Documentation — August 10, 2026
33 files changed, 128 insertions, 275 deletions — view the commit on the mirror.
Mobile compatibility pages folded into one; AWS Control Tower BYOB onboarding corrected
- Cortex XDR Compatibility Matrix lost two pages: the Android and iOS/iPadOS tables now live on their parent page, taking the book from 15 pages to 13.
- Most compatibility tables were re-emitted as raw HTML with a single Cortex XDR agent header row over the version columns.
- AWS Control Tower (BYOB) audit log collection gained a CloudFormation parameter, a corrected IAM role name, and a post-deployment page retitled to cover it.
- Microsoft Azure automated collection now documents one management-group diagnostic setting instead of per-subscription ones.
- Nine pages lost their front-matter
descriptionblocks, and several XSOAR/XSIAM naming slips were fixed.
Highlights
-
Android and iOS/iPadOS compatibility pages were deleted
Both tables were merged into the parent mobile page, so bookmarks to the two child pages break and the compatibility book drops from 15 to 13 pages.
-
The Control Tower BYOB IAM role is named CloudTrailReadRole, not cortex-logs-ingestion-access-<suffix>
Every occurrence in the cross-account KMS procedure changed, including the key-policy principal ARN a reader copies verbatim.
-
A LoggingAccountOuId parameter was added to the AWS authentication template
It names the OU containing the Log Archive account, and the neighbouring SnsTopicOuId description no longer spells out the aws-controltower-AllConfigNotifications topic.
-
Azure management-group scope creates a single diagnostic setting
Activity Logs propagate natively from child subscriptions through that one setting, and no per-subscription diagnostic setting is created.
-
XQL navigation is now Investigation & Response → Search → XQL Search
The Query Builder → XQL step was removed from both query procedures, shortening each numbered list by one step.
-
Two internal links moved in opposite directions
The ITDR Identity profile link was resolved from broken-reference to a real anchor, while the Windows agent release-notes link became broken-reference.
Changes
33 files listed, 15 written up and shaded below.
-
▸ ▾ README modified +1 −1
READMEGenerated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Navigation manifest (compatibility) modified +2 −15
.meta/compatibilityThe book's page tree and ordering — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Navigation manifest (xsiam) modified +1 −1
.meta/xsiamThe book's page tree and ordering — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Cloud platforms supported with Cortex XDR agent modified +1 −12 Lead-in sentence and the Supported cloud platforms heading removed; only the HTML table remains.
compatibility/where-can-i-install-the-cortex-xdr-agent/cloud-platforms-supported-with-cortex-xdr-agentRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,3 @@# Cloud platforms supported with Cortex XDR agent# Cloud platforms supported with Cortex XDR agentLearn about the cloud platforms that support Cortex XDR agents.Cortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE Alibaba Cloud ✓ ✓ ✓ ✓ ✓ ✓ Amazon Web Services (AWS) ✓ ✓ ✓ ✓ ✓ ✓ Google Cloud Platform ✓ ✓ ✓ ✓ ✓ ✓ IBM Cloud ✓ ✓ ✓ ✓ ✓ ✓ Microsoft Azure ✓ ✓ ✓ ✓ ✓ ✓ Oracle Cloud Infrastructure (OCI) ✓ ✓ ✓ ✓ ✓ ✓ ### Supported cloud platformsLinux Cloud Platform│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CE| --------------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ |Alibaba Cloud│✓│✓│✓│✓│✓│✓Amazon Web Services (AWS)│✓│✓│✓│✓│✓│✓Google Cloud Platform│✓│✓│✓│✓│✓│✓IBM Cloud│✓│✓│✓│✓│✓│✓Microsoft Azure│✓│✓│✓│✓│✓│✓Oracle Cloud Infrastructure (OCI)│✓│✓│✓│✓│✓│✓Show markdown source
@@ -1,14 +1,3 @@ # Cloud platforms supported with Cortex XDR agent -Learn about the cloud platforms that support Cortex XDR agents. - -### Supported cloud platforms - -| Linux Cloud Platform | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| --------------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ | -| Alibaba Cloud | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Amazon Web Services (AWS) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Google Cloud Platform | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| IBM Cloud | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Microsoft Azure | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Oracle Cloud Infrastructure (OCI) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>Alibaba Cloud</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Web Services (AWS)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Google Cloud Platform</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>IBM Cloud</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Microsoft Azure</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Oracle Cloud Infrastructure (OCI)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table>
-
▸ ▾ Linux modified +50 −93 Intro rewritten around the kernel-module vs eBPF choice, and the kernel support link repointed to cortex-docs.paloaltonetworks.com/linux-kernel-versions.
compatibility/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported/linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,150 +1,107 @@# Linux# Linux### Supported Linux operating systems## Supported Linux operating systemsThe following Linux operating systems support the Cortex XDR agent.The following Linux operating systems support the Cortex XDR agent.The Cortex XDR agent protects Linux Servers by preventing known and unknown malware from running by halting any attempts to leverage software exploits and vulnerabilities to compromise the server. Cortex XDR offers two methods for agent protection on Linux endpoints; a Kernel module and a user-mode (eBPF-based) approach. To help you choose the best deployment for your environment, see the feature differences between these two modes in the latest Cortex XDR agent Admin guide.There are two methods for agent protection on Linux endpoints; a Kernel module and a user-mode (eBPF-based) approach. To help you choose the best deployment for your environment, see the feature differences between these two modes in the latest Cortex XDR agent Admin guide.See the latest Kernel Module versions supported.For the latest Kernel modules support see here.hint infohint info### Note### NoteCortex XDR agent 9.1 was the last agent release supporting Linux kernels below 3.10. To avoid service disruption, hosts running kernels below 3.10 must not be upgraded beyond the 9.1 agent line. Disable auto-upgrades for endpoint profiles managing those machines, and prevent manual upgrades of the hosts to agent versions later than 9.1Cortex XDR agent 9.1 was the last agent release supporting Linux kernels below 3.10. To avoid service disruption, hosts running kernels below 3.10 must not be upgraded beyond the 9.1 agent line. Disable auto-upgrades for endpoint profiles managing those machines, and prevent manual upgrades of the hosts to agent versions later than 9.1endhintendhint### Alibaba Cloud Linux### Alibaba Cloud LinuxAlibaba Cloud Linux Operating System│Agent version 9.3│Agent version 9.2│Agent version 9.1-CE│Agent version 9.1│Agent version 9.0││Cortex XDR agent│││││| ------------------------------------ | ----------------- | ----------------- | -------------------- | ----------------- | ----------------- | - || --------------------- | ---------------- | --- | ------ | --- | --- | ------ |Alibaba Cloud Linux 3│✓│✓│✓│✓│—│—│9.3│9.2│9.1-CE│9.1│9.0│8.7-CEAlibaba Cloud Linux 3│✓│✓│✓│✓│—│—### AlmaLinux### AlmaLinuxAlmaLinux Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CE│Cortex XDR agent│││││| -------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ || ------------ | ---------------- | --- | ------ | --- | --- | ------ |AlmaLinux 8│✓│✓│✓│✓│✓│✓│9.3│9.2│9.1-CE│9.1│9.0│8.7-CEAlmaLinux 9│✓│✓│✓│✓│✓│✓AlmaLinux 10│✓│✓│✓│✓│✓│✓AlmaLinux 10│✓│✓│✓│✓│✓│✓AlmaLinux 9│✓│✓│✓│✓│✓│✓AlmaLinux 8│✓│✓│✓│✓│✓│✓### Amazon Linux/Amazon Linux 2/Amazon Linux 2023### Amazon Linux/Amazon Linux 2/Amazon Linux 2023Amazon Linux Operating System Agent version 9.3 Agent version
9.2Agent version
9.1-CEAgent version
9.1Agent version
9.0Agent version
8.7-CEAMI 2018.03 ✓ ✓ ✓ ✓ ✓ ✓ Amazon Linux 2 AMI ✓ ✓ ✓ ✓ ✓ ✓ Amazon Linux 2 AMI (aarch64) ✓ ✓ ✓ ✓ ✓ ✓ Amazon Linux 2023 ✓ ✓ ✓ ✓ ✓ ✓ Amazon Linux 2023 (aarch64) ✓ ✓ ✓ ✓ ✓ — Cortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE AMI 2018.03 ✓ ✓ ✓ ✓ ✓ ✓ Amazon Linux 2 AMI ✓ ✓ ✓ ✓ ✓ ✓ Amazon Linux 2 AMI (aarch64) ✓ ✓ ✓ ✓ ✓ ✓ Amazon Linux 2023 ✓ ✓ ✓ ✓ ✓ ✓ Amazon Linux 2023 (aarch64) ✓ ✓ ✓ ✓ ✓ — ### Debian### DebianDebian Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CECortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE Debian 13 (Trixie) ✓ ✓ ✓ ✓ ✓ ✓ Debian 12 (Bookworm) ✓ ✓ ✓ ✓ ✓ ✓ Debian 11 (Bullseye) ✓ ✓ ✓ ✓ ✓ ✓ Debian 10 (Buster) ✓ ✓ ✓ ✓ ✓ ✓ Debian 10 (Buster) aarch64 ✓ ✓ ✓ ✓ ✓ ✓ Debian 9 (Stretch) ✓ ✓ ✓ ✓ ✓ ✓ | -------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ |Debian 9 (Stretch)│✓│✓│✓│✓│✓│✓Debian 10 (Buster)│✓│✓│✓│✓│✓│✓Debian 10 (Buster) aarch64│✓│✓│✓│✓│✓│✓Debian 11 (Bullseye)│✓│✓│✓│✓│✓│✓Debian 12 (Bookworm)│✓│✓│✓│✓│✓│✓Debian 13 (Trixie)│✓│✓│✓│✓│✓│✓### CentOS### CentOSCentOS Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CECortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE CentOS Stream 9 ✓ ✓ ✓ ✓ ✓ ✓ CentOS Stream 8 ✓ ✓ ✓ ✓ ✓ ✓ CentOS Stream 8 aarch64 ✓ ✓ ✓ ✓ ✓ ✓ CentOS 8 ✓ ✓ ✓ ✓ ✓ ✓ CentOS 8 aarch64 ✓ ✓ ✓ ✓ ✓ ✓ CentOS 7.9 aarch64 ✓
User mode agent not supported
✓
User mode agent not supported
✓
User mode agent not supported
✓
User mode agent not supported
✓
User mode agent not supported
✓
User mode agent not supported
CentOS 7 ✓ ✓ ✓ ✓ ✓ ✓ CentOS 6
(6.7 and above)Async mode only Async mode only ✓ ✓ ✓ ✓ | --------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- |CentOS 6 (supports 6.7 and above)│Async mode only│Async mode only│✓│✓│✓│✓CentOS 7│✓│✓│✓│✓│✓│✓CentOS 7.9 aarch64│✓User mode agent not supported
│✓User mode agent not supported
│✓User mode agent not supported
│✓User mode agent not supported
│✓User mode agent not supported
│✓User mode agent not supported
CentOS 8│✓│✓│✓│✓│✓│✓CentOS 8 aarch64│✓│✓│✓│✓│✓│✓CentOS Stream 8│✓│✓│✓│✓│✓│✓CentOS Stream 8 aarch64│✓│✓│✓│✓│✓│✓CentOS Stream 9│✓│✓│✓│✓│✓│✓### Fedora Server### Fedora ServerFedora Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CE│Cortex XDR agent│││││| ------------------------ | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ || ------------------------ | ---------------- | --- | ------ | --- | --- | ------ |Fedora Server (USM only)│✓│✓│✓│✓│✓│✓│9.3│9.2│9.1-CE│9.1│9.0│8.7-CEFedora Server (USM only)│✓│✓│✓│✓│✓│✓### openSUSE### openSUSEopenSUSE Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CE│Cortex XDR agent│││││| ---------------------------- | --------------------------- | --------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- || ---------------------------- | ---------------- | --- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- |openSUSE Leap 16.0 (UM only)│✓│✓│✓From content release 2280-36261
│✓From content release 2280-36261
│—│—│9.3│9.2│9.1-CE│9.1│9.0│8.7-CEopenSUSE Leap 15.6 (UM only)│✓│✓│✓From content release 2160-30885
│✓From content release 2160-30885
│✓From content release 2160-30885
│✓From content release 2160-30885
openSUSE Leap 16.0 (UM only)│✓│✓│✓From content release 2280-36261
│✓From content release 2280-36261
│—│—openSUSE Leap 15.3│✓│✓│✓│✓│✓│✓openSUSE Leap 15.6 (UM only)│✓│✓│✓From content release 2160-30885
│✓From content release 2160-30885
│✓From content release 2160-30885
│✓From content release 2160-30885
openSUSE Leap 15.2│✓│✓│✓│✓│✓│✓openSUSE Leap 15.3│✓│✓│✓│✓│✓│✓openSUSE Leap 15.1│✓│✓│✓│✓│✓│✓openSUSE Leap 15.2│✓│✓│✓│✓│✓│✓openSUSE Leap 15.1│✓│✓│✓│✓│✓│✓### Oracle Linux### Oracle LinuxOracle Linux Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CECortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE Oracle 10 x86_64 ✓ ✓ ✓ ✓ ✓ ✓
From content release 1940-22526
Oracle 10 aarch64 ✓ ✓ ✓ ✓ ✓ ✓
From content release 1940-22526
Oracle 9 x86_64 — Release 9.4 and later ✓ ✓ ✓ ✓ ✓ ✓ Oracle 9 x86_64 — Release 9.3* ✓ ✓ ✓ ✓ ✓ ✓ Oracle 9 aarch64 ✓ ✓ ✓ ✓ ✓ ✓ Oracle 8 ✓ ✓ ✓ ✓ ✓ ✓ Oracle 8 aarch64 ✓ ✓ ✓ ✓ ✓ ✓ Oracle 7 ✓ ✓ ✓ ✓ ✓ ✓
Oracle Linux 6 (6.7 and above)- RHCK (kernel 2.6.32)
- UEK Release 2 (kernel 2.6.39)
- UEK Release 3 (kernel 3.8.13)
Async mode only Async mode only ✓ ✓ ✓ ✓ | ---------------------------------------------------------------------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ---------------------------------------------- |Oracle 6 (supports 6.7 and above)
Oracle Linux 6 with RHCK (kernel 2.6.32)││││││*Oracle Linux 9.3 x86_64 notes:
Oracle Linux 6 with UEK Release 2 (kernel 2.6.39)││││││
Oracle Linux 6 with UEK Release 3 (kernel 3.8.13)│Async mode only│Async mode only│✓│✓│✓│✓Oracle 7│✓│✓│✓│✓│✓│✓Oracle 8│✓│✓│✓│✓│✓│✓Oracle 8 aarch64│✓│✓│✓│✓│✓│✓Oracle 9 x86_64 — Release 9.3│✓│✓│✓│✓│✓│✓Oracle 9 x86_64 — Release 9.4 and later│✓│✓│✓│✓│✓│✓Oracle 9 aarch64│✓│✓│✓│✓│✓│✓Oracle 10 x86_64│✓│✓│✓│✓│✓│✓From content release 1940-22526
Oracle 10 aarch64│✓│✓│✓│✓│✓│✓From content release 1940-22526
#### Oracle Linux 9 x86_64 release 9.3 requirementsKernel│Support│Minimum agent versionKernel│Support│Minimum agent version| ------ | -------------- | --------------------- || ------ | -------------- | --------------------- |RHCK│User mode only│8.2RHCK│User mode only│8.2UEK│Supported│7.9-CEUEK│Supported│7.9-CE### Red Hat Enterprise Linux### Red Hat Enterprise LinuxRed Hat Enterprise Linux Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CECortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE RHEL 10 x86_64 ✓ ✓ ✓ ✓ ✓ ✓ RHEL 10 aarch64 ✓ ✓ ✓ ✓ ✓ ✓ RHEL 9* x86_64 ✓ ✓ ✓ ✓ ✓ ✓ RHEL 9* aarch64 ✓ ✓ ✓ ✓ ✓ ✓ RHEL 8 x86_64 ✓ ✓ ✓ ✓ ✓ ✓ RHEL 8 aarch64 ✓
User mode agent not supported
✓
User mode agent not supported
✓
User mode agent not supported
✓
User mode agent not supported
✓
User mode agent not supported
✓
User mode agent not supported
RHEL 7 ✓ ✓ ✓ ✓ ✓ ✓ RHEL 6 (supports 6.7 and above) Async mode only Async mode only ✓ ✓ ✓ ✓ | ----------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- |RHEL 6 (supports 6.7 and above)│Async mode only│Async mode only│✓│✓│✓│✓RHEL 7│✓│✓│✓│✓│✓│✓RHEL 8 x86_64│✓│✓│✓│✓│✓│✓RHEL 8 aarch64│✓User mode agent not supported
│✓User mode agent not supported
│✓User mode agent not supported
│✓User mode agent not supported
│✓User mode agent not supported
│✓User mode agent not supported
RHEL 9 x86_64│✓│✓│✓│✓│✓│✓RHEL 9 aarch64│✓│✓│✓│✓│✓│✓RHEL 10 x86_64│✓│✓│✓│✓│✓│✓RHEL 10 aarch64│✓│✓│✓│✓│✓│✓hint infohint info### RHEL 9 requirement### *RHEL 9 requirementRHEL 9.3 and later require agent version 8.2 or later.RHEL 9.3 and later requires Cortex XDR agent version 8.2 or later.endhintendhint### Rocky Linux### Rocky LinuxRocky Linux Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CE│Cortex XDR agent│││││| ---------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ || ---------------------- | ---------------- | --- | ------ | --- | --- | ------ |Rocky Linux 10 x86_64│✓│✓│✓│✓│✓│✓│9.3│9.2│9.1-CE│9.1│9.0│8.7-CERocky Linux 9 x86_64│✓│✓│✓│✓│✓│✓Rocky Linux 10 x86_64│✓│✓│✓│✓│✓│✓Rocky Linux 9 aarch64│✓│✓│✓│✓│✓│✓Rocky Linux 9 x86_64│✓│✓│✓│✓│✓│✓Rocky Linux 8 x86_64│✓│✓│✓│✓│✓│✓Rocky Linux 9 aarch64│✓│✓│✓│✓│✓│✓Rocky Linux 8 x86_64│✓│✓│✓│✓│✓│✓### SUSE Linux Enterprise Server### SUSE Linux Enterprise ServerSUSE Linux Enterprise Server Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CE│Cortex XDR agent│││││| --------------------------------------------- | --------------------------- | --------------------------- | ---------------------------------------------- | ---------------------------------------------- | --------------------------- | ---------------------------------------------- || ----------------- | ---------------- | --------------- | ---------------------------------------------- | ---------------------------------------------- | --- | ---------------------------------------------- |Server 16.0│✓│✓│✓From content release 2280-36261
│✓From content release 2280-36261
│—│—│9.3│9.2│9.1-CE│9.1│9.0│8.7-CEServer 15 SP7│✓│✓│✓│✓│✓│✓From content release 1940-22526
Server 16.0│✓│✓│✓From content release 2280-36261
│✓From content release 2280-36261
│—│—Server 15 SP0-SP6│✓│✓│✓│✓│✓│✓Server 15 SP7│✓│✓│✓│✓│✓│✓From content release 1940-22526
Server 12 SP4-SP5│✓│✓│✓│✓│✓│✓Server 15 SP0-SP6│✓│✓│✓│✓│✓│✓Server 11 SP4│Async mode only│Async mode only│✓│✓│✓│✓Server 12 SP4-SP5│✓│✓│✓│✓│✓│✓Server 11 SP4│Async mode only│Async mode only│✓│✓│✓│✓### Ubuntu### UbuntuUbuntu Operating System│Agent version
9.3│Agent version
9.2│Agent version
9.1-CE│Agent version
9.1│Agent version
9.0│Agent version
8.7-CECortex XDR agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE 24.04 LTS x86_64 ✓ ✓ ✓ ✓ ✓ ✓ 24.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 22.04 LTS x86_64 ✓ ✓ ✓ ✓ ✓ ✓ 22.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 20.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 20.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 18.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 18.04 LTS aarch64 ✓ ✓ ✓ ✓ ✓ ✓ 16.04 LTS ✓ ✓ ✓ ✓ ✓ ✓ 14.04 LTS Async mode only Async mode only ✓ ✓ ✓ ✓ 12.04 LTS Async mode only Async mode only ✓ ✓ ✓ ✓ | ----------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ |12.04 LTS│Async mode only│Async mode only│✓│✓│✓│✓14.04 LTS│Async mode only│Async mode only│✓│✓│✓│✓16.04 LTS│✓│✓│✓│✓│✓│✓18.04 LTS│✓│✓│✓│✓│✓│✓18.04 LTS aarch64│✓│✓│✓│✓│✓│✓20.04 LTS│✓│✓│✓│✓│✓│✓20.04 LTS aarch64│✓│✓│✓│✓│✓│✓22.04 LTS x86_64│✓│✓│✓│✓│✓│✓22.04 LTS aarch64│✓│✓│✓│✓│✓│✓24.04 LTS x86_64│✓│✓│✓│✓│✓│✓24.04 LTS aarch64│✓│✓│✓│✓│✓│✓Show markdown source
@@ -1,150 +1,107 @@ # Linux -### Supported Linux operating systems +## Supported Linux operating systems The following Linux operating systems support the Cortex XDR agent. -The Cortex XDR agent protects Linux Servers by preventing known and unknown malware from running by halting any attempts to leverage software exploits and vulnerabilities to compromise the server. Cortex XDR offers two methods for agent protection on Linux endpoints; a Kernel module and a user-mode (eBPF-based) approach. To help you choose the best deployment for your environment, see the feature differences between these two modes in the latest Cortex XDR agent Admin guide. +There are two methods for agent protection on Linux endpoints; a Kernel module and a user-mode (eBPF-based) approach. To help you choose the best deployment for your environment, see the feature differences between these two modes in the latest Cortex XDR agent Admin guide. -See the [latest Kernel Module versions](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Linux-Kernel-Versions/Latest-Kernel-Module-Version-Support) supported. +For the latest Kernel modules support see [here](https://cortex-docs.paloaltonetworks.com/linux-kernel-versions). {% hint style="info" %} ### Note Cortex XDR agent 9.1 was the last agent release supporting Linux kernels below 3.10. To avoid service disruption, hosts running kernels below 3.10 must not be upgraded beyond the 9.1 agent line. Disable auto-upgrades for endpoint profiles managing those machines, and prevent manual upgrades of the hosts to agent versions later than 9.1 {% endhint %} ### Alibaba Cloud Linux -| Alibaba Cloud Linux Operating System | Agent version 9.3 | Agent version 9.2 | Agent version 9.1-CE | Agent version 9.1 | Agent version 9.0 | | -| ------------------------------------ | ----------------- | ----------------- | -------------------- | ----------------- | ----------------- | - | -| Alibaba Cloud Linux 3 | ✓ | ✓ | ✓ | ✓ | — | — | +| | Cortex XDR agent | | | | | | +| --------------------- | ---------------- | --- | ------ | --- | --- | ------ | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| Alibaba Cloud Linux 3 | ✓ | ✓ | ✓ | ✓ | — | — | ### AlmaLinux -| AlmaLinux Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| -------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ | -| AlmaLinux 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| AlmaLinux 9 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| AlmaLinux 10 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| | Cortex XDR agent | | | | | | +| ------------ | ---------------- | --- | ------ | --- | --- | ------ | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| AlmaLinux 10 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| AlmaLinux 9 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| AlmaLinux 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ### Amazon Linux/Amazon Linux 2/Amazon Linux 2023 -<table data-header-hidden><thead><tr><th></th><th width="128"></th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td>Amazon Linux Operating System</td><td>Agent version 9.3</td><td>Agent version<br>9.2</td><td>Agent version<br>9.1-CE</td><td>Agent version<br>9.1</td><td>Agent version<br>9.0</td><td>Agent version<br>8.7-CE</td></tr><tr><td>AMI 2018.03</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Linux 2 AMI</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Linux 2 AMI (aarch64)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Linux 2023</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Linux 2023 (aarch64)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td></tr></tbody></table> +<table><thead><tr><th></th><th width="128">Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>AMI 2018.03</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Linux 2 AMI</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Linux 2 AMI (aarch64)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Linux 2023</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Amazon Linux 2023 (aarch64)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td></tr></tbody></table> ### Debian -| Debian Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| -------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ | -| Debian 9 (Stretch) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Debian 10 (Buster) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Debian 10 (Buster) aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Debian 11 (Bullseye) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Debian 12 (Bookworm) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Debian 13 (Trixie) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>Debian 13 (Trixie)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Debian 12 (Bookworm)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Debian 11 (Bullseye)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Debian 10 (Buster)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Debian 10 (Buster) aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Debian 9 (Stretch)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table> ### CentOS -| CentOS Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| --------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -| CentOS 6 (supports 6.7 and above) | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ | -| CentOS 7 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| CentOS 7.9 aarch64 | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | -| CentOS 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| CentOS 8 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| CentOS Stream 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| CentOS Stream 8 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| CentOS Stream 9 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>CentOS Stream 9</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>CentOS