Platform Changes
Everything that moved across Cortex — the documentation, the analytics rules, and the content packs.
Covering August 29, 2026, 00:00–24:00 UTC · published August 30, 2026 08:56 UTC.
Last checked about 17 hours ago. Summaries are written by claude-code/claude-opus-5; the changes themselves are recorded automatically.
Documentation
10 pages changed +78 −42AWS audit log role renamed to cortex-logs-ingestion-access-*; manual deployment method added for AWS, GCP and Azure
- The AWS audit log reader role is renamed from CloudTrailReadRole / CortexLogsReadRole to
cortex-logs-ingestion-access-*, including in the cross-account KMS key policy example. - A new Deployment Method advanced setting offers Infrastructure as Code (recommended) or Manual onboarding on AWS, Google Cloud Platform and Microsoft Azure.
- Custom (BYOB) audit log collection is rebuilt around SNS: the Cortex-created SQS queue subscribes to your SNS topic, so S3 event notifications now target the topic rather than the queue.
- Two new BYOB constraints are documented — the Control Tower log bucket must use Bucket owner enforced object ownership, and its objects may be encrypted under at most one customer-managed KMS key.
- AWS resource inventory
- AWS security capabilities and deployment planning
- AWS security model and authentication
- Cortex XSIAM and AWS audit log collection architecture
- Grant cross-account KMS key access for Control Tower BYOB log collection
- How to onboard Amazon Web Services
- and 4 more
Analytics rules
0 rules changed +0 −0Synced, and nothing changed upstream.
Content packs
1 pack changed +78 −1A single-pack day: Qualys defaults LAST_VM_AUTH_SCAN_DATETIME when the field is missing
- One pack moves for one upstream commit (+78/-1) — the quietest content day of the past fortnight.
- qualys supplies a default for
LAST_VM_AUTH_SCAN_DATETIMEwhen the field is absent (#45681). - 78 insertions against a single deletion: handling was added, not rewritten.
- No pack was added or removed.
- qualys
BIOC rules are not tracked yet — that sync signs in to a live Cortex tenant, so there is nowhere for an unattended daily export to run.