Vendor-specific data sources and connectors

Cortex XSIAM enables you to ingest data from a wide range of third-party vendors and security services. For many popular vendors, you can choose between distinct types of ingestion methods to fit your organizational needs:

* Connectors
* Standard data sources (also called data collectors)
* Cloud Service Provider (CSP) onboarding data sources
* Content pack integrations (Marketplace)

In some cases, the same vendor is available through multiple options. Check the available descriptions for each entry in both the user interface and documentation to decide which option is more suitable for your needs.

| Data Source Type | Primary Use | Configuration Method | Cortex XSIAM Features | Recommendation |
| --------------------------------------------------- | -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Connector | Unified integration for all vendor capabilities. | Configured on the **Data Sources & Integrations** page using a unified wizard. | Includes data ingestion, parsing, normalization, plus built-in commands, automations, and posture management. | Recommended approach for all supported vendors. Choose this for a streamlined, multi-capability setup. |
| Standard data source (also called data collectors) | Ingesting raw logs and events. | Configured in the **Data Sources & Integrations** page using the Data Source Onboarder. | Limited to data ingestion, parsing, and normalization. | Choose this if you only need raw data ingestion for a service not yet covered by a unified connector. |
| Cloud Service Provider (CSP) onboarding data source | Ingesting cloud assets and infrastructure logs. | Configured in the **Data Sources & Integrations** page using the cloud service provider (CSP) onboarding wizard. | Facilitates seamless setup of CSP data, such as AWS, Azure, GCP, and OCI, with minimal user input. | Choose this for streamlined discovery and security posture management of your cloud environments. |
| Content pack integration (Marketplace) | Ingesting data and enabling rich security functionality. | <p>Configured via a content pack downloaded from Marketplace by either:</p><ul><li>Using the Data Source Onboarder on the <strong>Data Sources &#x26; Integrations</strong> page (if available)</li><li>Installing the content pack from <strong>Settings</strong> → <strong>Configurations</strong> → <strong>Marketplace</strong>, and then configuring the integration instance on the <strong>Data Sources &#x26; Integrations</strong> page.</li></ul> | Includes: Data ingestion, parsing, normalization, plus built-in commands and automations, such as playbooks, scripts, correlation rules, and data model rules. | <p>Primarily used for partner-managed, community-contributed, or Palo Alto Networks managed integrations that have not yet been consolidated into a unified connector.</p><p>Choose this option for any of the following reasons:</p><ul><li>You need to define automations.</li><li>You need to collect data that is not covered by a standard collector.</li><li>You need to install rules or automations relevant to integrations or data sources.</li></ul> |

### Availability for new tenants

If your Cortex XSIAM tenant was onboarded after July 26, 2026, a strategic Connector experience is available for Palo Alto Networks managed integrations. Standalone Marketplace integrations that have been consolidated into unified connectors are hidden from Marketplace to ensure a simplified configuration flow. For these specific vendors, always use the uniquely named Connector to manage all supported sub-capabilities. Partner and community integrations remain available as standalone entries in [Marketplace](../marketplace).

### Third-party vendor list

Cortex XSIAM provides specific documentation for each vendor to help you choose and configure the right connection. To ensure you have a single, unified reference point, the vendors are listed in alphabetical order and includes every supported vendor, regardless of the data source group connector, such as the Broker VM or CSP Onboarding.

#### Keep in mind the following:

* **Unique connector names**: Each connector has its own unique name. Even if multiple connectors exist for a single vendor, they will be clearly labeled to distinguish their capabilities.
* **Licensing requirements**: Availability of specific connectors, capabilities, and sub-capabilities is determined by your tenant license. You will only see and be able to onboard services supported by your active license.
* **Consolidated management**: Regardless of whether you are using a traditional data source or a new unified connector, all active instances are managed from the **Data Sources & Integrations** page.
* **Marketplace reference:** This list identifies vendors that offer Palo Alto Networks managed connectors. It does not include every available Marketplace content pack, particularly partner-managed and community-contributed integrations, which are always managed as standalone packs. To view the complete list of all available integrations, see the [Cortex Developer Docs for Marketplace](https://cortex.marketplace.pan.dev/marketplace/). This site provides instructions for these integrations by selecting the <**content pack>** → **Content** → **Integrations**, and choosing the relevant steps for your implementation. You can always install these standalone integrations directly from **Settings → Configurations → Marketplace** or the **Data Sources & Integrations** page (if available).
* **Requirement hand-off (new tenants)**: If your tenant was onboarded after July 26, 2026, the unified wizard handles all configuration steps. Yet, you must still refer to the [Cortex Developer Docs for Marketplace](https://cortex.marketplace.pan.dev/marketplace/) for critical technical information not provided in the wizard, such as available fetched incidents data, commands, and other specific technical details related to the integration. Note that the Marketplace site may occasionally reference a different Cortex product, but the technical requirements remain applicable.

***

Sub-topics