Stream 8</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>CentOS Stream 8 aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>CentOS 8</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>CentOS 8 aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>CentOS 7.9 aarch64</td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td></tr><tr><td>CentOS 7</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>CentOS 6<br>(6.7 and above)</td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table> ### Fedora Server -| Fedora Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| ------------------------ | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ | -| Fedora Server (USM only) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| | Cortex XDR agent | | | | | | +| ------------------------ | ---------------- | --- | ------ | --- | --- | ------ | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| Fedora Server (USM only) | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ### openSUSE -| openSUSE Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| ---------------------------- | --------------------------- | --------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | -| openSUSE Leap 16.0 (UM only) | ✓ | ✓ | <p>✓</p><p>From content release 2280-36261</p> | <p>✓</p><p>From content release 2280-36261</p> | — | — | -| openSUSE Leap 15.6 (UM only) | ✓ | ✓ | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> | -| openSUSE Leap 15.3 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| openSUSE Leap 15.2 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| openSUSE Leap 15.1 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| | Cortex XDR agent | | | | | | +| ---------------------------- | ---------------- | --- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| openSUSE Leap 16.0 (UM only) | ✓ | ✓ | <p>✓</p><p>From content release 2280-36261</p> | <p>✓</p><p>From content release 2280-36261</p> | — | — | +| openSUSE Leap 15.6 (UM only) | ✓ | ✓ | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> | <p>✓</p><p>From content release 2160-30885</p> | +| openSUSE Leap 15.3 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| openSUSE Leap 15.2 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| openSUSE Leap 15.1 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ### Oracle Linux -| Oracle Linux Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| ---------------------------------------------------------------------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ---------------------------------------------- | -| <p>Oracle 6 (supports 6.7 and above)<br><br>Oracle Linux 6 with RHCK (kernel 2.6.32)</p> | | | | | | | -| <p><br>Oracle Linux 6 with UEK Release 2 (kernel 2.6.39)</p> | | | | | | | -| <p><br>Oracle Linux 6 with UEK Release 3 (kernel 3.8.13)</p> | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ | -| Oracle 7 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Oracle 8 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Oracle 8 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Oracle 9 x86\_64 — Release 9.3 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Oracle 9 x86\_64 — Release 9.4 and later | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Oracle 9 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Oracle 10 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | <p>✓</p><p>From content release 1940-22526</p> | -| Oracle 10 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | <p>✓</p><p>From content release 1940-22526</p> | - -#### Oracle Linux 9 x86\_64 release 9.3 requirements +<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>Oracle 10 x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td><p>✓</p><p>From content release 1940-22526</p></td></tr><tr><td>Oracle 10 aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td><p>✓</p><p>From content release 1940-22526</p></td></tr><tr><td>Oracle 9 x86_64 — Release 9.4 and later</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Oracle 9 x86_64 — Release 9.3*</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Oracle 9 aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Oracle 8</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Oracle 8 aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>Oracle 7</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td><p><br>Oracle Linux 6 (6.7 and above)</p><ul><li>RHCK (kernel 2.6.32)</li><li>UEK Release 2 (kernel 2.6.39)</li><li>UEK Release 3 (kernel 3.8.13)</li></ul></td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table> + +\*Oracle Linux 9.3 x86\_64 notes: | Kernel | Support | Minimum agent version | | ------ | -------------- | --------------------- | | RHCK | User mode only | 8.2 | | UEK | Supported | 7.9-CE | ### Red Hat Enterprise Linux -| Red Hat Enterprise Linux Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| ----------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -| RHEL 6 (supports 6.7 and above) | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ | -| RHEL 7 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| RHEL 8 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| RHEL 8 aarch64 | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | <p>✓</p><p>User mode agent not supported</p> | -| RHEL 9 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| RHEL 9 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| RHEL 10 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| RHEL 10 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>RHEL 10 x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>RHEL 10 aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>RHEL 9* x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>RHEL 9* aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>RHEL 8 x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>RHEL 8 aarch64</td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td><td><p>✓</p><p>User mode agent not supported</p></td></tr><tr><td>RHEL 7</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>RHEL 6 (supports 6.7 and above)</td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table> {% hint style="info" %} -### RHEL 9 requirement +### \*RHEL 9 requirement -RHEL 9.3 and later require agent version 8.2 or later. +RHEL 9.3 and later requires Cortex XDR agent version 8.2 or later. {% endhint %} ### Rocky Linux -| Rocky Linux Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| ---------------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ | -| Rocky Linux 10 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Rocky Linux 9 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Rocky Linux 9 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Rocky Linux 8 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| | Cortex XDR agent | | | | | | +| ---------------------- | ---------------- | --- | ------ | --- | --- | ------ | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| Rocky Linux 10 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| Rocky Linux 9 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| Rocky Linux 9 aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| Rocky Linux 8 x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ### SUSE Linux Enterprise Server -| SUSE Linux Enterprise Server Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| --------------------------------------------- | --------------------------- | --------------------------- | ---------------------------------------------- | ---------------------------------------------- | --------------------------- | ---------------------------------------------- | -| Server 16.0 | ✓ | ✓ | <p>✓</p><p>From content release 2280-36261</p> | <p>✓</p><p>From content release 2280-36261</p> | — | — | -| Server 15 SP7 | ✓ | ✓ | ✓ | ✓ | ✓ | <p>✓</p><p>From content release 1940-22526</p> | -| Server 15 SP0-SP6 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Server 12 SP4-SP5 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| Server 11 SP4 | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ | +| | Cortex XDR agent | | | | | | +| ----------------- | ---------------- | --------------- | ---------------------------------------------- | ---------------------------------------------- | --- | ---------------------------------------------- | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| Server 16.0 | ✓ | ✓ | <p>✓</p><p>From content release 2280-36261</p> | <p>✓</p><p>From content release 2280-36261</p> | — | — | +| Server 15 SP7 | ✓ | ✓ | ✓ | ✓ | ✓ | <p>✓</p><p>From content release 1940-22526</p> | +| Server 15 SP0-SP6 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| Server 12 SP4-SP5 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| Server 11 SP4 | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ | ### Ubuntu -| Ubuntu Operating System | <p>Agent version<br>9.3</p> | <p>Agent version<br>9.2</p> | <p>Agent version<br>9.1-CE</p> | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.7-CE</p> | -| ----------------------- | --------------------------- | --------------------------- | ------------------------------ | --------------------------- | --------------------------- | ------------------------------ | -| 12.04 LTS | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ | -| 14.04 LTS | Async mode only | Async mode only | ✓ | ✓ | ✓ | ✓ | -| 16.04 LTS | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| 18.04 LTS | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| 18.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| 20.04 LTS | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| 20.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| 22.04 LTS x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| 22.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| 24.04 LTS x86\_64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | -| 24.04 LTS aarch64 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent</th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td></tr><tr><td>24.04 LTS x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>24.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>22.04 LTS x86_64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>22.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>20.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>20.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>18.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>18.04 LTS aarch64</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>16.04 LTS</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>14.04 LTS</td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>12.04 LTS</td><td>Async mode only</td><td>Async mode only</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table> -
▸ ▾ Mac modified +2 −2 Wording only: the FedRAMP note now reads "for Intel processors only" and the table's row label was blanked.
compatibility/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported/macRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,20 +1,20 @@# Mac# Mac### Supported Mac operating systems### Supported Mac operating systemsThe following Mac operating systems support the Cortex XDR agent.The following Mac operating systems support the Cortex XDR agent.│Cortex XDR Agent Version││││││Cortex XDR Agent Version│││││| -------------------------------- | ------------------------ | --- | ------ | --- | --- | ------ || -------------------------------- | ------------------------ | --- | ------ | --- | --- | ------ |Mac Operating System│9.3│9.2│9.1-CE│9.1│9.0│8.7-CE│9.3│9.2│9.1-CE│9.1│9.0│8.7-CEmacOS 26Tahoe
│✓│✓│✓│✓│✓│✓macOS 26Tahoe
│✓│✓│✓│✓│✓│✓macOS 15Sequoia
│✓│✓│✓│✓│✓│✓macOS 15Sequoia
│✓│✓│✓│✓│✓│✓macOS 14Sonoma
│✓│✓│✓│✓│✓│✓macOS 14Sonoma
│✓│✓│✓│✓│✓│✓macOS 13.XVentura
│—│—│✓│✓│✓│✓macOS 13.XVentura
│—│—│✓│✓│✓│✓macOS 12.XMonterey
│—│—│—│—│—│—macOS 12.XMonterey
│—│—│—│—│—│—hint infohint info### Note### NoteThe Cortex Agent for macOS is FedRamp compliant from version 7.6.0 and later, but only for Intel processors.The Cortex Agent for macOS is FedRamp compliant from version 7.6.0 and later for Intel processors only.endhintendhintShow markdown source
@@ -1,20 +1,20 @@ # Mac ### Supported Mac operating systems The following Mac operating systems support the Cortex XDR agent. | | Cortex XDR Agent Version | | | | | | | -------------------------------- | ------------------------ | --- | ------ | --- | --- | ------ | -| Mac Operating System | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | | <p>macOS 26</p><p>Tahoe</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | <p>macOS 15</p><p>Sequoia</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | <p>macOS 14</p><p>Sonoma</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | <p>macOS 13.X</p><p>Ventura</p> | — | — | ✓ | ✓ | ✓ | ✓ | | <p>macOS 12.X</p><p>Monterey</p> | — | — | — | — | — | — | {% hint style="info" %} ### Note -The Cortex Agent for macOS is FedRamp compliant from version 7.6.0 and later, but only for Intel processors. +The Cortex Agent for macOS is FedRamp compliant from version 7.6.0 and later for Intel processors only. {% endhint %} -
▸ ▾ Windows modified +15 −21 Windows 10 and 11 tables drop the empty 7.9.103-CE column; the agent release-notes link is now broken-reference.
compatibility/where-can-i-install-the-cortex-xdr-agent/endpoint-operating-systems-supported/windowsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -49,52 +49,46 @@ Cortex XDR agent 7.9 was the last version to support Windows 7. Release 7.9.103-All Windows 8 variants were supported until January 2023 (Microsoft EOL + 3 years). Release 7.9-CE, up to release 7.9.102-CE, offered support for Windows 8.1 until March 19, 2025. No new capabilities will be developed for these OS versions.All Windows 8 variants were supported until January 2023 (Microsoft EOL + 3 years). Release 7.9-CE, up to release 7.9.102-CE, offered support for Windows 8.1 until March 19, 2025. No new capabilities will be developed for these OS versions.The extended-life agent 7.9.103-CE does not support Windows 8.1The extended-life agent 7.9.103-CE does not support Windows 8.1### Windows 10### Windows 10The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.Windows 10│Cortex XDR Agent 9.3│Cortex XDR Agent 9.2│Cortex XDR Agent 9.1CE│Cortex XDR Agent 9.1│Cortex XDR Agent 9.0│Cortex XDR Agent 8.7CE│Cortex XDR Agent 7.9.103-CE│Cortex XDR Agent│││││| ---------------------------------------------------------- | -------------------- | -------------------- | ---------------------- | -------------------- | -------------------- | ---------------------- | --------------------------- || ---------------------------------------------------------- | ---------------- | --- | ------ | --- | --- | ------ |19H2, 20H1, 20H2, 21H1│—│—│—│—│—│✓││9.3│9.2│9.1-CE│9.1│9.0│8.7-CEThreshold LTSB, Redstone LTSB, Redstone 5 LTSB, 21H2, 22H2│✓│✓│✓│✓│✓│✓│19H2, 20H1, 20H2, 21H1│—│—│—│—│—│✓Windows 10 IoT Core
Windows 10 IoT Enterprise│✓│✓│✓│✓│✓│✓│Threshold LTSB, Redstone LTSB, Redstone 5 LTSB, 21H2, 22H2│✓│✓│✓│✓│✓│✓Windows 10 IoT Core
Windows 10 IoT Enterprise│✓│✓│✓│✓│✓│✓### Windows 11### Windows 11The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.Windows 11│Cortex XDR Agent 9.3│Cortex XDR Agent 9.2│Cortex XDR Agent 9.1CE│Cortex XDR Agent 9.1│Cortex XDR Agent 9.0│Cortex XDR Agent 8.7CE│Cortex XDR Agent 7.9.103-CE│Cortex XDR Agent│││││| ----------------------------- | -------------------- | -------------------- | ---------------------- | -------------------- | -------------------- | ---------------------- | --------------------------- || ----------------------------- | ---------------- | --- | ------ | --- | --- | ------ |25H2
x86_64 and ARM│✓│✓│✓│✓│✓│—││9.3│9.2│9.1-CE│9.1│9.0│8.7-CE24H2
x86_64 and ARM│✓│✓│✓│✓│✓│✓│25H2
x86_64 and ARM│✓│✓│✓│✓│✓│—23H2
x86_64 and ARM│✓│✓│✓│✓│✓│✓│24H2
x86_64 and ARM│✓│✓│✓│✓│✓│✓22H2
x86_64│✓│✓│✓│✓│✓│✓│23H2
x86_64 and ARM│✓│✓│✓│✓│✓│✓22H2
x86_64│✓│✓│✓│✓│✓│✓hint infohint info### Note### NoteWindows running on ARM is subject to certain limitations, see Known limitations in the latest Cortex XDR agent release notes.Windows running on ARM is subject to certain limitations, see Known limitations in the latest Cortex XDR agent release notes.endhintendhint### Windows Server### Windows ServerThe Datacenter edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.The Datacenter edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible.hint infohint info### Note### NoteRelease 7.9-CE, up to release 7.9.102-CE, was supported Windows Server until March 19, 2025.Release 7.9-CE, up to release 7.9.102-CE, was supported Windows Server until March 19, 2025.The extended-life agent 7.9.103-CE supports Windows Server 2008 R2 SP1 until December 31, 2027.The extended-life agent 7.9.103-CE supports Windows Server 2008 R2 SP1 until December 31, 2027.endhintendhintWindows Server│Cortex XDR Agent 9.3│Cortex XDR Agent 9.2│Cortex XDR Agent 9.1CE│Cortex XDR Agent 9.1│Cortex XDR Agent 9.0│Cortex XDR Agent 8.7CE│Cortex XDR Agent 7.9.103-CECortex XDR Agent 9.3 9.2 9.1-CE 9.1 9.0 8.7-CE 7.9.103-CE 2025 ✓ ✓ ✓ ✓ ✓ ✓ — 2022 ✓ ✓ ✓ ✓ ✓ ✓ — 2019 LTSC
2019 Core✓ ✓ ✓ ✓ ✓ ✓ — 2016 ✓ ✓ ✓ ✓ ✓ ✓ — 2012 (Support until Oct 2027)
2012 R2 (Support until Oct 2027)✓ ✓ ✓ ✓ ✓ ✓ — 2012 Core ✓ ✓ ✓ ✓ ✓ ✓ — 2008 R2 SP1 — — — — — — ✓ | ------------------------------------------------------------------------------------ | -------------------- | -------------------- | ---------------------- | -------------------- | -------------------- | ---------------------- | --------------------------- |2025│✓│✓│✓│✓│✓│✓│—2022│✓│✓│✓│✓│✓│✓│—2019 LTSC
2019 Core│✓│✓│✓│✓│✓│✓│—2016│✓│✓│✓│✓│✓│✓│—2012 (Supported until October 2027)
2012 R2 (Supported until October 2027)│✓│✓│✓│✓│✓│✓│—2012 Core│✓│✓│✓│✓│✓│✓│—2008 R2 SP1│—│—│—│—│—│—│✓Show markdown source
@@ -49,52 +49,46 @@ Cortex XDR agent 7.9 was the last version to support Windows 7. Release 7.9.103- All Windows 8 variants were supported until January 2023 (Microsoft EOL + 3 years). Release 7.9-CE, up to release 7.9.102-CE, offered support for Windows 8.1 until March 19, 2025. No new capabilities will be developed for these OS versions. The extended-life agent 7.9.103-CE does not support Windows 8.1 ### Windows 10 The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible. -| Windows 10 | Cortex XDR Agent 9.3 | Cortex XDR Agent 9.2 | Cortex XDR Agent 9.1CE | Cortex XDR Agent 9.1 | Cortex XDR Agent 9.0 | Cortex XDR Agent 8.7CE | Cortex XDR Agent 7.9.103-CE | -| ---------------------------------------------------------- | -------------------- | -------------------- | ---------------------- | -------------------- | -------------------- | ---------------------- | --------------------------- | -| 19H2, 20H1, 20H2, 21H1 | — | — | — | — | — | ✓ | | -| Threshold LTSB, Redstone LTSB, Redstone 5 LTSB, 21H2, 22H2 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | -| <p>Windows 10 IoT Core<br>Windows 10 IoT Enterprise</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | +| | Cortex XDR Agent | | | | | | +| ---------------------------------------------------------- | ---------------- | --- | ------ | --- | --- | ------ | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| 19H2, 20H1, 20H2, 21H1 | — | — | — | — | — | ✓ | +| Threshold LTSB, Redstone LTSB, Redstone 5 LTSB, 21H2, 22H2 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| <p>Windows 10 IoT Core<br>Windows 10 IoT Enterprise</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ### Windows 11 The Enterprise edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible. -| Windows 11 | Cortex XDR Agent 9.3 | Cortex XDR Agent 9.2 | Cortex XDR Agent 9.1CE | Cortex XDR Agent 9.1 | Cortex XDR Agent 9.0 | Cortex XDR Agent 8.7CE | Cortex XDR Agent 7.9.103-CE | -| ----------------------------- | -------------------- | -------------------- | ---------------------- | -------------------- | -------------------- | ---------------------- | --------------------------- | -| <p>25H2<br>x86_64 and ARM</p> | ✓ | ✓ | ✓ | ✓ | ✓ | — | | -| <p>24H2<br>x86_64 and ARM</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | -| <p>23H2<br>x86_64 and ARM</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | -| <p>22H2<br>x86_64</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | | +| | Cortex XDR Agent | | | | | | +| ----------------------------- | ---------------- | --- | ------ | --- | --- | ------ | +| | 9.3 | 9.2 | 9.1-CE | 9.1 | 9.0 | 8.7-CE | +| <p>25H2<br>x86_64 and ARM</p> | ✓ | ✓ | ✓ | ✓ | ✓ | — | +| <p>24H2<br>x86_64 and ARM</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| <p>23H2<br>x86_64 and ARM</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | +| <p>22H2<br>x86_64</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | {% hint style="info" %} ### Note -Windows running on ARM is subject to certain limitations, see Known limitations in the latest Cortex XDR agent [release notes](https://docs-cortex.paloaltonetworks.com/p/XDR-Agent). +Windows running on ARM is subject to certain limitations, see Known limitations in the latest Cortex XDR agent [release notes](broken-reference). {% endhint %} ### Windows Server The Datacenter edition is tested for compatibility. Unless specifically stated otherwise, assume that all sub-editions are also compatible. {% hint style="info" %} ### Note Release 7.9-CE, up to release 7.9.102-CE, was supported Windows Server until March 19, 2025. The extended-life agent 7.9.103-CE supports Windows Server 2008 R2 SP1 until December 31, 2027. {% endhint %} -| Windows Server | Cortex XDR Agent 9.3 | Cortex XDR Agent 9.2 | Cortex XDR Agent 9.1CE | Cortex XDR Agent 9.1 | Cortex XDR Agent 9.0 | Cortex XDR Agent 8.7CE | Cortex XDR Agent 7.9.103-CE | -| ------------------------------------------------------------------------------------ | -------------------- | -------------------- | ---------------------- | -------------------- | -------------------- | ---------------------- | --------------------------- | -| 2025 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | -| 2022 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | -| <p>2019 LTSC<br>2019 Core</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | -| 2016 | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | -| <p>2012 (Supported until October 2027)<br>2012 R2 (Supported until October 2027)</p> | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | -| 2012 Core | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — | -| 2008 R2 SP1 | — | — | — | — | — | — | ✓ | +<table data-search="false"><thead><tr><th></th><th>Cortex XDR Agent</th><th></th><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.3</td><td>9.2</td><td>9.1-CE</td><td>9.1</td><td>9.0</td><td>8.7-CE</td><td>7.9.103-CE</td></tr><tr><td>2025</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td></tr><tr><td>2022</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td></tr><tr><td>2019 LTSC<br>2019 Core</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td></tr><tr><td>2016</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td></tr><tr><td>2012 (Support until Oct 2027)<br>2012 R2 (Support until Oct 2027)</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td></tr><tr><td>2012 Core</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td><td>—</td></tr><tr><td>2008 R2 SP1</td><td>—</td><td>—</td><td>—</td><td>—</td><td>—</td><td>—</td><td>✓</td></tr></tbody></table> -
▸ ▾ Kubernetes platforms supported modified +4 −21 Platform table re-emitted as HTML with sub-OS rows nested, and the admin-guide link now points at an app.gitbook.com authoring URL.
