Security
- Absolute
- abuse.ch
- AbuseIPDB
- Accenture
- AdminByRequest
- Aha
- AIOps
- Akamai
- AlgoSec
- Alibaba Cloud
- AlienVault
- Amazon
- Anomali
- Anthropic
- Apache
- API Security
- APIVoid
- Apollo.io
- AppSentinels
- ArcSight
- Arista Networks
- Arkime
- Armis
- Articulate Global
- Asana
- Atlassian
- AttackIQ
- Aurora Endpoint Security
- Automox
- BeyondTrust
- BitSight
- bitwarden
- Blocklist.de
- BloodHound Enterprise
- BlueCat Address Manager
- BMC
- Box
- Broadcom
- BruteForceBlocker
- Businessmap
- C2SEC
- CAPESandbox
- Carbon Black
- Celonis
- Centreon
- ChatGPT Enterprise
- Check Point
- CheckPhish
- CipherTrust
- CIRCL
- CircleCI
- Cisco
- Citrix
- ClickUp
- Cloaken
- CloudConvert
- Cloudflare
- Code42
- Cohesity
- Contentful
- Corelight
- Couchbase
- CounterTack
- Coveo
- Cribl
- CrowdStrike
- CryptoCurrency
- Cuckoo Sandbox
- Cursor
- CybelAngel
- CyberArk
- Cyber Triage
- CYFIRMA
- Darktrace
- Databricks
- DataDog
- DeHashed
- DHS
- digicert
- dnstwist
- Docker
- DocuSign
- Dropbox
- Druva
- EasyVista
- Email Hippo
- Elastic
- Endgame
- Envoy
- Exabeam
- ExtraHop
- F5
- Fastly
- Fidelis
- Filigran
- Forcepoint
- ForeScout
- Fortinet
- Fortra
- FraudWatch
- Freshworks
- Gainsight
- Gamma.AI
- Gemini Enterprise
- Genetec
- Generic
- Genesys
- Gigamon
- GitGuardian
- GitHub
- GitLab
- Giphy
- GraphQL
- Grouped Example Connector
- GRR
- Grafana
- Halcyon
- Harbor
- Harness
- HashiCorp
- Have I Been Pwnd
- HCL BigFix
- HPE Aruba
- Hostio Solutions
- HTTP log collector
- IBM
- iManage
- Imperva
- InfoArmor
- Infoblox
- Intellum
- Intercom
- IPInfo.io
- IPstack
- Ironscales
- Ivanti
- iZOOlogic
- Jamf
- JFrog
- Joe Security
- JumpCloud
- JSONWhoIs.com
- Kafka
- Kaspersky
- Keeper Security
- KnowBe4
- Koi
- Koodous
- Kubernetes
- Kustomer
- LastPass
- Lastline
- LevelBlue
- LogRhythm
- LOLBAS
- Lookout
- Lumu
- Mail Utilities
- Majestic
- ManageEngine
- Mattermost
- MaxMind
- Menlo Security
- Meta
- Mimecast
-
Microsoft
- Azure DevOps
- Azure Event Hub
- Azure Firewall
- Azure Network Watcher
- Microsoft Azure
- Microsoft Copilot Studio
- Microsoft Defender for Endpoint Events
- Microsoft Entra ID
- Microsoft Office 365
- Microsoft Office 365 (email)
- Microsoft 365 (Posture)
- Microsoft Teams
- Azure Log Analytics
- Azure Services
- Azure WAF
- Microsoft Active Directory
- Microsoft Identity
- Microsoft Intune
- Microsoft Security Automation and Collection
- Microsoft Windows Tools
- M365 Automation and Collection
- MISP
- MITRE
- Monday
- MongoDB
- MuleSoft
- Mural
- MxToolBox
- NetBox
- Netcraft
- Netmiko
- NetQuest
- Netskope
- Nintex Workflow Cloud
- NIST
- nmap
- NAVEX
- Nutanix
- Okta
- OneLogin
- OpenAI
- OpenCVE
- OpenLDAP
- OpenPhish
- OpenText
- OPSWAT
- Oracle
- Orca Security
- PacketMail.net
- PacketSled
- PagerDuty
- PAT Helpdesk Advanced
- PhishLabs
- Ping Identity
- Pipedrive
- Pipl
- Plainview
- Proofpoint
- ProtectWise
- Qualtrics
- Qualys
- Quest KACE
- Radware
- Rapid7
- Razor Group
- Recorded Future
- Red Hat
- Redis Labs
- Redmine
- ReliaQuest
- RemoteAccess
- Retarus
- RSA
- RTIR
- runZero
- Salesforce
- SailPoint
- Samhaus
- SANS DShield
- SAP
- Saviynt
- SecurityScorecard
- Securonix
- Sentry
- SentinelOne
- ServiceNow
- Shopify
- Shodan
- Skyhigh Security
- Slack
- SMB
- SMIME Messaging
- Snowflake
- SolarWinds
- Sonatype Nexus
- Sophos
- Splunk
- Sublime Security
- Sumo Logic
- SysAid
- Syslog Sender
- Tanium
- TAXII
- TeamViewer
- Telegram
- Tenable
- Terraform
- Thales
- TheHive
- Thinkst Canary
- ThreatConnect
- ThreatMiner.org
- ThreatX
- Tidy
- TOPdesk
- Tor Exit Adress
- Trellix
- TrendAI
- Twilio
- Uptycs
- Vectra
- Versa Networks
- VMware
- VulnDB
- WhatsMyBrowser.org
- Whois
- WithSecure
- Workday
- X
- YouTrack
- Zendesk
- Zero Networks
- Zimperium
- Zoom
- Zscaler
- Connectors
- Standard data sources
-
Cloud service provider (CSP) onboarding
- Understand CSP onboarding tiers and licensing
-
Amazon Web Services cloud onboarding
- AWS security capabilities and deployment planning
- AWS resource inventory
- AWS security model and authentication
- Cortex XSIAM and AWS audit log collection architecture
- Onboard Amazon Web Services
- Prerequisites for onboarding AWS
- How to onboard Amazon Web Services
- Deploy the authentication template in AWS
- Post-deployment: Custom (BYOB) and Control Tower audit log collection
- Grant cross-account KMS key access for Control Tower BYOB log collection
- AWS post-deployment verification
- Microsoft Azure cloud onboarding
-
Google Cloud Platform onboarding
- Onboard Google Cloud Platform
- Prerequisites for onboarding GCP
- How to onboard Google Cloud Platform
- How to onboard GCP with foundational configuration
- Deploy the Terraform authentication template in GCP