compatibility/where-can-i-install-the-cortex-xdr-agent/kubernetes-platforms-supportedRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,34 +1,17 @@# Kubernetes platforms supported# Kubernetes platforms supportedView the Kubernetes platforms that are supported with Cortex XDR agents.View the Kubernetes platforms that are supported with Cortex XDR agents.### Supported Kubernetes platformsThis table shows the Kubernetes platform versions that have been compatibility tested. The table shows the latest version that has been tested. All versions that are not EOL, up to the latest version tested for compatibility are supported.This table shows the Kubernetes platform versions that have been compatibility tested. The table shows the latest version that has been tested. All versions that are not EOL, up to the latest version tested for compatibility in the table below are supported.For installation instructions refer to Cortex XDR Agent for Linux → Install the Cortex XDR Agent for Kubernetes Hosts in the latest Cortex XDR agent admin guide.For installation instructions refer to Cortex XDR Agent for Linux → Install the Cortex XDR Agent for Kubernetes Hosts in the latest Cortex XDR agent admin guide.Linux Kubernetes Platform Version Unmanaged Kubernetes (k8s) 1.30 Amazon Elastic Kubernetes Service (EKS)
- BottleRocket OS x86_64
User mode agent only - BottleRocket OS aarch64
User mode agent only
1.35 Microsoft Azure Kubernetes Service (AKS)
- CBL-mariner 2 x86_64
1.35 Google Kubernetes Engine (GKE)
- Google Container-Optimized OS (COS)* x86_64
User mode agent only - Google Kubernetes Engine (GKE) Autopilot
1.35 Oracle Kubernetes Engine (OKE) 1.33 Red Hat Openshift Container Platform (OCP)
- RHCOS* x86_64
User mode agent only
4.18
4.19 in agent versions 9.1.1 and later
4.20 in agent versions 9.1.1 and later
SUSE Rancher Kubernetes Engine 2 (RKE2) 1.28 Talos 1.8.3 Linux Kubernetes Platform│Version| --------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |Unmanaged Kubernetes (k8s)│1.30Amazon Elastic Kubernetes Service (EKS)│1.35↳ BottleRocket OS x86_64User mode agent only
│↳ BottleRocket OS aarch64User mode agent only
│Microsoft Azure Kubernetes Service (AKS)│1.35↳ CBL-mariner 2 x86_64│Google Kubernetes Engine (GKE)│1.35↳ Google Container-Optimized OS (COS)* x86_64User mode agent only
│↳ Google Kubernetes Engine (GKE) Autopilot│Oracle Kubernetes Engine (OKE)│1.33Red Hat Openshift Container Platform (OCP)│4.184.19 in agent versions 9.1.1 and later
4.20 in agent versions 9.1.1 and later
↳ RHCOS* x86_64User mode agent only
│SUSE Rancher Kubernetes Engine 2 (RKE2)│1.28Talos│1.8.3hint infohint info### Note### NotesIn Google Container-Optimized OS release 100 and earlier, where the FANOTIFY EXEC flag is not supported, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.In Google Container-Optimized OS release 100 and earlier, where the FANOTIFY EXEC flag is not supported, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.In RHCOS version 4.12 and earlier, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.In RHCOS version 4.12 and earlier, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode.endhintendhintShow markdown source
@@ -1,34 +1,17 @@ # Kubernetes platforms supported View the Kubernetes platforms that are supported with Cortex XDR agents. -### Supported Kubernetes platforms +This table shows the Kubernetes platform versions that have been compatibility tested. The table shows the latest version that has been tested. All versions that are not EOL, up to the latest version tested for compatibility are supported. -This table shows the Kubernetes platform versions that have been compatibility tested. The table shows the latest version that has been tested. All versions that are not EOL, up to the latest version tested for compatibility in the table below are supported. +For installation instructions refer to Cortex XDR Agent for Linux → Install the Cortex XDR Agent for Kubernetes Hosts in the latest [Cortex XDR agent admin guide](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/YhAQu4OiCd3X2NZv62G3/). -For installation instructions refer to Cortex XDR Agent for Linux → Install the Cortex XDR Agent for Kubernetes Hosts in the latest [Cortex XDR agent admin guide](broken-reference). - -| Linux Kubernetes Platform | Version | -| --------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- | -| Unmanaged Kubernetes (k8s) | 1.30 | -| Amazon Elastic Kubernetes Service (EKS) | 1.35 | -| <p> ↳ BottleRocket OS x86_64</p><p> User mode agent only</p> | | -| <p> ↳ BottleRocket OS aarch64</p><p> User mode agent only</p> | | -| Microsoft Azure Kubernetes Service (AKS) | 1.35 | -| ↳ CBL-mariner 2 x86\_64 | | -| Google Kubernetes Engine (GKE) | 1.35 | -| <p> ↳ Google Container-Optimized OS (COS)<sup>*</sup> x86_64</p><p> User mode agent only</p> | | -| ↳ Google Kubernetes Engine (GKE) Autopilot | | -| Oracle Kubernetes Engine (OKE) | 1.33 | -| Red Hat Openshift Container Platform (OCP) | <p>4.18</p><p>4.19 in agent versions 9.1.1 and later</p><p>4.20 in agent versions 9.1.1 and later</p> | -| <p> ↳ RHCOS<sup>*</sup> x86_64</p><p> User mode agent only</p> | | -| SUSE Rancher Kubernetes Engine 2 (RKE2) | 1.28 | -| Talos | 1.8.3 | +<table data-search="false"><thead><tr><th width="411.5">Linux Kubernetes Platform</th><th>Version</th></tr></thead><tbody><tr><td>Unmanaged Kubernetes (k8s)</td><td>1.30</td></tr><tr><td><p>Amazon Elastic Kubernetes Service (EKS)</p><ul><li>BottleRocket OS x86_64<br>User mode agent only</li><li>BottleRocket OS aarch64<br>User mode agent only</li></ul></td><td>1.35</td></tr><tr><td><p>Microsoft Azure Kubernetes Service (AKS)</p><ul><li>CBL-mariner 2 x86_64</li></ul></td><td>1.35</td></tr><tr><td><p>Google Kubernetes Engine (GKE)</p><ul><li>Google Container-Optimized OS (COS)<sup>*</sup> x86_64<br>User mode agent only</li><li>Google Kubernetes Engine (GKE) Autopilot</li></ul></td><td>1.35</td></tr><tr><td>Oracle Kubernetes Engine (OKE)</td><td>1.33</td></tr><tr><td><p>Red Hat Openshift Container Platform (OCP)</p><ul><li>RHCOS<sup>*</sup> x86_64<br>User mode agent only</li></ul></td><td><p>4.18</p><p>4.19 in agent versions 9.1.1 and later</p><p>4.20 in agent versions 9.1.1 and later</p></td></tr><tr><td>SUSE Rancher Kubernetes Engine 2 (RKE2)</td><td>1.28</td></tr><tr><td>Talos</td><td>1.8.3</td></tr></tbody></table> {% hint style="info" %} -### Note +### Notes In Google Container-Optimized OS release 100 and earlier, where the FANOTIFY EXEC flag is not supported, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode. In RHCOS version 4.12 and earlier, the Kernel configuration may be partial for the user mode agent to properly function. In such cases, the agent will fallback to asynchronous mode. {% endhint %} - BottleRocket OS x86_64
-
▸ ▾ Mobile operating systems supported with Cortex XDR modified +19 −0 Absorbs the Android and iOS/iPadOS tables, including the note that SMS filtering and call blocking work only on iPhones.
compatibility/where-can-i-install-the-cortex-xdr-agent/mobile-operating-systems-supported-with-cortex-xdrRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,3 +1,22 @@# Mobile operating systems supported with Cortex XDR# Mobile operating systems supported with Cortex XDRThe following tables show the mobile operating systems on which you can install each release of the agent. You can install the Cortex XDR agent on Android and iOS, mobile phones and tablets.The following tables show the mobile operating systems on which you can install each release of the agent. You can install the Cortex XDR agent on Android and iOS, mobile phones and tablets.### AndroidCortex XDR agent for Android 9.1 9.0 8.9 8.8 26 ✓ ✓ — — 16 ✓ ✓ — — 15 ✓ ✓ ✓ ✓ 14 ✓ ✓ ✓ ✓ 13 ✓ ✓ ✓ ✓ 12 ✓ ✓ ✓ ✓ 11 ✓ ✓ ✓ ✓ 10 ✓ ✓ ✓ ✓ 9 ✓ ✓ ✓ ✓ 8 ✓ ✓ ✓ ✓ ### iOS/iPadOShint info### NoteThe SMS filtering and call blocking features offered by Cortex XDR are available only in iPhones. iPads do not support SMS messaging or cellular-based telephony, even when fitted with a SIM card.endhint│Cortex XDR agent for iOS│││| -------------- | ------------------------ | --- | --- | --- |│9.1│9.0│8.9│8.826│✓│✓│—│—16.0 and later│✓│✓│✓│✓15.0 and later│—│—│—│—Show markdown source
@@ -1,3 +1,22 @@ # Mobile operating systems supported with Cortex XDR The following tables show the mobile operating systems on which you can install each release of the agent. You can install the Cortex XDR agent on Android and iOS, mobile phones and tablets. + +### Android + +<table data-search="false"><thead><tr><th></th><th>Cortex XDR agent for Android</th><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td>9.1</td><td>9.0</td><td>8.9</td><td>8.8</td></tr><tr><td>26</td><td>✓</td><td>✓</td><td>—</td><td>—</td></tr><tr><td>16</td><td>✓</td><td>✓</td><td>—</td><td>—</td></tr><tr><td>15</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>14</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>13</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>12</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>11</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>10</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>9</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr><tr><td>8</td><td>✓</td><td>✓</td><td>✓</td><td>✓</td></tr></tbody></table> + +### iOS/iPadOS + +{% hint style="info" %} +### Note + +The SMS filtering and call blocking features offered by Cortex XDR are available only in iPhones. iPads do not support SMS messaging or cellular-based telephony, even when fitted with a SIM card. +{% endhint %} + +| | Cortex XDR agent for iOS | | | | +| -------------- | ------------------------ | --- | --- | --- | +| | 9.1 | 9.0 | 8.9 | 8.8 | +| 26 | ✓ | ✓ | — | — | +| 16.0 and later | ✓ | ✓ | ✓ | ✓ | +| 15.0 and later | — | — | — | — | -
▸ ▾ Android deleted +0 −16 Deleted; its agent 9.1-8.8 support table now sits on the parent mobile page.
compatibility/where-can-i-install-the-cortex-xdr-agent/mobile-operating-systems-supported-with-cortex-xdr/androidRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗
Before After@@ -1,16 +0,0 @@# Android### Cortex XDR Mobile Agent VersionAndroid│Agent version
9.1│Agent version
9.0│Agent version
8.9│Agent version
8.8| ------- | --------------------------- | --------------------------- | --------------------------- | --------------------------- |26│✓│✓│—│—16│✓│✓│—│—15│✓│✓│✓│✓14│✓│✓│✓│✓13│✓│✓│✓│✓12│✓│✓│✓│✓11│✓│✓│✓│✓10│✓│✓│✓│✓9│✓│✓│✓│✓8│✓│✓│✓│✓Show markdown source
@@ -1,16 +0,0 @@ -# Android - -### Cortex XDR Mobile Agent Version - -| Android | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.9</p> | <p>Agent version<br>8.8</p> | -| ------- | --------------------------- | --------------------------- | --------------------------- | --------------------------- | -| 26 | ✓ | ✓ | — | — | -| 16 | ✓ | ✓ | — | — | -| 15 | ✓ | ✓ | ✓ | ✓ | -| 14 | ✓ | ✓ | ✓ | ✓ | -| 13 | ✓ | ✓ | ✓ | ✓ | -| 12 | ✓ | ✓ | ✓ | ✓ | -| 11 | ✓ | ✓ | ✓ | ✓ | -| 10 | ✓ | ✓ | ✓ | ✓ | -| 9 | ✓ | ✓ | ✓ | ✓ | -| 8 | ✓ | ✓ | ✓ | ✓ |
-
▸ ▾ iOS/iPadOS deleted +0 −15 Deleted; its agent 9.1-8.8 support table and iPhone-only note now sit on the parent mobile page.
compatibility/where-can-i-install-the-cortex-xdr-agent/mobile-operating-systems-supported-with-cortex-xdr/ios-ipadosRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗
Before After@@ -1,15 +0,0 @@# iOS/iPadOShint info### NoteThe SMS filtering and call blocking features offered by Cortex XDR are available only in iPhones. iPads do not support SMS messaging or cellular-based telephony, even when fitted with a SIM card.endhint### Cortex XDR iOS Agent VersioniOS/iPadOS│Agent version
9.1│Agent version
9.0│Agent version
8.9│Agent version
8.8| -------------- | --------------------------- | --------------------------- | --------------------------- | --------------------------- |26│✓│✓│—│—16.0 and later│✓│✓│✓│✓15.0 and later│—│—│—│—Show markdown source
@@ -1,15 +0,0 @@ -# iOS/iPadOS - -{% hint style="info" %} -### Note - -The SMS filtering and call blocking features offered by Cortex XDR are available only in iPhones. iPads do not support SMS messaging or cellular-based telephony, even when fitted with a SIM card. -{% endhint %} - -### Cortex XDR iOS Agent Version - -| iOS/iPadOS | <p>Agent version<br>9.1</p> | <p>Agent version<br>9.0</p> | <p>Agent version<br>8.9</p> | <p>Agent version<br>8.8</p> | -| -------------- | --------------------------- | --------------------------- | --------------------------- | --------------------------- | -| 26 | ✓ | ✓ | — | — | -| 16.0 and later | ✓ | ✓ | ✓ | ✓ | -| 15.0 and later | — | — | — | — | -
▸ ▾ Cortex XSIAM and AWS audit log collection architecture modified +7 −7 Bucket lifecycle and retention are now described as customer-managed for custom Control Tower collection as well as BYOB.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/cortex-cloud-and-aws-audit-log-collection-architectureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -20,28 +20,28 @@ The following stages describe the event-driven ingestion flow for CloudTrail log6. Cortex extracts the S3 path from the SQS message and downloads the specific log files using s3:GetObject.6. Cortex extracts the S3 path from the SQS message and downloads the specific log files using s3:GetObject.7. Cortex decrypts the logs using the KMS key. The gzip-compressed content is then decompressed.7. Cortex decrypts the logs using the KMS key. The gzip-compressed content is then decompressed.8. Cortex forwards the processed logs to your dedicated Cortex single tenant (GCS bucket).8. Cortex forwards the processed logs to your dedicated Cortex single tenant (GCS bucket).9. Cortex deletes the processed SQS message using sqs:DeleteMessage.9. Cortex deletes the processed SQS message using sqs:DeleteMessage.10. The Cortex XSIAM instance processes the logs for security analysis.10. The Cortex XSIAM instance processes the logs for security analysis.### Data security for audit logs### Data security for audit logsIn automated log collection mode, CloudTrail logs are retained in the S3 bucket for seven days (per the bucket's lifecycle expiration rule), and then automatically deleted. In custom (BYOB) log collection mode, you manage the S3 bucket lifecycle and retention. In both modes, forwarded log files are stored in your dedicated single-tenant Cortex XSIAM log storage bucket. CloudTrail log files at rest in the customer's S3 bucket are encrypted using the CloudTrail logs CMK (a customer-managed KMS key in your AWS account).In automated log collection mode, CloudTrail logs are retained in the S3 bucket for seven days (per the bucket's lifecycle expiration rule), and then automatically deleted. In custom (BYOB) and custom Control Tower log collection mode, you manage the S3 bucket lifecycle and retention. In all modes, forwarded log files are stored in your dedicated single-tenant Cortex XSIAM log storage bucket. CloudTrail log files at rest in the customer's S3 bucket are encrypted using the CloudTrail logs CMK (a customer-managed KMS key in your AWS account).### Key Management Service (KMS) considerations### Key Management Service (KMS) considerationsCloudTrail log files are encrypted at rest in the customer's S3 bucket. How the KMS key is provisioned depends on the deployment mode:CloudTrail log files are encrypted at rest in the customer's S3 bucket. How the KMS key is provisioned depends on the deployment mode:Aspect│Automated log collection│Custom (BYOB) log collection│Custom Control Tower log collectionAspect│Automated log collection│Custom (BYOB) log collection│Custom Control Tower log collection| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |KMS key creation│Cortex XSIAM creates a new Customer Managed Key (CMK) via CloudFormation.│No KMS key is created. The customer supplies the optionalCloudTrailKmsArnparameter at deployment time.│No KMS key is created. The customer supplies the optionalCloudTrailKmsArnparameter at deployment time.KMS key creation│Cortex XSIAM creates a new Customer Managed Key (CMK) via CloudFormation.│No KMS key is created. The customer supplies the optionalCloudTrailKmsArnparameter at deployment time.│No KMS key is created. The customer supplies the optionalCloudTrailKmsArnparameter at deployment time.Key policy│The Cortex XSIAM-created CMK uses the standard account-root key policy, which delegates access management to IAM. TheCloudTrailReadRolerole's inline IAM policy (provisioned by the same template) grantskms:Decrypton the CMK, so no customer key-policy edits are required.│The customer's KMS key policy must explicitly allow theCloudTrailReadRolerole to performkms:Decrypt.│The KMS key used by Control Tower resides in the management account, while the Cortex IAM role is deployed into the logging account. Because the key and the role are in different accounts, the KMS key policy in the management account must explicitly allow thecortex-logs-ingestion-access-<resource-suffix>role (in the logging account) to performkms:Decrypt. See Grant cross-account KMS key access.Key policy│The Cortex XSIAM-created CMK uses the standard account-root key policy, which delegates access management to IAM. TheCloudTrailReadRolerole's inline IAM policy (provisioned by the same template) grantskms:Decrypton the CMK, so no customer key-policy edits are required.│The customer's KMS key policy must explicitly allow theCloudTrailReadRolerole to performkms:Decrypt.│The KMS key used by Control Tower resides in the management account, while the Cortex IAM role is deployed into the logging account. Because the key and the role are in different accounts, the KMS key policy in the management account must explicitly allow theCloudTrailReadRolerole (in the logging account) to performkms:Decrypt. See Grant cross-account KMS key access.Role permission│The audit log reader role inline policy includeskms:Decrypton the Cortex XSIAM-created CMK.│IfCloudTrailKmsArnis provided, the role inline policy includeskms:Decryptscoped to that ARN. If left empty, thekms:Decryptstatement is omitted entirely.│IfCloudTrailKmsArnis provided, the role inline policy includeskms:Decryptscoped to that ARN. If left empty, thekms:Decryptstatement is omitted entirely.Role permission│The audit log reader role inline policy includeskms:Decrypton the Cortex XSIAM-created CMK.│IfCloudTrailKmsArnis provided, the role inline policy includeskms:Decryptscoped to that ARN. If left empty, thekms:Decryptstatement is omitted entirely.│IfCloudTrailKmsArnis provided, the role inline policy includeskms:Decryptscoped to that ARN. If left empty, thekms:Decryptstatement is omitted entirely.Unencrypted/SSE-S3 buckets│Not applicable (Cortex XSIAM always creates an encrypted bucket).│If the bucket uses SSE-S3 or no encryption, leave theCloudTrailKmsArnparameter empty.│If the bucket uses SSE-S3 or no encryption, leave theCloudTrailKmsArnparameter empty.Unencrypted/SSE-S3 buckets│Not applicable (Cortex XSIAM always creates an encrypted bucket).│If the bucket uses SSE-S3 or no encryption, leave theCloudTrailKmsArnparameter empty.│If the bucket uses SSE-S3 or no encryption, leave theCloudTrailKmsArnparameter empty.You must use a customer-managed KMS key (CMK), not an AWS-managed or AWS-owned key. CloudTrail requires a symmetric CMK for trail encryption, and the audit log reader role must be granted kms:Decrypt through the key policy, which is only configurable on customer-managed keys.You must use a customer-managed KMS key (CMK), not an AWS-managed or AWS-owned key. CloudTrail requires a symmetric CMK for trail encryption, and the audit log reader role must be granted kms:Decrypt through the key policy, which is only configurable on customer-managed keys.hint infohint info#### Note: Custom Control Tower (BYOB) log collection with KMS encryption#### Note: Custom Control Tower (BYOB) log collection with KMS encryptionIf you provide aCloudTrailKmsArnand the KMS key resides in a different account than the Log Archive account, a manual step is required. The Cortex CloudFormation template automatically grantskms:Decryptto thecortex-logs-ingestion-access-<resource-suffix>role on the IAM side, but AWS also requires the KMS key resource policy to explicitly allow access from the Log Archive account. You must manually add this statement to the KMS key policy to complete the cross-account handshake. For the full procedure, see grant-cross-account-kms-key-access-for-control-tower-byob-log-collection.If you provide aCloudTrailKmsArnand the KMS key resides in a different account than the Log Archive account, a manual step is required. The Cortex CloudFormation template automatically grantskms:Decryptto thecortex-logs-ingestion-access-<resource-suffix>role on the IAM side, but AWS also requires the KMS key resource policy to explicitly allow access from the Log Archive account. You must manually add this statement to the KMS key policy to complete the cross-account handshake. For the full procedure, see grant-cross-account-kms-key-access-for-control-tower-byob-log-collection.endhintendhintShow markdown source
@@ -20,28 +20,28 @@ The following stages describe the event-driven ingestion flow for CloudTrail log 6. Cortex extracts the S3 path from the SQS message and downloads the specific log files using **s3:GetObject**. 7. Cortex decrypts the logs using the KMS key. The gzip-compressed content is then decompressed. 8. Cortex forwards the processed logs to your dedicated Cortex single tenant (GCS bucket). 9. Cortex deletes the processed SQS message using **sqs:DeleteMessage**. 10. The Cortex XSIAM instance processes the logs for security analysis. ### **Data security for audit logs** -In automated log collection mode, CloudTrail logs are retained in the S3 bucket for seven days (per the bucket's lifecycle expiration rule), and then automatically deleted. In custom (BYOB) log collection mode, you manage the S3 bucket lifecycle and retention. In both modes, forwarded log files are stored in your dedicated single-tenant Cortex XSIAM log storage bucket. CloudTrail log files at rest in the customer's S3 bucket are encrypted using the CloudTrail logs CMK (a customer-managed KMS key in your AWS account). +In automated log collection mode, CloudTrail logs are retained in the S3 bucket for seven days (per the bucket's lifecycle expiration rule), and then automatically deleted. In custom (BYOB) and custom Control Tower log collection mode, you manage the S3 bucket lifecycle and retention. In all modes, forwarded log files are stored in your dedicated single-tenant Cortex XSIAM log storage bucket. CloudTrail log files at rest in the customer's S3 bucket are encrypted using the CloudTrail logs CMK (a customer-managed KMS key in your AWS account). ### **Key Management Service (KMS) considerations** CloudTrail log files are encrypted at rest in the customer's S3 bucket. How the KMS key is provisioned depends on the deployment mode: -| Aspect | Automated log collection | Custom (BYOB) log collection | Custom Control Tower log collection | -| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| KMS key creation | Cortex XSIAM creates a new Customer Managed Key (CMK) via CloudFormation. | No KMS key is created. The customer supplies the optional `CloudTrailKmsArn` parameter at deployment time. | No KMS key is created. The customer supplies the optional `CloudTrailKmsArn` parameter at deployment time. | -| Key policy | The Cortex XSIAM-created CMK uses the standard account-root key policy, which delegates access management to IAM. The `CloudTrailReadRole` role's inline IAM policy (provisioned by the same template) grants `kms:Decrypt` on the CMK, so no customer key-policy edits are required. | The customer's KMS key policy must explicitly allow the `CloudTrailReadRole` role to perform `kms:Decrypt`. | The KMS key used by Control Tower resides in the management account, while the Cortex IAM role is deployed into the logging account. Because the key and the role are in different accounts, the KMS key policy in the management account must explicitly allow the `cortex-logs-ingestion-access-<resource-suffix>` role (in the logging account) to perform `kms:Decrypt`. See [Grant cross-account KMS key access](grant-cross-account-kms-key-access-for-control-tower-byob-log-collection). | -| Role permission | The audit log reader role inline policy includes `kms:Decrypt` on the Cortex XSIAM-created CMK. | If `CloudTrailKmsArn` is provided, the role inline policy includes `kms:Decrypt` scoped to that ARN. If left empty, the `kms:Decrypt` statement is omitted entirely. | If `CloudTrailKmsArn` is provided, the role inline policy includes `kms:Decrypt` scoped to that ARN. If left empty, the `kms:Decrypt` statement is omitted entirely. | -| Unencrypted/SSE-S3 buckets | Not applicable (Cortex XSIAM always creates an encrypted bucket). | If the bucket uses SSE-S3 or no encryption, leave the `CloudTrailKmsArn` parameter empty. | If the bucket uses SSE-S3 or no encryption, leave the `CloudTrailKmsArn` parameter empty. | +| Aspect | Automated log collection | Custom (BYOB) log collection | Custom Control Tower log collection | +| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| KMS key creation | Cortex XSIAM creates a new Customer Managed Key (CMK) via CloudFormation. | No KMS key is created. The customer supplies the optional `CloudTrailKmsArn` parameter at deployment time. | No KMS key is created. The customer supplies the optional `CloudTrailKmsArn` parameter at deployment time. | +| Key policy | The Cortex XSIAM-created CMK uses the standard account-root key policy, which delegates access management to IAM. The `CloudTrailReadRole` role's inline IAM policy (provisioned by the same template) grants `kms:Decrypt` on the CMK, so no customer key-policy edits are required. | The customer's KMS key policy must explicitly allow the `CloudTrailReadRole` role to perform `kms:Decrypt`. | The KMS key used by Control Tower resides in the management account, while the Cortex IAM role is deployed into the logging account. Because the key and the role are in different accounts, the KMS key policy in the management account must explicitly allow the `CloudTrailReadRole` role (in the logging account) to perform `kms:Decrypt`. See [Grant cross-account KMS key access](grant-cross-account-kms-key-access-for-control-tower-byob-log-collection). | +| Role permission | The audit log reader role inline policy includes `kms:Decrypt` on the Cortex XSIAM-created CMK. | If `CloudTrailKmsArn` is provided, the role inline policy includes `kms:Decrypt` scoped to that ARN. If left empty, the `kms:Decrypt` statement is omitted entirely. | If `CloudTrailKmsArn` is provided, the role inline policy includes `kms:Decrypt` scoped to that ARN. If left empty, the `kms:Decrypt` statement is omitted entirely. | +| Unencrypted/SSE-S3 buckets | Not applicable (Cortex XSIAM always creates an encrypted bucket). | If the bucket uses SSE-S3 or no encryption, leave the `CloudTrailKmsArn` parameter empty. | If the bucket uses SSE-S3 or no encryption, leave the `CloudTrailKmsArn` parameter empty. | You must use a customer-managed KMS key (CMK), not an AWS-managed or AWS-owned key. CloudTrail requires a symmetric CMK for trail encryption, and the audit log reader role must be granted kms:Decrypt through the key policy, which is only configurable on customer-managed keys. {% hint style="info" %} #### Note: Custom Control Tower (BYOB) log collection with KMS encryption If you provide a `CloudTrailKmsArn` and the KMS key resides in a different account than the Log Archive account, a manual step is required. The Cortex CloudFormation template automatically grants `kms:Decrypt` to the `cortex-logs-ingestion-access-<resource-suffix>` role on the IAM side, but AWS also requires the KMS key resource policy to explicitly allow access from the Log Archive account. You must manually add this statement to the KMS key policy to complete the cross-account handshake. For the full procedure, see [grant-cross-account-kms-key-access-for-control-tower-byob-log-collection](grant-cross-account-kms-key-access-for-control-tower-byob-log-collection "mention"). {% endhint %} -
▸ ▾ Deploy the authentication template in AWS modified +2 −1 Adds the LoggingAccountOuId CloudFormation parameter for the OU holding the Log Archive account.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/deploy-the-authentication-template-in-awsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -18,17 +18,18 @@ When you select to manually deploy the authentication template, you must connect4. In Specify template, select Upload a template file, then click Choose file and upload the template downloaded from Cortex XSIAM. Click Next.4. In Specify template, select Upload a template file, then click Choose file and upload the template downloaded from Cortex XSIAM. Click Next.5. In the Specify stack details page, enter a Stack name.5. In the Specify stack details page, enter a Stack name.6. In Parameters, review the values pre-populated by Cortex XSIAM: ExternalID, OutpostRoleArn, and CortexPlatformRoleName. If you have enabled custom Control Tower audit log collection, the following pre-populated values are also displayed: SqsQueueName and CloudTrailReadRoleName. Do not change these values. The ExternalID is unique to your Cortex XSIAM tenant and acts as a shared secret in the role's trust policy. Replacing it will prevent Cortex XSIAM from assuming the role.6. In Parameters, review the values pre-populated by Cortex XSIAM: ExternalID, OutpostRoleArn, and CortexPlatformRoleName. If you have enabled custom Control Tower audit log collection, the following pre-populated values are also displayed: SqsQueueName and CloudTrailReadRoleName. Do not change these values. The ExternalID is unique to your Cortex XSIAM tenant and acts as a shared secret in the role's trust policy. Replacing it will prevent Cortex XSIAM from assuming the role.7. In Parameters, if you have enabled custom log collection, enter the following details:7. In Parameters, if you have enabled custom log collection, enter the following details:•CloudTrailKmsArn: (Optional) The ARN of the AWS KMS key used to encrypt the CloudTrail log files, if using.•CloudTrailKmsArn: (Optional) The ARN of the AWS KMS key used to encrypt the CloudTrail log files, if using.•CloudTrailLogBucket: The name of the Amazon S3 bucket where CloudTrail stores the log files.•CloudTrailLogBucket: The name of the Amazon S3 bucket where CloudTrail stores the log files.•CloudTrailSnsArn: The ARN of the Amazon SNS topic that CloudTrail uses to send notifications when new log files are delivered.•CloudTrailSnsArn: The ARN of the Amazon SNS topic that CloudTrail uses to send notifications when new log files are delivered.•LoggingAccountId: (Only for custom Control Tower BYOB) The AWS Account ID of the dedicated AWS Control Tower logging account where the centralized S3 bucket resides.•LoggingAccountId: (Only for custom Control Tower BYOB) The AWS Account ID of the dedicated AWS Control Tower logging account where the centralized S3 bucket resides.•SnsTopicOuId: (Only for custom Control Tower BYOB) OU containing the SNS topic account (whereaws-controltower-AllConfigNotificationsresides).•SnsTopicOuId: (Only for custom Control Tower BYOB) OU containing the SNS topic account.•LoggingAccountOuId: (Only for custom Control Tower BYOB) OU containing the Log Archive account.•OrganizationalUnitId: (Only for organization or organizational unit scope) Organizational root ID.•OrganizationalUnitId: (Only for organization or organizational unit scope) Organizational root ID.8. Click Next and Next again.8. Click Next and Next again.9. In Review, in the Capabilities section, acknowledge that CloudFormation might create IAM resources with custom names and click Submit. (This is required because the template creates the IAM roles Cortex XSIAM uses to access your account.) The stack is complete when it appears in the Stacks list with status of CREATE_COMPLETE.9. In Review, in the Capabilities section, acknowledge that CloudFormation might create IAM resources with custom names and click Submit. (This is required because the template creates the IAM roles Cortex XSIAM uses to access your account.) The stack is complete when it appears in the Stacks list with status of CREATE_COMPLETE.When the template is successfully uploaded to AWS and the stack creation is complete, a Lambda function notifies Cortex XSIAM and the cloud instance will appear as Connected. The initial discovery scan is then started. When the scan is complete, you can view the discovered assets in Asset Inventory.When the template is successfully uploaded to AWS and the stack creation is complete, a Lambda function notifies Cortex XSIAM and the cloud instance will appear as Connected. The initial discovery scan is then started. When the scan is complete, you can view the discovered assets in Asset Inventory.endtabendtabtab Terraformtab TerraformShow markdown source
@@ -18,17 +18,18 @@ When you select to manually deploy the authentication template, you must connect 4. In **Specify template**, select **Upload a template file**, then click **Choose file** and upload the template downloaded from Cortex XSIAM. Click **Next**. 5. In the **Specify stack details** page, enter a **Stack name**. 6. In **Parameters**, review the values pre-populated by Cortex XSIAM: **ExternalID**, **OutpostRoleArn**, and **CortexPlatformRoleName**. If you have enabled custom Control Tower audit log collection, the following pre-populated values are also displayed: **SqsQueueName** and **CloudTrailReadRoleName**. Do not change these values. The **ExternalID** is unique to your Cortex XSIAM tenant and acts as a shared secret in the role's trust policy. Replacing it will prevent Cortex XSIAM from assuming the role. 7. In **Parameters**, if you have enabled custom log collection, enter the following details: * `CloudTrailKmsArn`**:** (Optional) The ARN of the AWS KMS key used to encrypt the CloudTrail log files, if using. * `CloudTrailLogBucket`**:** The name of the Amazon S3 bucket where CloudTrail stores the log files. * `CloudTrailSnsArn`**:** The ARN of the Amazon SNS topic that CloudTrail uses to send notifications when new log files are delivered. * `LoggingAccountId`: (Only for custom Control Tower BYOB) The AWS Account ID of the dedicated AWS Control Tower logging account where the centralized S3 bucket resides. - * `SnsTopicOuId`: (Only for custom Control Tower BYOB) OU containing the SNS topic account (where `aws-controltower-AllConfigNotifications` resides). + * `SnsTopicOuId`: (Only for custom Control Tower BYOB) OU containing the SNS topic account. + * `LoggingAccountOuId`: (Only for custom Control Tower BYOB) OU containing the Log Archive account. * `OrganizationalUnitId`: (Only for organization or organizational unit scope) Organizational root ID. 8. Click **Next** and **Next** again. 9. In **Review**, in the **Capabilities** section, acknowledge that CloudFormation might create IAM resources with custom names and click Submit. (This is required because the template creates the IAM roles Cortex XSIAM uses to access your account.) The stack is complete when it appears in the Stacks list with status of **CREATE\_COMPLETE**. When the template is successfully uploaded to AWS and the stack creation is complete, a Lambda function notifies Cortex XSIAM and the cloud instance will appear as **Connected**. The initial discovery scan is then started. When the scan is complete, you can view the discovered assets in **Asset Inventory**. {% endtab %} {% tab title="Terraform" %} -