- Connect Google Workspace with your GCP cloud instance
- Monitor GCP resources inside service perimeters
- Oracle Cloud Infrastructure cloud onboarding
- Alibaba Cloud cloud onboarding
- Outpost onboarding
- Introduction to Terraform for Cloud service provider (CSP) onboarding
- Manually connect a cloud instance
- Manage cloud instances
- Pending cloud instances
- Edit your onboarded CSP configuration
- Update cloud permissions after Cortex XSIAM release updates
- Troubleshoot errors on cloud instances
- Cloud service provider permissions
-
Generic on-premise data collectors
-
Broker VM data collector applets
- Activate Apache Kafka Collector
- Activate Cortex Network Scanner
- Activate CSV Collector
- Activate Database Collector
- Activate DSPM Database
- Activate DSPM Fileshare
- Activate Files and Folders Collector
- Activate FTP Collector
- Activate Local Agent Settings
- Activate NetFlow Collector
- Activate Network Mapper
- Activate Registry Scanner
- Syslog Collector applet
- Activate Transporter
- Activate Windows Event Collector
-
XDR Collectors
- XDR Collector audit logs
- XDR Collector machine requirements and supported operating systems
- Resources required to enable access to XDR collectors
-
Manage XDR Collectors
- XDR Collectors installation resource for Windows and Linux
- Create an XDR Collector installation package
- Install the XDR Collector installation package for Windows
- Install the XDR Collector installation package for Linux
- Configure XDR Collector upgrade scheduler
- Set an application proxy for XDR Collectors
- Set an alias for an XDR Collector machine
- Upgrade XDR Collectors
- Uninstall the XDR Collector
- Define XDR Collector machine groups
- About Cortex XDR Collector content updates
- XDR Collector profiles
- Apply profiles to collection machine policies
- XDR Collector datasets
-
Broker VM data collector applets
-
Palo Alto Networks integrations
- Cloud Next-Generation Firewall
- Next-Generation Firewall
- Prisma Access
- Prisma Access Browser
- Ingest detection data from Strata Logging Service
- IoT Security
- Cortex Attack Surface Management
- Cortex Automation Developer Tools
- Cortex Data Lake
- Cortex Internals
- Cortex XDR
- Enterprise DLP
- Palo Alto Networks Cortex
- PAN PSIRT Advisories
- Prisma Cloud Compute
- Prisma Cloud CSPM
- SaaS Security (Aperture)
- Threat Vault
- WildFire Cloud
- Log type filtering
- Collecting URL and File log types
- Cloud Posture and Runtime Security data sources
- External alerts using External Issue Mapping
- Administration and troubleshooting
- Marketplace
- Configure the Cortex Agentic Assistant
- Cortex MCP server
-
Automations
- Automation in Cortex XSIAM
- Quick Actions
- Automation Exclusion Center
-
Playbooks
- Playbooks overview
- Access to playbooks
- Playbook development checkli
- Plan your playbook
- Manage playbooks
-
Build your playbook
- Choose from existing playbooks or create your own
- Configure playbook settings
- Add objects from the Task Library
-
Customize your playbook
- Configure a sub-playbook loop
- Filter and transform Cortex XSIAM playbook data
- Create custom filters and transformers
- Filter considerations, categories, and built-in filters
- Transformer considerations, categories, and built-in transformers
- Extend context in playbooks
- Extract indicators in playbooks
- Update issue fields with playbook tasks
- Test your playbook
- Manage playbook content
- Accelerate playbook development using the Automation Engineer agent (preview)
- Best practices for playbooks
- Autonomous playbooks
- AI Prompts
- Agentic Response (Preview)
- Create an automation rule
- Scripts
- Context data
- Lists
- Jobs
-
Engines
- What is an engine?
- Engine requirements
- Install an engine
- Manage engines
- Upgrade an engine
- Remove an engine
- Configure engines
- Use an engine in an integration
- Run a script using an engine
- Troubleshoot engines
- Troubleshoot integrations running on engines
- Remote repository management
-
Customize cases and issues
- External integrations
- Set up case scoring
- Create a starring configuration
- Create custom case statuses and resolution reasons
- Create a sync profile
- Create a case domain
- Customize case fields and layouts
- Customize issue fields and layouts
- Create SLAs for case and issue resolution
- Create issue exceptions
- Optimize case grouping in correlations
- Run indicator extraction in the CLI
- XQL query management
-
Multi-Tenant
- What is Cortex XSIAM multi-tenant?
- Multi-tenant central licensing management
- Onboard Cortex multi-tenant
- Dynamic license allocation
- Child tenant management
- About managed threat hunting
- Managed Services configuration in Cortex