▸ ▾ Grant cross-account KMS key access for Control Tower BYOB log collection modified +4 −4 The cross-account role is now CloudTrailReadRole everywhere, including the sample KMS key-policy principal.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/grant-cross-account-kms-key-access-for-control-tower-byob-log-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -6,52 +6,52 @@ description: >-------# Grant cross-account KMS key access for Control Tower BYOB log collection# Grant cross-account KMS key access for Control Tower BYOB log collectionThis procedure is required if you are using custom Control Tower (BYOB) log collection and you choose to encrypt your logs with a KMS key.This procedure is required if you are using custom Control Tower (BYOB) log collection and you choose to encrypt your logs with a KMS key.When a KMS key and the accessing IAM role reside in different AWS accounts, AWS requires a two-way trust handshake to authorize access:When a KMS key and the accessing IAM role reside in different AWS accounts, AWS requires a two-way trust handshake to authorize access:• IAM side (Automated): The Cortex XSIAM CloudFormation template automatically attacheskms:Decryptpermissions for your specified key ARN to thecortex-logs-ingestion-access-<resource-suffix>role in the Log Archive account.• IAM side (Automated): The Cortex XSIAM CloudFormation template automatically attacheskms:Decryptpermissions for your specified key ARN to theCloudTrailReadRolerole in the Log Archive account.• KMS key policy side (Manual): You must update the KMS key's resource policy to explicitly trust and allow the Cortex XSIAM IAM role in the Log Archive account to perform thekms:Decryptaction.• KMS key policy side (Manual): You must update the KMS key's resource policy to explicitly trust and allow the Cortex XSIAM IAM role in the Log Archive account to perform thekms:Decryptaction.hint infohint info#### Prerequisites#### PrerequisitesBefore you begin, retrieve and note the following values:Before you begin, retrieve and note the following values:• Logging account ID: The 12-digit AWS account ID of your logging account where the Cortex IAM role is deployed.• Logging account ID: The 12-digit AWS account ID of your logging account where the Cortex IAM role is deployed.• Cortex role name: The exact name of the IAM role created by the Cortex XSIAM CloudFormation template in the Log Archive account (e.g.,cortex-logs-ingestion-access-<resource>-<suffix>). You can retrieve this from the Outputs tab of the deployed CloudFormation stack.• Cortex role name: The exact name of the IAM role created by the Cortex XSIAM CloudFormation template in the Log Archive account (e.g.,CloudTrailReadRole). You can retrieve this from the Outputs tab of the deployed CloudFormation stack.• KMS key ID or ARN: The identifier of the KMS key used to encrypt your Control Tower S3 bucket.• KMS key ID or ARN: The identifier of the KMS key used to encrypt your Control Tower S3 bucket.endhintendhint1. Sign in to the AWS Management Console of the Management account where the KMS key resides.1. Sign in to the AWS Management Console of the Management account where the KMS key resides.2. Navigate to Key Management Service (KMS) > Customer managed keys.2. Navigate to Key Management Service (KMS) > Customer managed keys.3. Select the KMS key used to encrypt your Control Tower S3 bucket.3. Select the KMS key used to encrypt your Control Tower S3 bucket.4. Select the Key policy tab, then click Edit.4. Select the Key policy tab, then click Edit.5. In the JSON editor, locate the closing bracket (]) of theStatementarray.5. In the JSON editor, locate the closing bracket (]) of theStatementarray.6. Append a comma (,) to the statement immediately preceding the closing bracket, then paste the following block:6. Append a comma (,) to the statement immediately preceding the closing bracket, then paste the following block:```json```json{{"Sid": "AllowCortexCrossAccountKmsDecrypt","Sid": "AllowCortexCrossAccountKmsDecrypt","Effect": "Allow","Effect": "Allow","Principal": {"Principal": {"AWS": "arn:aws:iam::<LOGGING_ACCOUNT_ID>:role/<CORTEX_ROLE_NAME>""AWS": "arn:aws:iam::<LOGGING_ACCOUNT_ID>:role/<CloudTrailReadRole>"},},"Action": "kms:Decrypt","Action": "kms:Decrypt","Resource": "*""Resource": "*"}}``````Where:Where:•<LOGGING_ACCOUNT_ID>is your 12-digit Log Archive account ID.•<LOGGING_ACCOUNT_ID>is your 12-digit Log Archive account ID.•<CORTEX_ROLE_NAME>is the full name of your Cortex IAM role.•<CloudTrailReadRole>is the full name of your Cortex IAM role.7. Click Save changes.7. Click Save changes.### Verify connection### Verify connectionOnce the key policy is updated, verify that Cortex XSIAM can successfully decrypt and ingest the logs:Once the key policy is updated, verify that Cortex XSIAM can successfully decrypt and ingest the logs:1. Log in to Cortex XSIAM.1. Log in to Cortex XSIAM.2. Navigate to Settings > Data Sources & Integrations > Cloud Accounts.2. Navigate to Settings > Data Sources & Integrations > Cloud Accounts.Show markdown source
@@ -6,52 +6,52 @@ description: >- --- # Grant cross-account KMS key access for Control Tower BYOB log collection This procedure is required if you are using custom Control Tower (BYOB) log collection and you choose to encrypt your logs with a KMS key. When a KMS key and the accessing IAM role reside in different AWS accounts, AWS requires a two-way trust handshake to authorize access: -* IAM side (Automated): The Cortex XSIAM CloudFormation template automatically attaches `kms:Decrypt` permissions for your specified key ARN to the `cortex-logs-ingestion-access-<resource-suffix>` role in the Log Archive account. +* IAM side (Automated): The Cortex XSIAM CloudFormation template automatically attaches `kms:Decrypt` permissions for your specified key ARN to the `CloudTrailReadRole` role in the Log Archive account. * KMS key policy side (Manual): You must update the KMS key's resource policy to explicitly trust and allow the Cortex XSIAM IAM role in the Log Archive account to perform the `kms:Decrypt` action. {% hint style="info" %} #### Prerequisites Before you begin, retrieve and note the following values: * **Logging account ID**: The 12-digit AWS account ID of your logging account where the Cortex IAM role is deployed. -* Cortex role name: The exact name of the IAM role created by the Cortex XSIAM CloudFormation template in the Log Archive account (e.g., `cortex-logs-ingestion-access-<resource>-<suffix>`). You can retrieve this from the **Outputs** tab of the deployed CloudFormation stack. +* Cortex role name: The exact name of the IAM role created by the Cortex XSIAM CloudFormation template in the Log Archive account (e.g., `CloudTrailReadRole`). You can retrieve this from the **Outputs** tab of the deployed CloudFormation stack. * KMS key ID or ARN: The identifier of the KMS key used to encrypt your Control Tower S3 bucket. {% endhint %} 1. Sign in to the AWS Management Console of the Management account where the KMS key resides. 2. Navigate to **Key Management Service (KMS) > Customer managed keys**. 3. Select the KMS key used to encrypt your Control Tower S3 bucket. 4. Select the **Key policy** tab, then click **Edit**. 5. In the JSON editor, locate the closing bracket (`]`) of the `Statement` array. 6. Append a comma (`,`) to the statement immediately preceding the closing bracket, then paste the following block: ```json { "Sid": "AllowCortexCrossAccountKmsDecrypt", "Effect": "Allow", "Principal": { - "AWS": "arn:aws:iam::<LOGGING_ACCOUNT_ID>:role/<CORTEX_ROLE_NAME>" + "AWS": "arn:aws:iam::<LOGGING_ACCOUNT_ID>:role/<CloudTrailReadRole>" }, "Action": "kms:Decrypt", "Resource": "*" } ``` Where: * `<LOGGING_ACCOUNT_ID>` is your 12-digit Log Archive account ID. - * `<CORTEX_ROLE_NAME>` is the full name of your Cortex IAM role. + * `<CloudTrailReadRole>` is the full name of your Cortex IAM role. 7. Click **Save changes**. ### Verify connection Once the key policy is updated, verify that Cortex XSIAM can successfully decrypt and ingest the logs: 1. Log in to Cortex XSIAM. 2. Navigate to **Settings > Data Sources & Integrations > Cloud Accounts**. -
▸ ▾ How to onboard Amazon Web Services modified +2 −2
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/how-to-onboard-amazon-web-servicesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -68,20 +68,20 @@ After completing the prerequisites, follow these instructions to onboard your Am• Automated: Select this option to have Cortex XSIAM provisions CloudTrail, S3, SQS, SNS, and KMS key resources in your AWS environment to collect audit logs.• Automated: Select this option to have Cortex XSIAM provisions CloudTrail, S3, SQS, SNS, and KMS key resources in your AWS environment to collect audit logs.• Collect data events: You can choose to collect data events, which captures S3 object-level and Lambda invocation events for enhanced visibility.• Collect data events: You can choose to collect data events, which captures S3 object-level and Lambda invocation events for enhanced visibility.• Cost considerations: Data events can generate high volumes in active environments (millions of events per day for busy S3 buckets). We recommend you review your CloudTrail pricing and expected event volume before enabling.• Cost considerations: Data events can generate high volumes in active environments (millions of events per day for busy S3 buckets). We recommend you review your CloudTrail pricing and expected event volume before enabling.• Custom: (Default) Use this option to use an existing Amazon S3 bucket for storing your CloudTrail logs.• Custom: (Default) Use this option to use an existing Amazon S3 bucket for storing your CloudTrail logs.• When you deploy the authentication template, you will enter the following details: S3 bucket name, SNS topic ARN, KMS key ARN (optional, if bucket is encrypted). For CloudFormation, these are entered as stack parameters. For Terraform, you are prompted for these values when you run terraform apply.• When you deploy the authentication template, you will enter the following details: S3 bucket name, SNS topic ARN, KMS key ARN (optional, if bucket is encrypted). For CloudFormation, these are entered as stack parameters. For Terraform, you are prompted for these values when you run terraform apply.• Cortex XSIAM creates the SQS queue, the CortexLogsReadRole IAM role, and the S3-to-SNS-to-SQS event notification infrastructure.• Cortex XSIAM creates the SQS queue, the CortexLogsReadRole IAM role, and the S3-to-SNS-to-SQS event notification infrastructure.• After you deploy the authentication template, you must configure the S3 bucket event notification to send to the Cortex XSIAM-created SQS queue.• After you deploy the authentication template, you must configure the S3 bucket event notification to send to the Cortex XSIAM-created SQS queue.• Custom - Control Tower: Select this option if your AWS Organization is managed by AWS Control Tower and uses a centralized Log Archive account. This option is only available for organization scope.• Custom - Control Tower: Select this option if your AWS Organization is managed by AWS Control Tower and uses a centralized Log Archive account. This option is only available for organization scope.• When you deploy the authentication template in CloudFormation, you will enter the following details: S3 bucket name (the centralized Control Tower bucket in the Log Archive account), SNS topic ARN (the Control Tower-provisionedaws-controltower-AllConfigNotificationstopic), KMS key ARN (optional), and the logging account ID (the AWS account ID of the Log Archive account).• When you deploy the authentication template in CloudFormation, you will enter the following details: S3 bucket name (the centralized Control Tower bucket in the Log Archive account), SNS topic ARN (the Control Tower-provisionedaws-controltower-AllConfigNotificationstopic), KMS key ARN (optional), logging account ID (the AWS account ID of the Log Archive account), logging account OU ID (the OU ID of the organizational unit that directly contains the Log Archive account), and the SNS topic OU ID (the OU ID of the organizational unit that directly contains the account where the SNS topic resides).• Cortex XSIAM deploys the IAM role into the Log Archive account and creates the SQS queue in the same account that hosts the customer's CloudTrail SNS topic.• Cortex XSIAM deploys the IAM role into the Log Archive account and creates the SQS queue in the same account that hosts the customer's CloudTrail SNS topic.<div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><h4>Important</h4><p>It is critical to ensure that your KMS key region and SNS topic region are the exact same as the AWS region where you are deploying the authentication template. For custom Control Tower (BYOB), deploy the stack in the same region as your Control Tower home region, where the <code>aws-controltower-AllConfigNotifications</code> SNS topic resides.</p></div><div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><h4>Important</h4><p>It is critical to ensure that your KMS key region and SNS topic region are the exact same as the AWS region where you are deploying the authentication template. For custom Control Tower (BYOB), deploy the stack in the same region as your Control Tower home region, where the SNS topic resides.</p></div>• Upload unknown files to WildFire: Use this option to upload unknown files scanned during registry image scans to WildFire for detonation analysis.• Upload unknown files to WildFire: Use this option to upload unknown files scanned during registry image scans to WildFire for detonation analysis.This option expands malware detection by allowing WildFire to analyze new samples found in your registry images. When a detonation result returns a malicious verdict, the system re-evaluates the relevant registry image and creates a malware finding.<br>This option expands malware detection by allowing WildFire to analyze new samples found in your registry images. When a detonation result returns a malicious verdict, the system re-evaluates the relevant registry image and creates a malware finding.<br><figure><img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FbLVVFbhzGA2oRZS73rxU%2Fimage.png?alt=media&token=cd29d9e4-72d8-401b-8cf0-d66079761890" alt=""><figcaption></figcaption></figure><figure><img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FbLVVFbhzGA2oRZS73rxU%2Fimage.png?alt=media&token=cd29d9e4-72d8-401b-8cf0-d66079761890" alt=""><figcaption></figcaption></figure><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h4>Notes</h4><ul><li>The file types sent for WildFire analysis depend on the platform type. WildFire accepts files up to 300 MB in size.</li><li>This setting applies only to registry image scans and is enabled by default for new AWS instances. For existing instances, this setting is disabled by default to preserve current behavior. You can enable it at any time by editing the instance configuration.</li><li>Your cloud provider may charge standard outbound data transfer (egress) fees when scanning with an <a href="../outpost-onboarding">Outpost</a>.</li></ul></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h4>Notes</h4><ul><li>The file types sent for WildFire analysis depend on the platform type. WildFire accepts files up to 300 MB in size.</li><li>This setting applies only to registry image scans and is enabled by default for new AWS instances. For existing instances, this setting is disabled by default to preserve current behavior. You can enable it at any time by editing the instance configuration.</li><li>Your cloud provider may charge standard outbound data transfer (egress) fees when scanning with an <a href="../outpost-onboarding">Outpost</a>.</li></ul></div>Show markdown source
@@ -68,20 +68,20 @@ After completing the prerequisites, follow these instructions to onboard your Am * **Automated:** Select this option to have Cortex XSIAM provisions CloudTrail, S3, SQS, SNS, and KMS key resources in your AWS environment to collect audit logs. * **Collect data events:** You can choose to collect data events, which captures S3 object-level and Lambda invocation events for enhanced visibility. * **Cost considerations:** Data events can generate high volumes in active environments (millions of events per day for busy S3 buckets). We recommend you review your CloudTrail pricing and expected event volume before enabling. * **Custom**: (Default) Use this option to use an existing Amazon S3 bucket for storing your CloudTrail logs. * When you deploy the authentication template, you will enter the following details: S3 bucket name, SNS topic ARN, KMS key ARN (optional, if bucket is encrypted). For CloudFormation, these are entered as stack parameters. For Terraform, you are prompted for these values when you run terraform apply. * Cortex XSIAM creates the SQS queue, the **CortexLogsReadRole** IAM role, and the S3-to-SNS-to-SQS event notification infrastructure. * After you deploy the authentication template, you must configure the S3 bucket event notification to send to the Cortex XSIAM-created SQS queue. * **Custom - Control Tower:** Select this option if your AWS Organization is managed by AWS Control Tower and uses a centralized Log Archive account. This option is only available for organization scope. - * When you deploy the authentication template in CloudFormation, you will enter the following details: S3 bucket name (the centralized Control Tower bucket in the Log Archive account), SNS topic ARN (the Control Tower-provisioned `aws-controltower-AllConfigNotifications` topic), KMS key ARN (optional), and the logging account ID (the AWS account ID of the Log Archive account). + * When you deploy the authentication template in CloudFormation, you will enter the following details: S3 bucket name (the centralized Control Tower bucket in the Log Archive account), SNS topic ARN (the Control Tower-provisioned `aws-controltower-AllConfigNotifications` topic), KMS key ARN (optional), logging account ID (the AWS account ID of the Log Archive account), logging account OU ID (the OU ID of the organizational unit that directly contains the Log Archive account), and the SNS topic OU ID (the OU ID of the organizational unit that directly contains the account where the SNS topic resides). * Cortex XSIAM deploys the IAM role into the Log Archive account and creates the SQS queue in the same account that hosts the customer's CloudTrail SNS topic. - <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><h4>Important</h4><p>It is critical to ensure that your KMS key region and SNS topic region are the exact same as the AWS region where you are deploying the authentication template. For custom Control Tower (BYOB), deploy the stack in the same region as your Control Tower home region, where the <code>aws-controltower-AllConfigNotifications</code> SNS topic resides.</p></div> + <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><h4>Important</h4><p>It is critical to ensure that your KMS key region and SNS topic region are the exact same as the AWS region where you are deploying the authentication template. For custom Control Tower (BYOB), deploy the stack in the same region as your Control Tower home region, where the SNS topic resides.</p></div> * **Upload unknown files to WildFire:** Use this option to upload unknown files scanned during registry image scans to WildFire for detonation analysis. This option expands malware detection by allowing WildFire to analyze new samples found in your registry images. When a detonation result returns a malicious verdict, the system re-evaluates the relevant registry image and creates a malware finding.<br> <figure><img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FbLVVFbhzGA2oRZS73rxU%2Fimage.png?alt=media&token=cd29d9e4-72d8-401b-8cf0-d66079761890" alt=""><figcaption></figcaption></figure> <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h4>Notes</h4><ul><li>The file types sent for WildFire analysis depend on the platform type. WildFire accepts files up to 300 MB in size.</li><li>This setting applies only to registry image scans and is enabled by default for new AWS instances. For existing instances, this setting is disabled by default to preserve current behavior. You can enable it at any time by editing the instance configuration.</li><li>Your cloud provider may charge standard outbound data transfer (egress) fees when scanning with an <a href="../outpost-onboarding">Outpost</a>.</li></ul></div> -
▸ ▾ Post-deployment: Custom (BYOB) and Control Tower audit log collection modified +3 −3 Retitled to cover Custom (BYOB) and Control Tower; the KMS key-policy troubleshooting item is now Control Tower only.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/amazon-web-services-cloud-onboarding/post-deployment-custom-byob-audit-log-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,11 +1,11 @@# Post-deployment: Custom (BYOB) audit log collection# Post-deployment: Custom (BYOB) and Control Tower audit log collectionIf you selected Custom (BYOB) audit log collection, you must configure your S3 bucket to forward event notifications to the SQS queue created by the template. The steps differ depending on your deployment method.If you selected Custom (BYOB) or Custom Control Tower audit log collection, you must configure your S3 bucket to forward event notifications to the SQS queue created by the template. The steps differ depending on your deployment method.tabstabstab CloudFormation Custom (BYOB)tab CloudFormation Custom (BYOB)The CloudFormation stack creates the SQS queue in your account. You must manually configure your S3 bucket to send event notifications to it.The CloudFormation stack creates the SQS queue in your account. You must manually configure your S3 bucket to send event notifications to it.1. In the AWS CloudFormation console, open the stack and select the Outputs tab.1. In the AWS CloudFormation console, open the stack and select the Outputs tab.2. Note thesqs_urloutput value.2. Note thesqs_urloutput value.3. Derive the SQS queue ARN from the URL (format:arn:aws:sqs:<region>:<account-id>:<queue-name>), or retrieve it from the AWS SQS console.3. Derive the SQS queue ARN from the URL (format:arn:aws:sqs:<region>:<account-id>:<queue-name>), or retrieve it from the AWS SQS console.@@ -46,17 +46,17 @@ The Terraform template creates the SQS queue in your account. You must manuallyendtabsendtabs### Troubleshooting custom audit log collection### Troubleshooting custom audit log collectionUse this section to diagnose issues with custom (BYOB) audit log collection after deploying the authentication template. The most common causes of failure are:Use this section to diagnose issues with custom (BYOB) audit log collection after deploying the authentication template. The most common causes of failure are:• S3 event notifications not configured or misconfigured: For Terraform and standard CloudFormation deployments, you must manually configure your S3 bucket to forwards3:ObjectCreated:*events to the SQS queue created by the template. If this step is skipped or the wrong SQS ARN is used, logs will not reach Cortex XSIAM.• S3 event notifications not configured or misconfigured: For Terraform and standard CloudFormation deployments, you must manually configure your S3 bucket to forwards3:ObjectCreated:*events to the SQS queue created by the template. If this step is skipped or the wrong SQS ARN is used, logs will not reach Cortex XSIAM.• Cross-region resources: The S3 bucket, SNS topic, SQS queue, and authentication template deployment must all be in the same AWS region. Cross-region configurations are not supported.• Cross-region resources: The S3 bucket, SNS topic, SQS queue, and authentication template deployment must all be in the same AWS region. Cross-region configurations are not supported.• KMS key policy not updated: If your S3 bucket is encrypted with a customer-managed KMS key, you must manually update the KMS key policy to allow the Cortex log-collector IAM role to callkms:Decrypt. This cannot be done automatically by the template.• KMS key policy not updated: (Only relevant for Custom Control Tower audit log collection) If your S3 bucket is encrypted with a customer-managed KMS key, you must manually update the KMS key policy to allow the Cortex log-collector IAM role to callkms:Decrypt. This cannot be done automatically by the template.• Instance remains in Pending state: This indicates the template deployed successfully but the notification to Cortex XSIAM did not complete. You can connect the instance manually from the Cortex XSIAM pending instances panel. See Manually connect a cloud instance for more details.• Instance remains in Pending state: This indicates the template deployed successfully but the notification to Cortex XSIAM did not complete. You can connect the instance manually from the Cortex XSIAM pending instances panel. See Manually connect a cloud instance for more details.Select the tab for your deployment method for specific troubleshooting steps.Select the tab for your deployment method for specific troubleshooting steps.tabstabstab CloudFormation Custom (BYOB)tab CloudFormation Custom (BYOB)Symptom Likely cause Resolution Stack creation fails with IAM permission errors AWS credentials lack required CloudFormation or IAM permissions Ensure your AWS credentials have permissions to create CloudFormation stacks, IAM roles, SQS queues, and the resources required by your selected capabilities. CloudTrailSnsArnparameter rejectedSNS ARN format is incorrect The ARN must match arn:(aws|aws-us-gov):sns:<region>:<account-id>:<topic-name>.CloudTrailKmsArnparameter rejectedKMS ARN format is incorrect The ARN must match arn:(aws|aws-us-gov):kms:<region>:<account-id>:key/<uuid>. Leave the field empty if no KMS key is used.Instance remains in Pending state after stack creation Lambda notification to Cortex XSIAM failed Check the Lambda function logs in CloudWatch for errors. If the notification failed, connect the instance manually: select the pending instance, click Connect manually, and provide the CortexPlatformRoleARN and External ID shown in the CloudFormation stack Outputs tab.Logs not appearing in Cortex XSIAM after stack creation S3 event notification not configured, or configured with wrong SQS ARN Confirm you have configured the S3 bucket event notification to send s3:ObjectCreated:*events to the SQS queue. Retrieve the correct SQS ARN from thesqs_urlvalue in the CloudFormation stack Outputs tab. Ensure the S3 bucket, SNS topic, and CloudFormation stack are all in the same AWS region.KMS decryption errors in Cortex XSIAM KMS key policy does not allow the CortexLogsReadRoleto callkms:DecryptUpdate the KMS key policy to allow kms:Decryptfor theCortexLogsReadRole-*IAM role created by the stack. This must be done manually after the stack is deployed.Symptom Likely cause Resolution Stack creation fails with IAM permission errors AWS credentials lack required CloudFormation or IAM permissions Ensure your AWS credentials have permissions to create CloudFormation stacks, IAM roles, SQS queues, and the resources required by your selected capabilities. CloudTrailSnsArnparameter rejectedSNS ARN format is incorrect The ARN must match arn:(aws|aws-us-gov):sns:<region>:<account-id>:<topic-name>.CloudTrailKmsArnparameter rejectedKMS ARN format is incorrect The ARN must match arn:(aws|aws-us-gov):kms:<region>:<account-id>:key/<uuid>. Leave the field empty if no KMS key is used.Instance remains in Pending state after stack creation Lambda notification to Cortex XSIAM failed Check the Lambda function logs in CloudWatch for errors. If the notification failed, connect the instance manually: select the pending instance, click Connect manually, and provide the CortexPlatformRoleARN and External ID shown in the CloudFormation stack Outputs tab.Logs not appearing in Cortex XSIAM after stack creation S3 event notification not configured, or configured with wrong SQS ARN Confirm you have configured the S3 bucket event notification to send s3:ObjectCreated:*events to the SQS queue. Retrieve the correct SQS ARN from thesqs_urlvalue in the CloudFormation stack Outputs tab. Ensure the S3 bucket, SNS topic, and CloudFormation stack are all in the same AWS region.KMS decryption errors in Cortex XSIAM KMS key policy does not allow the CortexLogsReadRoleto callkms:DecryptUpdate the KMS key policy to allow kms:Decryptfor theCortexLogsReadRole-*IAM role created by the stack. This must be done manually after the stack is deployed.Show markdown source
@@ -1,11 +1,11 @@ -# Post-deployment: Custom (BYOB) audit log collection +# Post-deployment: Custom (BYOB) and Control Tower audit log collection -If you selected **Custom (BYOB)** audit log collection, you must configure your S3 bucket to forward event notifications to the SQS queue created by the template. The steps differ depending on your deployment method. +If you selected **Custom (BYOB) or Custom Control Tower** audit log collection, you must configure your S3 bucket to forward event notifications to the SQS queue created by the template. The steps differ depending on your deployment method. {% tabs %} {% tab title="CloudFormation Custom (BYOB)" %} The CloudFormation stack creates the SQS queue in your account. You must manually configure your S3 bucket to send event notifications to it. 1. In the AWS CloudFormation console, open the stack and select the **Outputs** tab. 2. Note the `sqs_url` output value. 3. Derive the SQS queue ARN from the URL (format: `arn:aws:sqs:<region>:<account-id>:<queue-name>`), or retrieve it from the AWS SQS console. @@ -46,17 +46,17 @@ The Terraform template creates the SQS queue in your account. You must manually {% endtabs %} ### Troubleshooting custom audit log collection Use this section to diagnose issues with custom (BYOB) audit log collection after deploying the authentication template. The most common causes of failure are: * **S3 event notifications not configured or misconfigured**: For Terraform and standard CloudFormation deployments, you must manually configure your S3 bucket to forward `s3:ObjectCreated:*` events to the SQS queue created by the template. If this step is skipped or the wrong SQS ARN is used, logs will not reach Cortex XSIAM. * **Cross-region resources**: The S3 bucket, SNS topic, SQS queue, and authentication template deployment must all be in the same AWS region. Cross-region configurations are not supported. -* **KMS key policy not updated**: If your S3 bucket is encrypted with a customer-managed KMS key, you must manually update the KMS key policy to allow the Cortex log-collector IAM role to call `kms:Decrypt`. This cannot be done automatically by the template. +* **KMS key policy not updated:** (Only relevant for Custom Control Tower audit log collection) If your S3 bucket is encrypted with a customer-managed KMS key, you must manually update the KMS key policy to allow the Cortex log-collector IAM role to call `kms:Decrypt`. This cannot be done automatically by the template. * **Instance remains in Pending state**: This indicates the template deployed successfully but the notification to Cortex XSIAM did not complete. You can connect the instance manually from the Cortex XSIAM pending instances panel. See [Manually connect a cloud instance](../manually-connect-a-cloud-instance) for more details. Select the tab for your deployment method for specific troubleshooting steps. {% tabs %} {% tab title="CloudFormation Custom (BYOB)" %} <table><thead><tr><th width="204.37109375">Symptom</th><th width="215.3203125">Likely cause</th><th>Resolution</th></tr></thead><tbody><tr><td>Stack creation fails with IAM permission errors</td><td>AWS credentials lack required CloudFormation or IAM permissions</td><td>Ensure your AWS credentials have permissions to create CloudFormation stacks, IAM roles, SQS queues, and the resources required by your selected capabilities.</td></tr><tr><td><code>CloudTrailSnsArn</code> parameter rejected</td><td>SNS ARN format is incorrect</td><td>The ARN must match <code>arn:(aws|aws-us-gov):sns:<region>:<account-id>:<topic-name></code>.</td></tr><tr><td><code>CloudTrailKmsArn</code> parameter rejected</td><td>KMS ARN format is incorrect</td><td>The ARN must match <code>arn:(aws|aws-us-gov):kms:<region>:<account-id>:key/<uuid></code>. Leave the field empty if no KMS key is used.</td></tr><tr><td>Instance remains in Pending state after stack creation</td><td>Lambda notification to Cortex XSIAM failed</td><td>Check the Lambda function logs in CloudWatch for errors. If the notification failed, connect the instance manually: select the pending instance, click <strong>Connect manually</strong>, and provide the <code>CortexPlatformRole</code> ARN and External ID shown in the CloudFormation stack Outputs tab.</td></tr><tr><td>Logs not appearing in Cortex XSIAM after stack creation</td><td>S3 event notification not configured, or configured with wrong SQS ARN</td><td>Confirm you have configured the S3 bucket event notification to send <code>s3:ObjectCreated:*</code> events to the SQS queue. Retrieve the correct SQS ARN from the <code>sqs_url</code> value in the CloudFormation stack Outputs tab. Ensure the S3 bucket, SNS topic, and CloudFormation stack are all in the same AWS region.</td></tr><tr><td>KMS decryption errors in Cortex XSIAM</td><td>KMS key policy does not allow the <code>CortexLogsReadRole</code> to call <code>kms:Decrypt</code></td><td>Update the KMS key policy to allow <code>kms:Decrypt</code> for the <code>CortexLogsReadRole-*</code> IAM role created by the stack. This must be done manually after the stack is deployed.</td></tr></tbody></table> -
▸ ▾ How to onboard Microsoft Azure modified +3 −3 Tenant and management-group scope now uses one management-group diagnostic setting rather than one per subscription.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/how-to-onboard-microsoft-azureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -80,20 +80,20 @@ Cortex XSIAM performs a live verification of each tenant's approval status again• Automation: Use automation to pre-configure a list of integrations and associated commands to automate security issue responses. Commands can be utilized individually or as part of custom playbooks for issue remediation.• Automation: Use automation to pre-configure a list of integrations and associated commands to automate security issue responses. Commands can be utilized individually or as part of custom playbooks for issue remediation.• Log Level: (Optional - for Automation only) Configure the automation integration logging level. Possible values are:• Log Level: (Optional - for Automation only) Configure the automation integration logging level. Possible values are:• Off (Default)• Off (Default)• Debug• Debug• Verbose• Verbose• Agentless disk scanning: (Recommended) Implement agentless disk scanning to remotely detect and remediate vulnerabilities during the development lifecycle.• Agentless disk scanning: (Recommended) Implement agentless disk scanning to remotely detect and remediate vulnerabilities during the development lifecycle.• Cloud Tags: Define tags and tag values to be added to any new resource created by Cortex XSIAM in Microsoft Azure. Note: Themanaged_by = paloaltonetworkstag is automatically added to all resources. This tag is mandatory. You cannot edit or remove this tag.• Cloud Tags: Define tags and tag values to be added to any new resource created by Cortex XSIAM in Microsoft Azure. Note: Themanaged_by = paloaltonetworkstag is automatically added to all resources. This tag is mandatory. You cannot edit or remove this tag.• Log Collection Configuration: To maximize security coverage, include the collection of audit logs using Event Hub. Select the collection method:• Log Collection Configuration: To maximize security coverage, include the collection of audit logs using Event Hub. Select the collection method:• Automated collection: Cortex XSIAM provisions the resource group, Event Hub namespace, Event Hub, consumer group, storage account, user-assigned managed identity (UAMI), federated identity credential, diagnostic settings, and role assignment resources in your Azure environment to collect audit logs.• Automated collection: Cortex XSIAM provisions the resource group, Event Hub namespace, Event Hub, consumer group, storage account, user-assigned managed identity (UAMI), federated identity credential, diagnostic settings, and role assignment resources in your Azure environment to collect audit logs.• Tenant/management group scope: An Azure policy definition is also created to automatically deploy diagnostic settings to each subscription in the scope.• Tenant/management group scope: A single diagnostic setting is created at the management group scope. Azure natively propagates Activity Logs from all child subscriptions through this management group-level setting and no per-subscription diagnostic setting is created. An Azure policy definition is also deployed to create the Cortex resource group in each child subscription.• Cost considerations: Event Hub pricing is based on throughput units and ingress/egress. High-volume environments with many subscriptions can generate significant event throughput. We recommend you review your Azure Event Hubs pricing and expected event volume before enabling.• Cost considerations: Event Hub pricing is based on throughput units and ingress/egress. High-volume environments with many subscriptions can generate significant event throughput. We recommend you review your Azure Event Hubs pricing and expected event volume before enabling.• Custom (user defined): Select this option to use an existing Event Hub for storing your audit logs.• Custom (user defined): Select this option to use an existing Event Hub for storing your audit logs.• When you deploy the authentication template in ARM, you will enter the following details: Event Hub name, Event Hub namespace, Event Hub resource group name.• When you deploy the authentication template in ARM, you will enter the following details: Event Hub name, Event Hub namespace, Event Hub resource group name.• Cortex XSIAM creates the user-assigned managed identity (UAMI), federated identity credential, role assignments, and consumer group.• Cortex XSIAM creates the user-assigned managed identity (UAMI), federated identity credential, role assignments, and consumer group.• After you deploy the stack in ARM, you must ensure that your existing Event Hub has the appropriate diagnostic settings configured to stream Azure Activity Logs.• After you deploy the stack in ARM, you must ensure that your existing Event Hub has the appropriate diagnostic settings configured to stream Azure Activity Logs.#### Important#### ImportantIt is critical to ensure that your namespace and Event Hub belong to the specific Azure subscription being onboarded. Cross-subscription or centralized logging is not currently supported.It is critical to ensure that your namespace and Event Hub belong to the specific Azure subscription being onboarded. Cross-subscription or centralized logging is not currently supported.Show markdown source
@@ -80,20 +80,20 @@ Cortex XSIAM performs a live verification of each tenant's approval status again * **Automation:** Use automation to pre-configure a list of integrations and associated commands to automate security issue responses. Commands can be utilized individually or as part of custom playbooks for issue remediation. * **Log Level:** (Optional - for Automation only) Configure the automation integration logging level. Possible values are: * Off (Default) * Debug * Verbose * **Agentless disk scanning:** (Recommended) Implement agentless disk scanning to remotely detect and remediate vulnerabilities during the development lifecycle. * **Cloud Tags:** Define tags and tag values to be added to any new resource created by Cortex XSIAM in Microsoft Azure. Note: The `managed_by = paloaltonetworks` tag is automatically added to all resources. This tag is mandatory. You cannot edit or remove this tag. * **Log Collection Configuration:** To maximize security coverage, include the collection of audit logs using Event Hub. Select the collection method: - * Automated collection: Cortex XSIAM provisions the resource group, Event Hub namespace, Event Hub, consumer group, storage account, user-assigned managed identity (UAMI), federated identity credential, diagnostic settings, and role assignment resources in your Azure environment to collect audit logs. - * Tenant/management group scope: An Azure policy definition is also created to automatically deploy diagnostic settings to each subscription in the scope. + * **Automated collection:** Cortex XSIAM provisions the resource group, Event Hub namespace, Event Hub, consumer group, storage account, user-assigned managed identity (UAMI), federated identity credential, diagnostic settings, and role assignment resources in your Azure environment to collect audit logs. + * **Tenant/management group scope:** A single diagnostic setting is created at the management group scope. Azure natively propagates Activity Logs from all child subscriptions through this management group-level setting and no per-subscription diagnostic setting is created. An Azure policy definition is also deployed to create the Cortex resource group in each child subscription. * **Cost considerations:** Event Hub pricing is based on throughput units and ingress/egress. High-volume environments with many subscriptions can generate significant event throughput. We recommend you review your [Azure Event Hubs pricing](https://azure.microsoft.com/en-us/pricing/details/event-hubs/) and expected event volume before enabling. - * Custom (user defined): Select this option to use an existing Event Hub for storing your audit logs. + * **Custom** (user defined): Select this option to use an existing Event Hub for storing your audit logs. * When you deploy the authentication template in ARM, you will enter the following details: Event Hub name, Event Hub namespace, Event Hub resource group name. * Cortex XSIAM creates the user-assigned managed identity (UAMI), federated identity credential, role assignments, and consumer group. * After you deploy the stack in ARM, you must ensure that your existing Event Hub has the appropriate diagnostic settings configured to stream Azure Activity Logs. #### Important It is critical to ensure that your namespace and Event Hub belong to the specific Azure subscription being onboarded. Cross-subscription or centralized logging is not currently supported. -
▸ ▾ Complete data source and connector catalog modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/complete-data-source-catalogRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,17 +3,17 @@ description: >-Learn more about the complete data source and connector catalog available inLearn more about the complete data source and connector catalog available inCortex XSIAM.Cortex XSIAM.------# Complete data source and connector catalog# Complete data source and connector catalogThe complete data source catalog is a conceptual grouping that is comprised of all configuration points available for data ingestion across Cortex XSIAM. It represents the aggregate of every integration method, from unified vendor connectors and cloud onboarding wizards to generic on-premise collectors and specialized Marketplace integrations.The complete data source catalog is a conceptual grouping that is comprised of all configuration points available for data ingestion across Cortex XSIAM. It represents the aggregate of every integration method, from unified vendor connectors and cloud onboarding wizards to generic on-premise collectors and specialized Marketplace integrations.The catalog is best understood by categorizing ingestion methods into the following core groups. By consulting the specific documentation sections dedicated to each category as detailed below, you gain a complete overview of all available ingestion options that collectively form the data source catalog.The catalog is best understood by categorizing ingestion methods into the following core groups. By consulting the specific documentation sections dedicated to each category as detailed below, you gain a complete overview of all available ingestion options that collectively form the data source and connector catalog.### Vendor-specific data sources and connectors### Vendor-specific data sources and connectorsThis section includes integrations for specific third-party security and IT products, such as Okta, Box, and Salesforce. These include:This section includes integrations for specific third-party security and IT products, such as Okta, Box, and Salesforce. These include:• Connectors: The strategic, unified experience that allows you to manage all of a vendor's capabilities, such as log collection, automation, and posture, through a single configuration wizard.• Connectors: The strategic, unified experience that allows you to manage all of a vendor's capabilities, such as log collection, automation, and posture, through a single configuration wizard.• Standard data collectors: Traditional built-in API and file-based collection functionalities.• Standard data collectors: Traditional built-in API and file-based collection functionalities.Show markdown source
@@ -3,17 +3,17 @@ description: >- Learn more about the complete data source and connector catalog available in Cortex XSIAM. --- # Complete data source and connector catalog The complete data source catalog is a conceptual grouping that is comprised of all configuration points available for data ingestion across Cortex XSIAM. It represents the aggregate of every integration method, from unified vendor connectors and cloud onboarding wizards to generic on-premise collectors and specialized Marketplace integrations. -The catalog is best understood by categorizing ingestion methods into the following core groups. By consulting the specific documentation sections dedicated to each category as detailed below, you gain a complete overview of all available ingestion options that collectively form the data source catalog. +The catalog is best understood by categorizing ingestion methods into the following core groups. By consulting the specific documentation sections dedicated to each category as detailed below, you gain a complete overview of all available ingestion options that collectively form the data source and connector catalog. ### Vendor-specific data sources and connectors This section includes integrations for specific third-party security and IT products, such as Okta, Box, and Salesforce. These include: * **Connectors**: The strategic, unified experience that allows you to manage all of a vendor's capabilities, such as log collection, automation, and posture, through a single configuration wizard. * **Standard data collectors**: Traditional built-in API and file-based collection functionalities.
-
▸ ▾ Grouped Example Connector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/grouped-example-connector/grouped-example-connectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,17 +1,17 @@# Grouped Example Connector# Grouped Example Connectorhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintPOC of Grouped Connectors / view_groups. Four mocked Microsoft-themed XSOAR integrations (EWS O365, EWS v2, Office 365 Feed, Microsoft Teams) wired to exercise:settings.grouped, split connection/configurationsview_groupsregistries, per-handlerauth_optionsview_grouppinning, one profile shared across multiple capabilities, multiple profiles bound to one sub-capability, two integrations under the same capability with duplicated field names perview_group, integration-shared params across two sub-capabilities, per-integrationengine/proxy/trust-any-certin connectiongeneral_configurations, and per-integrationintegrationLogLevelwith serializer rewrites. Appendix G + I carve-outs honored for Microsoft Teams. Every vendor / pack / capability mapping here is mocked.POC of Grouped Connectors / view_groups. Four mocked Microsoft-themed XSIAM integrations (EWS O365, EWS v2, Office 365 Feed, Microsoft Teams) wired to exercise:settings.grouped, split connection/configurationsview_groupsregistries, per-handlerauth_optionsview_grouppinning, one profile shared across multiple capabilities, multiple profiles bound to one sub-capability, two integrations under the same capability with duplicated field names perview_group, integration-shared params across two sub-capabilities, per-integrationengine/proxy/trust-any-certin connectiongeneral_configurations, and per-integrationintegrationLogLevelwith serializer rewrites. Appendix G + I carve-outs honored for Microsoft Teams. Every vendor / pack / capability mapping here is mocked.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• EWS O365: The new EWS O365 integration uses OAuth 2.0 protocol and can be used with Exchange Online and Office 365 (mail).• EWS O365: The new EWS O365 integration uses OAuth 2.0 protocol and can be used with Exchange Online and Office 365 (mail).• EWS v2: Exchange Web Services and Office 365 (mail).• EWS v2: Exchange Web Services and Office 365 (mail).• Fetch Issues:• Fetch Issues:• Microsoft Teams: Send messages and notifications to your team members.• Microsoft Teams: Send messages and notifications to your team members.Show markdown source
@@ -1,17 +1,17 @@ # Grouped Example Connector {% hint style="warning" %} **Important** This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. {% endhint %} -POC of Grouped Connectors / view\_groups. Four mocked Microsoft-themed XSOAR integrations (EWS O365, EWS v2, Office 365 Feed, Microsoft Teams) wired to exercise: `settings.grouped`, split connection/configurations `view_groups` registries, per-handler `auth_options` `view_group` pinning, one profile shared across multiple capabilities, multiple profiles bound to one sub-capability, two integrations under the same capability with duplicated field names per `view_group`, integration-shared params across two sub-capabilities, per-integration `engine`/`proxy`/`trust-any-cert` in connection `general_configurations`, and per-integration `integrationLogLevel` with serializer rewrites. Appendix G + I carve-outs honored for Microsoft Teams. Every vendor / pack / capability mapping here is mocked. +POC of Grouped Connectors / view\_groups. Four mocked Microsoft-themed XSIAM integrations (EWS O365, EWS v2, Office 365 Feed, Microsoft Teams) wired to exercise: `settings.grouped`, split connection/configurations `view_groups` registries, per-handler `auth_options` `view_group` pinning, one profile shared across multiple capabilities, multiple profiles bound to one sub-capability, two integrations under the same capability with duplicated field names per `view_group`, integration-shared params across two sub-capabilities, per-integration `engine`/`proxy`/`trust-any-cert` in connection `general_configurations`, and per-integration `integrationLogLevel` with serializer rewrites. Appendix G + I carve-outs honored for Microsoft Teams. Every vendor / pack / capability mapping here is mocked. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [EWS O365](https://xsoar.pan.dev/docs/reference/integrations/ewso365): The new EWS O365 integration uses OAuth 2.0 protocol and can be used with Exchange Online and Office 365 (mail). * [EWS v2](https://xsoar.pan.dev/docs/reference/integrations/ews-v2): Exchange Web Services and Office 365 (mail). * Fetch Issues: * [Microsoft Teams](https://xsoar.pan.dev/docs/reference/integrations/microsoft-teams): Send messages and notifications to your team members. * [Office 365 Feed](https://xsoar.pan.dev/docs/reference/integrations/office-365-feed): -
▸ ▾ Proofpoint modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/proofpoint/proofpointRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -6,17 +6,17 @@This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintProofpoint is an email security and threat protection platform that guards against phishing, malware, and advanced email attacks. It includes Targeted Attack Protection (TAP), Threat Response for automated issue response, Protection Server for email gateway management, Cloud Threat Response, Browser Isolation, and URL phishing validation via IsItPhishing.Proofpoint is an email security and threat protection platform that guards against phishing, malware, and advanced email attacks. It includes Targeted Attack Protection (TAP), Threat Response for automated issue response, Protection Server for email gateway management, Cloud Threat Response, Browser Isolation, and URL phishing validation via IsItPhishing.This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information):• IsItPhishing: Collaborative web service that provides validation on whether a URL is a phishing page or not by analyzing the content of the webpage. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• IsItPhishing: Collaborative web service that provides validation on whether a URL is a phishing page or not by analyzing the content of the webpage. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Cloud Threat Response: Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSOAR for case management, and exposes commands to list and retrieve incident details. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Cloud Threat Response: Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSIAM for case management, and exposes commands to list and retrieve incident details. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Email Security Event Collector: Collects events for Proofpoint Email Security using the streaming API. This sub-capability is available with any active Cortex XSIAM license.• Proofpoint Email Security Event Collector: Collects events for Proofpoint Email Security using the streaming API. This sub-capability is available with any active Cortex XSIAM license.• Proofpoint Protection Server v2: Proofpoint email security appliance. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Protection Server v2: Proofpoint email security appliance. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint TAP v2: Use the Proofpoint Targeted Attack Protection (TAP) integration to protect against and provide additional visibility into phishing and other malicious email attacks. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint TAP v2: Use the Proofpoint Targeted Attack Protection (TAP) integration to protect against and provide additional visibility into phishing and other malicious email attacks. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Threat Protection: Threat Protection APIs are REST APIs that allow Proofpoint On Demand customers to retrieve, add, update or delete certain PoD configurations. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Threat Protection: Threat Protection APIs are REST APIs that allow Proofpoint On Demand customers to retrieve, add, update or delete certain PoD configurations. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Threat Response: Use the Proofpoint Threat Response integration to orchestrate and automate incident response. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• Proofpoint Threat Response: Use the Proofpoint Threat Response integration to orchestrate and automate incident response. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license.• ProofpointIsolationEventCollector: Proofpoint Isolation is an integration that supports fetching Browser and Email Isolation logs events. This sub-capability is available with any active Cortex XSIAM license.• ProofpointIsolationEventCollector: Proofpoint Isolation is an integration that supports fetching Browser and Email Isolation logs events. This sub-capability is available with any active Cortex XSIAM license.• ProofpointThreatResponseEventCollector: Use the Proofpoint Threat Response integration to orchestrate and automate incident response. This sub-capability is available with any active Cortex XSIAM license.• ProofpointThreatResponseEventCollector: Use the Proofpoint Threat Response integration to orchestrate and automate incident response. This sub-capability is available with any active Cortex XSIAM license.Show markdown source
@@ -6,17 +6,17 @@ This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace. {% endhint %} Proofpoint is an email security and threat protection platform that guards against phishing, malware, and advanced email attacks. It includes Targeted Attack Protection (TAP), Threat Response for automated issue response, Protection Server for email gateway management, Cloud Threat Response, Browser Isolation, and URL phishing validation via IsItPhishing. This connector includes the following sub-capabilities (Marketplace integrations link to PAN DEV for more information): * [IsItPhishing](https://xsoar.pan.dev/docs/reference/integrations/is-it-phishing): Collaborative web service that provides validation on whether a URL is a phishing page or not by analyzing the content of the webpage. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. -* Proofpoint Cloud Threat Response: Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSOAR for case management, and exposes commands to list and retrieve incident details. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. +* Proofpoint Cloud Threat Response: Fetches Proofpoint Cloud Threat Response (CTR) incidents into Cortex XSIAM for case management, and exposes commands to list and retrieve incident details. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Proofpoint Email Security Event Collector](https://xsoar.pan.dev/docs/reference/integrations/proofpoint-email-security-event-collector): Collects events for Proofpoint Email Security using the streaming API. This sub-capability is available with any active Cortex XSIAM license. * [Proofpoint Protection Server v2](https://xsoar.pan.dev/docs/reference/integrations/proofpoint-protection-server-v2): Proofpoint email security appliance. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Proofpoint TAP v2](https://xsoar.pan.dev/docs/reference/integrations/proofpoint-tap-v2): Use the Proofpoint Targeted Attack Protection (TAP) integration to protect against and provide additional visibility into phishing and other malicious email attacks. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Proofpoint Threat Protection](https://xsoar.pan.dev/docs/reference/integrations/proofpoint-threat-protection): Threat Protection APIs are REST APIs that allow Proofpoint On Demand customers to retrieve, add, update or delete certain PoD configurations. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [Proofpoint Threat Response](https://xsoar.pan.dev/docs/reference/integrations/proofpoint-threat-response): Use the Proofpoint Threat Response integration to orchestrate and automate incident response. This sub-capability is available with any active Cortex XSIAM or Cortex AgentiX license. * [ProofpointIsolationEventCollector](https://xsoar.pan.dev/docs/reference/integrations/proofpoint-isolation-event-collector): Proofpoint Isolation is an integration that supports fetching Browser and Email Isolation logs events. This sub-capability is available with any active Cortex XSIAM license. * [ProofpointThreatResponseEventCollector](https://xsoar.pan.dev/docs/reference/integrations/proofpoint-threat-response-event-collector): Use the Proofpoint Threat Response integration to orchestrate and automate incident response. This sub-capability is available with any active Cortex XSIAM license. -
▸ ▾ What are Cortex XSIAM data sources and connectors? modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/what-are-cortex-xsiam-data-sourcesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -12,17 +12,17 @@ Data sources and connectors are the foundational mechanisms used to ingest securThe ingestion methods and configuration options available to you in the UI depend on your tenant onboarding date:The ingestion methods and configuration options available to you in the UI depend on your tenant onboarding date:• New tenants (onboarded after July 26, 2026): You will primarily interact with the strategic Connector experience. Standalone Marketplace integrations that have been consolidated into connectors are hidden from the catalog to ensure a unified configuration flow.• New tenants (onboarded after July 26, 2026): You will primarily interact with the strategic Connector experience. Standalone Marketplace integrations that have been consolidated into connectors are hidden from the catalog to ensure a unified configuration flow.• Existing tenants (onboarded before July 26, 2026): You will continue to see both standalone Marketplace integrations and unified Connectors. Refer to the specific documentation for each vendor to determine the supported configuration method for your account.• Existing tenants (onboarded before July 26, 2026): You will continue to see both standalone Marketplace integrations and unified Connectors. Refer to the specific documentation for each vendor to determine the supported configuration method for your account.### Clarifying terminology: Data sources and connectors### Clarifying terminology: Data sources and connectorsIn the Cortex XSIAM user interface (UI), configuring ingestion involves different areas and terminologies depending on the type of connection and your tenant onboarding date. While Cortex XSIAM is introducing connectors as a new, unified approach to ingestion, traditional Data Source methods remain supported.In the Cortex XSIAM user interface (UI), configuring ingestion involves different areas and terminologies depending on the type of connection and your tenant onboarding date. While Cortex XSIAM is introducing connectors as a new, unified approach to ingestion, traditional data source methods remain supported.In the current intermediate state, it is important to understand how these terms relate to each other:In the current intermediate state, it is important to understand how these terms relate to each other:• Data sources: Represents the traditional method for any integration that provides data to Cortex XSIAM. In this documentation, Data Source is used as the category for these ingestion methods, which include:• Data sources: Represents the traditional method for any integration that provides data to Cortex XSIAM. In this documentation, Data Source is used as the category for these ingestion methods, which include:• Data collectors: Built-in tools primarily focused on raw log ingestion. This includes generic logs ingested via XDR Collectors and core ingestion functionalities found using the Data Source Onboarder.• Data collectors: Built-in tools primarily focused on raw log ingestion. This includes generic logs ingested via XDR Collectors and core ingestion functionalities found using the Data Source Onboarder.• Broker VM applets: Specialized applications running on the Broker VM that function as collectors, such as the Syslog Collector.• Broker VM applets: Specialized applications running on the Broker VM that function as collectors, such as the Syslog Collector.• Marketplace (integrations): Content packs that include collection integrations. These are often referred to as data sources in the UI, as integrations that fetch data are configured through the Data Source Onboarder on the Data Sources & Integrations page.• Marketplace (integrations): Content packs that include collection integrations. These are often referred to as data sources in the UI, as integrations that fetch data are configured through the Data Source Onboarder on the Data Sources & Integrations page.Show markdown source
@@ -12,17 +12,17 @@ Data sources and connectors are the foundational mechanisms used to ingest secur The ingestion methods and configuration options available to you in the UI depend on your tenant onboarding date: * **New tenants (onboarded after July 26, 2026)**: You will primarily interact with the strategic Connector experience. Standalone Marketplace integrations that have been consolidated into connectors are hidden from the catalog to ensure a unified configuration flow. * **Existing tenants (onboarded before July 26, 2026)**: You will continue to see both standalone Marketplace integrations and unified Connectors. Refer to the specific documentation for each vendor to determine the supported configuration method for your account. ### **Clarifying terminology: Data sources and connectors** -In the Cortex XSIAM user interface (UI), configuring ingestion involves different areas and terminologies depending on the type of connection and your tenant onboarding date. While Cortex XSIAM is introducing connectors as a new, unified approach to ingestion, traditional Data Source methods remain supported. +In the Cortex XSIAM user interface (UI), configuring ingestion involves different areas and terminologies depending on the type of connection and your tenant onboarding date. While Cortex XSIAM is introducing connectors as a new, unified approach to ingestion, traditional data source methods remain supported. In the current intermediate state, it is important to understand how these terms relate to each other: * **Data sources**: Represents the traditional method for any integration that provides data to Cortex XSIAM. In this documentation, Data Source is used as the category for these ingestion methods, which include: * **Data collectors**: Built-in tools primarily focused on raw log ingestion. This includes generic logs ingested via XDR Collectors and core ingestion functionalities found using the Data Source Onboarder. * **Broker VM applets**: Specialized applications running on the Broker VM that function as collectors, such as the Syslog Collector. * **Marketplace (integrations)**: Content packs that include collection integrations. These are often referred to as data sources in the UI, as integrations that fetch data are configured through the Data Source Onboarder on the **Data Sources & Integrations** page.
-
▸ ▾ Automate remediation for the Cortex Advanced Email Security module modified +0 −6
xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/automate-remediation-for-the-cortex-advanced-email-security-moduleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,8 @@---description: >-Automated response actions through the Cortex Advanced Email Security moduleimprove efficiency and reduce noise.---# Automate remediation for the Cortex Advanced Email Security module# Automate remediation for the Cortex Advanced Email Security moduleThe lightweight, real-time response engine inside the Advanced Email Security module executes automatic policy-driven actions to quickly respond to email threats before they manifest. Build your policy from the rules you configure by customizing the out-of-the-box templates.The lightweight, real-time response engine inside the Advanced Email Security module executes automatic policy-driven actions to quickly respond to email threats before they manifest. Build your policy from the rules you configure by customizing the out-of-the-box templates.Define the rules for your email security policy in Email Remediation Response Rules, located in Modules → Email Security → Remediation → Rules.Define the rules for your email security policy in Email Remediation Response Rules, located in Modules → Email Security → Remediation → Rules.Review all the remediation actions initiated by your policy in the Email Remediation Action Center, located in Modules → Email Security → Remediation → Action Center.Review all the remediation actions initiated by your policy in the Email Remediation Action Center, located in Modules → Email Security → Remediation → Action Center.Show markdown source
@@ -1,14 +1,8 @@ ---- -description: >- - Automated response actions through the Cortex Advanced Email Security module - improve efficiency and reduce noise. ---- - # Automate remediation for the Cortex Advanced Email Security module The lightweight, real-time response engine inside the Advanced Email Security module executes automatic policy-driven actions to quickly respond to email threats before they manifest. Build your policy from the rules you configure by customizing the out-of-the-box templates. Define the rules for your email security policy in Email Remediation Response Rules, located in **Modules** → **Email Security** → **Remediation** → **Rules**. Review all the remediation actions initiated by your policy in the Email Remediation Action Center, located in **Modules** → **Email Security** → **Remediation** → **Action Center**.
-
▸ ▾ Cortex Advanced Email Security module architecture and data flow modified +0 −7
xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-module-architecture-and-data-flowRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,15 +1,8 @@---description: >-The Cortex Advanced Email Security module, a cloud-native system, integratesmultiple components to ingest, analyze, and respond to email-borne threatseffectively.---# Cortex Advanced Email Security module architecture and data flow# Cortex Advanced Email Security module architecture and data flowThe Cortex Advanced Email Security module is composed of several logical components, deployed in a cloud-native architecture. These components work together to ingest, analyze, and respond to email-borne threats.The Cortex Advanced Email Security module is composed of several logical components, deployed in a cloud-native architecture. These components work together to ingest, analyze, and respond to email-borne threats.🖼 Simplified_Email_Security_Architecture__2_.png🖼 Simplified_Email_Security_Architecture__2_.pngShow markdown source
@@ -1,15 +1,8 @@ ---- -description: >- - The Cortex Advanced Email Security module, a cloud-native system, integrates - multiple components to ingest, analyze, and respond to email-borne threats - effectively. ---- - # Cortex Advanced Email Security module architecture and data flow The Cortex Advanced Email Security module is composed of several logical components, deployed in a cloud-native architecture. These components work together to ingest, analyze, and respond to email-borne threats.  <details>
-
▸ ▾ Cortex Advanced Email Security module overview modified +0 −4
xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-module-overviewRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,8 @@---description: Learn how to onboard, configure, and operate the Email Security module.---# Cortex Advanced Email Security module overview# Cortex Advanced Email Security module overviewhint warninghint warning### Prerequisite### PrerequisiteThe following are prerequisites for using the Cortex XSIAM Advanced Email Security module.The following are prerequisites for using the Cortex XSIAM Advanced Email Security module.endhintendhintShow markdown source
@@ -1,12 +1,8 @@ ---- -description: Learn how to onboard, configure, and operate the Email Security module. ---- - # Cortex Advanced Email Security module overview {% hint style="warning" %} ### Prerequisite The following are prerequisites for using the Cortex XSIAM Advanced Email Security module. {% endhint %} -
▸ ▾ Cortex Advanced Email Security threat detection and issues modified +0 −6
xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/cortex-advanced-email-security-threat-detection-and-issuesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,8 @@---description: >-The Cortex Advanced Email Security module uses artifact-based,metadata-driven, and LLM-powered engines to generate detections and insights.---# Cortex Advanced Email Security threat detection and issues# Cortex Advanced Email Security threat detection and issuesThe Cortex Advanced Email Security module supports a wide range of detection types, designed to identify malicious, suspicious, or policy-violating emails. These detections are generated by the artifact-based, metadata-driven, and LLM-powered engines described in the Architecture and Data Flow section.The Cortex Advanced Email Security module supports a wide range of detection types, designed to identify malicious, suspicious, or policy-violating emails. These detections are generated by the artifact-based, metadata-driven, and LLM-powered engines described in the Architecture and Data Flow section.Threat detection categoriesThreat detection categoriesShow markdown source
@@ -1,14 +1,8 @@ ---- -description: >- - The Cortex Advanced Email Security module uses artifact-based, - metadata-driven, and LLM-powered engines to generate detections and insights. ---- - # Cortex Advanced Email Security threat detection and issues The Cortex Advanced Email Security module supports a wide range of detection types, designed to identify malicious, suspicious, or policy-violating emails. These detections are generated by the artifact-based, metadata-driven, and LLM-powered engines described in the Architecture and Data Flow section. <details> <summary>Threat detection categories</summary>
-
▸ ▾ Deploy and configure the Email Security module modified +0 −4
xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/deploy-and-configure-the-email-security-moduleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,8 @@---description: Configure the Microsoft O365 integration and the module.---# Deploy and configure the Email Security module# Deploy and configure the Email Security moduleTo start using the Cortex Advanced Email Security module, configure the Microsoft O365 integration and then configure the module.To start using the Cortex Advanced Email Security module, configure the Microsoft O365 integration and then configure the module.### Integrate Microsoft 365 with the Cortex Advanced Email Security Module### Integrate Microsoft 365 with the Cortex Advanced Email Security ModuleDeploy the Cortex Advanced Email Security module by configuring integration permissions and settings for Microsoft 365.Deploy the Cortex Advanced Email Security module by configuring integration permissions and settings for Microsoft 365.Show markdown source
@@ -1,12 +1,8 @@ ---- -description: Configure the Microsoft O365 integration and the module. ---- - # Deploy and configure the Email Security module To start using the Cortex Advanced Email Security module, configure the Microsoft O365 integration and then configure the module. ### Integrate Microsoft 365 with the Cortex Advanced Email Security Module Deploy the Cortex Advanced Email Security module by configuring integration permissions and settings for Microsoft 365.
-
▸ ▾ Mailbox Inventory modified +0 −4
xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/mailbox-inventoryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,8 @@---description: View and manage your active email security assets---# Mailbox Inventory# Mailbox Inventoryhint infohint info### Notice### NoticeRequires the Advanced Email Security add-on.Requires the Advanced Email Security add-on.endhintendhintShow markdown source
@@ -1,12 +1,8 @@ ---- -description: View and manage your active email security assets ---- - # Mailbox Inventory {% hint style="info" %} ### Notice Requires the Advanced Email Security add-on. {% endhint %} -
▸ ▾ Malicious Email Inventory modified +0 −4
xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security/malicious-email-inventoryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,8 @@---description: Triage, analyze, and act on malicious email threats---# Malicious Email Inventory# Malicious Email Inventoryhint infohint info### Notice### NoticeRequires the Advanced Email Security module.Requires the Advanced Email Security module.endhintendhintShow markdown source
@@ -1,12 +1,8 @@ ---- -description: Triage, analyze, and act on malicious email threats ---- - # Malicious Email Inventory {% hint style="info" %} ### Notice Requires the Advanced Email Security module. {% endhint %} -
▸ ▾ Prevent malicious LDAP queries modified +1 −1 The Set up Identity Profiles link now resolves to the ITDR getting-started anchor instead of broken-reference.
xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/prevent-malicious-ldap-queriesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -15,9 +15,9 @@ The module identifies and blocks the unique signatures of specific reconnaissanc### Key Benefits### Key BenefitsImplementing this protection provides you with two primary advantages:Implementing this protection provides you with two primary advantages:• Real-Time prevention: Stops attacks proactively during the reconnaissance phase. By blocking the LDAP queries, the system blinds the attacker and forces them to operate without a map of your environment.• Real-Time prevention: Stops attacks proactively during the reconnaissance phase. By blocking the LDAP queries, the system blinds the attacker and forces them to operate without a map of your environment.• Enriched analytics: Every blocked query is fed back into the Cortex ITDR analytics engine. This data generates detailed issues within Cortex XSIAM, giving you actionable intelligence on exactly which tool was being used and who the attacker was targeting.• Enriched analytics: Every blocked query is fed back into the Cortex ITDR analytics engine. This data generates detailed issues within Cortex XSIAM, giving you actionable intelligence on exactly which tool was being used and who the attacker was targeting.To enable LDAP protection, toggle the LDAP protection setting in the Identity profile of the agent. To configure the Identity profile, see Set up Identity Profiles.To enable LDAP protection, toggle the LDAP protection setting in the Identity profile of the agent. To configure the Identity profile, see Set up Identity Profiles.Show markdown source
@@ -15,9 +15,9 @@ The module identifies and blocks the unique signatures of specific reconnaissanc ### Key Benefits Implementing this protection provides you with two primary advantages: * Real-Time prevention: Stops attacks proactively during the reconnaissance phase. By blocking the LDAP queries, the system blinds the attacker and forces them to operate without a map of your environment. * Enriched analytics: Every blocked query is fed back into the Cortex ITDR analytics engine. This data generates detailed issues within Cortex XSIAM, giving you actionable intelligence on exactly which tool was being used and who the attacker was targeting. -To enable LDAP protection, toggle the **LDAP protection** setting in the Identity profile of the agent. To configure the Identity profile, see [Set up Identity Profiles](broken-reference). +To enable LDAP protection, toggle the **LDAP protection** setting in the Identity profile of the agent. To configure the Identity profile, see [Set up Identity Profiles](../get-started-with-itdr#set-up-identity-profiles).
-
▸ ▾ About the Query Builder modified +0 −6
xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/about-the-query-builderRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,14 +1,8 @@---description: >-The Query Builder facilitates threat detection, case expansion, and dataanalytics for suspected threats.---# About the Query Builder# About the Query BuilderThe Query Builder aids in the detection of threats by allowing you to search for indicators of compromise and suspicious patterns within data sources. It assists in expanding case investigations by identifying related events and entities, such as activities associated with specific user accounts or network lateral movement. In addition, the Query Builder enables data analytics on suspected threats, helping organizations analyze large volumes of data to identify trends, anomalies, and correlations that may indicate potential security issues.The Query Builder aids in the detection of threats by allowing you to search for indicators of compromise and suspicious patterns within data sources. It assists in expanding case investigations by identifying related events and entities, such as activities associated with specific user accounts or network lateral movement. In addition, the Query Builder enables data analytics on suspected threats, helping organizations analyze large volumes of data to identify trends, anomalies, and correlations that may indicate potential security issues.To support investigation and analysis, you can search all of the data ingested by Cortex XSIAM by creating queries in the Query Builder. You can create queries that investigate leads, expose the root cause of an issue, perform damage assessment, and hunt for threats from your data sources.To support investigation and analysis, you can search all of the data ingested by Cortex XSIAM by creating queries in the Query Builder. You can create queries that investigate leads, expose the root cause of an issue, perform damage assessment, and hunt for threats from your data sources.Cortex XSIAM provides different options in the Query Builder for creating queries:Cortex XSIAM provides different options in the Query Builder for creating queries:Show markdown source
@@ -1,14 +1,8 @@ ---- -description: >- - The Query Builder facilitates threat detection, case expansion, and data - analytics for suspected threats. ---- - # About the Query Builder The Query Builder aids in the detection of threats by allowing you to search for indicators of compromise and suspicious patterns within data sources. It assists in expanding case investigations by identifying related events and entities, such as activities associated with specific user accounts or network lateral movement. In addition, the Query Builder enables data analytics on suspected threats, helping organizations analyze large volumes of data to identify trends, anomalies, and correlations that may indicate potential security issues. To support investigation and analysis, you can search all of the data ingested by Cortex XSIAM by creating queries in the Query Builder. You can create queries that investigate leads, expose the root cause of an issue, perform damage assessment, and hunt for threats from your data sources. Cortex XSIAM provides different options in the Query Builder for creating queries:
-
▸ ▾ How to build XQL queries modified +0 −4
xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queriesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,8 @@---description: Learn more about how to build XQL queries in the Query Builder.---# How to build XQL queries# How to build XQL queriesThe Cortex Query Language (XQL) enables you to query data ingested into Cortex XSIAM for rigorous endpoint and network event analysis. To help you create an effective XQL query with the proper syntax, the query field in the user interface provides suggestions and definitions as you type.The Cortex Query Language (XQL) enables you to query data ingested into Cortex XSIAM for rigorous endpoint and network event analysis. To help you create an effective XQL query with the proper syntax, the query field in the user interface provides suggestions and definitions as you type.XQL forms queries in stages. Each stage performs a specific query operation and is separated by a pipe character ( ). Queries require a dataset, or data source, to run against. You can either query the Cortex Data Model (XDM) or you can query specific datasets. In a dataset query, unless otherwise specified, the query runs against the xdr_datadataset, which contains all log information that Cortex XSIAM collects from all Cortex product agents, including EDR data, and PAN NGFW data. In XDM queries, you must specify the dataset mapped to the XDM that you want to run your query against.XQL forms queries in stages. Each stage performs a specific query operation and is separated by a pipe character ( ). Queries require a dataset, or data source, to run against. You can either query the Cortex Data Model (XDM) or you can query specific datasets. In a dataset query, unless otherwise specified, the query runs against the xdr_datadataset, which contains all log information that Cortex XSIAM collects from all Cortex product agents, including EDR data, and PAN NGFW data. In XDM queries, you must specify the dataset mapped to the XDM that you want to run your query against.hint infohint infoForensic datasets are not included by default in XQL query results, unless the dataset query is explicitly defined to use a forensic dataset.Forensic datasets are not included by default in XQL query results, unless the dataset query is explicitly defined to use a forensic dataset.Show markdown source
@@ -1,12 +1,8 @@ ---- -description: Learn more about how to build XQL queries in the Query Builder. ---- - # How to build XQL queries The Cortex Query Language (XQL) enables you to query data ingested into Cortex XSIAM for rigorous endpoint and network event analysis. To help you create an effective XQL query with the proper syntax, the query field in the user interface provides suggestions and definitions as you type. XQL forms queries in stages. Each stage performs a specific query operation and is separated by a pipe character (|). Queries require a dataset, or data source, to run against. You can either query the Cortex Data Model (XDM) or you can query specific datasets. In a dataset query, unless otherwise specified, the query runs against the **`xdr_data`** dataset, which contains all log information that Cortex XSIAM collects from all Cortex product agents, including EDR data, and PAN NGFW data. In XDM queries, you must specify the dataset mapped to the XDM that you want to run your query against. {% hint style="info" %} Forensic datasets are not included by default in XQL query results, unless the dataset query is explicitly defined to use a forensic dataset. -
▸ ▾ Create XQL query modified +6 −7 The dataset query procedure now starts at Search → XQL Search, dropping the separate Query Builder and XQL steps.
xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/create-xql-queryRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -57,28 +57,27 @@ While the query is running, you can navigate away from the page. A notificationendhintendhint</details></details>How to create a dataset queryHow to create a dataset query1. From Cortex XSIAM, select Investigation & Response → Search → Query Builder.1. From Cortex XSIAM, select Investigation & Response → Search → XQL Search.2. Click XQL.2. (Optional) Change the default time period against which to run your query from the time picker at the top right of the window. You can select the required Timeframe from any of the following options available:3. (Optional) Change the default time period against which to run your query from the time picker at the top right of the window. You can select the required Timeframe from any of the following options available:• Preset time ranges easily available to select from, such as 24 hours and 30 days.• Preset time ranges easily available to select from, such as 24 hours and 30 days.• Recently used selections from your previous queries.• Recently used selections from your previous queries.• Relative time: Define the time frame as the last <number> minutes, days, or hours by setting the number.• Relative time: Define the time frame as the last <number> minutes, days, or hours by setting the number.• Calendar: Create a customized time period by selecting the date range from the calendar and the specific Start Time and End Time.• Calendar: Create a customized time period by selecting the date range from the calendar and the specific Start Time and End Time.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><ul><li>Whenever the time period is changed in the query window, the <code>config timeframe</code> is automatically set to the time period defined for the entire query, including queries that are part of the <code>join</code> stage. Yet, this won't be visible as part of the query. Only if you manually type in the <code>config timeframe</code> will this be seen in the query.</li><li>These time picker options are available in XQL queries when using the Query Builder, XQL Widgets, and when defining XQL Widgets in Reports and Dashboards.</li></ul></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><ul><li>Whenever the time period is changed in the query window, the <code>config timeframe</code> is automatically set to the time period defined for the entire query, including queries that are part of the <code>join</code> stage. Yet, this won't be visible as part of the query. Only if you manually type in the <code>config timeframe</code> will this be seen in the query.</li><li>These time picker options are available in XQL queries when using the Query Builder, XQL Widgets, and when defining XQL Widgets in Reports and Dashboards.</li></ul></div>4. (Optional) To translate Splunk queries to XQL queries, enable Translate to XQL. If you choose to use this feature, enter your Splunk query in the Splunk field, click the arrow icon (
) to convert to XQL, and skip to Step 6.
3. (Optional) To translate Splunk queries to XQL queries, enable Translate to XQL. If you choose to use this feature, enter your Splunk query in the Splunk field, click the arrow icon (
) to convert to XQL, and skip to Step 6.
5. Create your query by typing in the query field. Relevant commands, their definitions, and operators are suggested as you type.4. Create your query by typing in the query field. Relevant commands, their definitions, and operators are suggested as you type.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Tip</h3><p>When creating XQL queries, you can:</p><ul><li>Use the up and down arrow keys to navigate through the auto-suggestion command suggestions and definitions.</li><li>Select an auto-suggestion command by pressing either the <strong>Enter</strong> or <strong>Tab</strong> key.</li><li>Press <strong>Shift</strong>+<strong>Enter</strong> to add a new line, and easily ignore the auto-suggestion output.</li><li>Close the auto-suggestion output by pressing the <strong>Esc</strong> key.</li></ul></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Tip</h3><p>When creating XQL queries, you can:</p><ul><li>Use the up and down arrow keys to navigate through the auto-suggestion command suggestions and definitions.</li><li>Select an auto-suggestion command by pressing either the <strong>Enter</strong> or <strong>Tab</strong> key.</li><li>Press <strong>Shift</strong>+<strong>Enter</strong> to add a new line, and easily ignore the auto-suggestion output.</li><li>Close the auto-suggestion output by pressing the <strong>Esc</strong> key.</li></ul></div>1. (Optional) Specify a dataset.1. (Optional) Specify a dataset.You only need to specify a dataset if you are running your query against a dataset that you have not set as default. Otherwise, the query runs against the **`xdr_data`** dataset. For more information, see [How to build XQL queries]().You only need to specify a dataset if you are running your query against a dataset that you have not set as default. Otherwise, the query runs against the **`xdr_data`** dataset. For more information, see [How to build XQL queries]().Example:Example:@@ -91,20 +90,20 @@ While the query is running, you can navigate away from the page. A notification```programlisting```programlistingdataset = xdr_datadataset = xdr_data| filter agent_os_type = ENUM.AGENT_OS_MAC| filter agent_os_type = ENUM.AGENT_OS_MAC| limit 250| limit 250``````6. Choose when to run your query:5. Choose when to run your query:• Run the query immediately.• Run the query immediately.• Run the query by the specified date and time, or on a specific date, by selecting the calendar icon (🖼 query-calendar-icon.png).• Run the query by the specified date and time, or on a specific date, by selecting the calendar icon (🖼 query-calendar-icon.png).7. (Optional) The Save As options save your query for future use:6. (Optional) The Save As options save your query for future use:• BIOC Rule: When compatible, saves the query as a BIOC rule. The XQL query must contain a filter for the event_type field.• BIOC Rule: When compatible, saves the query as a BIOC rule. The XQL query must contain a filter for the event_type field.• Correlation Rule: When compatible, saves the query as a Correlation Rule. For more information, see What's a correlation rule?.• Correlation Rule: When compatible, saves the query as a Correlation Rule. For more information, see What's a correlation rule?.• Query to Library: Saves the query to your personal query library. For more information, see Manage your personal query library.• Query to Library: Saves the query to your personal query library. For more information, see Manage your personal query library.• Widget to Library: For more information, see Create XQL widgets.• Widget to Library: For more information, see Create XQL widgets.hint infohint info### Tip### TipShow markdown source
@@ -57,28 +57,27 @@ While the query is running, you can navigate away from the page. A notification {% endhint %} </details> <details> <summary>How to create a dataset query</summary> -1. From Cortex XSIAM, select **Investigation & Response** → **Search** → **Query Builder**. -2. Click **XQL**. -3. _(Optional)_ Change the default time period against which to run your query from the time picker at the top right of the window. You can select the required **Timeframe** from any of the following options available: +1. From Cortex XSIAM, select **Investigation & Response** → **Search** → **XQL Search**. +2. _(Optional)_ Change the default time period against which to run your query from the time picker at the top right of the window. You can select the required **Timeframe** from any of the following options available: * Preset time ranges easily available to select from, such as **24 hours** and **30 days**. * Recently used selections from your previous queries. * **Relative time**: Define the time frame as the last \<number> minutes, days, or hours by setting the number. * **Calendar**: Create a customized time period by selecting the date range from the calendar and the specific **Start Time** and **End Time**. <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><ul><li>Whenever the time period is changed in the query window, the <code>config timeframe</code> is automatically set to the time period defined for the entire query, including queries that are part of the <code>join</code> stage. Yet, this won't be visible as part of the query. Only if you manually type in the <code>config timeframe</code> will this be seen in the query.</li><li>These time picker options are available in XQL queries when using the Query Builder, XQL Widgets, and when defining XQL Widgets in Reports and Dashboards.</li></ul></div> -4. _(Optional)_ To translate Splunk queries to XQL queries, enable **Translate to XQL**. If you choose to use this feature, enter your Splunk query in the **Splunk** field, click the arrow icon (<img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2Fgit-blob-71323bbde54be11af6b419e0c345f2d01f50d2f5%2F49c8fc73157209b7a766a070aef61257efb9b7d6ddc22957f2c8ae2c8e9084a2.png?alt=media" alt="translate-to-spl-arrow.png" data-size="line">) to convert to XQL, and skip to Step 6. -5. Create your query by typing in the query field. Relevant commands, their definitions, and operators are suggested as you type. +3. _(Optional)_ To translate Splunk queries to XQL queries, enable **Translate to XQL**. If you choose to use this feature, enter your Splunk query in the **Splunk** field, click the arrow icon (<img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2Fgit-blob-71323bbde54be11af6b419e0c345f2d01f50d2f5%2F49c8fc73157209b7a766a070aef61257efb9b7d6ddc22957f2c8ae2c8e9084a2.png?alt=media" alt="translate-to-spl-arrow.png" data-size="line">) to convert to XQL, and skip to Step 6. +4. Create your query by typing in the query field. Relevant commands, their definitions, and operators are suggested as you type. <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Tip</h3><p>When creating XQL queries, you can:</p><ul><li>Use the up and down arrow keys to navigate through the auto-suggestion command suggestions and definitions.</li><li>Select an auto-suggestion command by pressing either the <strong>Enter</strong> or <strong>Tab</strong> key.</li><li>Press <strong>Shift</strong>+<strong>Enter</strong> to add a new line, and easily ignore the auto-suggestion output.</li><li>Close the auto-suggestion output by pressing the <strong>Esc</strong> key.</li></ul></div> 1. (Optional) Specify a dataset. You only need to specify a dataset if you are running your query against a dataset that you have not set as default. Otherwise, the query runs against the **`xdr_data`** dataset. For more information, see [How to build XQL queries](). Example: @@ -91,20 +90,20 @@ While the query is running, you can navigate away from the page. A notification ```programlisting dataset = xdr_data | filter agent_os_type = ENUM.AGENT_OS_MAC | limit 250 ``` -6. Choose when to run your query: +5. Choose when to run your query: * Run the query immediately. * Run the query by the specified date and time, or on a specific date, by selecting the calendar icon (). -7. _(Optional)_ The Save As options save your query for future use: +6. _(Optional)_ The Save As options save your query for future use: * **BIOC Rule**: When compatible, saves the query as a BIOC rule. The XQL query must contain a filter for the **event\_type** field. * **Correlation Rule**: When compatible, saves the query as a Correlation Rule. For more information, see [What's a correlation rule?](../../../threat-management/detection-rules/what-are-detection-rules/whats-a-correlation-rule). * **Query to Library**: Saves the query to your personal query library. For more information, see [Manage your personal query library](../manage-your-personal-query-library). * **Widget to Library**: For more information, see [Create XQL widgets](../../../monitor-dashboards-and-reports/advanced-configuration/create-custom-widgets/create-xql-widgets). {% hint style="info" %} ### Tip -
▸ ▾ Graph query results modified +1 −1
xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/graph-query-resultsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,17 +3,17 @@To help you better understand your Cortex Query Language (XQL) query results and share your insights with others, Cortex XSIAM enables you to generate graphs and outputs of your query data directly from query results page.To help you better understand your Cortex Query Language (XQL) query results and share your insights with others, Cortex XSIAM enables you to generate graphs and outputs of your query data directly from query results page.hint infohint info### Tip### TipAlternatively, you can use the Cortex Agentic Assistant to generate custom graphs and charts using natural language prompts. By simply prompting the agent, it will build and execute the query, returning the visual representation. For more information, see Use natural language to query and visualize your data.Alternatively, you can use the Cortex Agentic Assistant to generate custom graphs and charts using natural language prompts. By simply prompting the agent, it will build and execute the query, returning the visual representation. For more information, see Use natural language to query and visualize your data.endhintendhint1. Select Investigation & Response → Search → Query Builder → XQL.1. Select Investigation & Response → Search → XQL Search.2. Run an XQL query.2. Run an XQL query.Enter the following query:Enter the following query:```programlisting```programlistingdataset = xdr_datadataset = xdr_data| fields action_total_upload, _time| fields action_total_upload, _time| limit 10| limit 10Show markdown source
@@ -3,17 +3,17 @@ To help you better understand your Cortex Query Language (XQL) query results and share your insights with others, Cortex XSIAM enables you to generate graphs and outputs of your query data directly from query results page. {% hint style="info" %} ### Tip Alternatively, you can use the Cortex Agentic Assistant to generate custom graphs and charts using natural language prompts. By simply prompting the agent, it will build and execute the query, returning the visual representation. For more information, see [Use natural language to query and visualize your data](../../../agentic-assistant-chat/use-natural-language-to-query-and-visualize-your-data). {% endhint %} -1. Select **Investigation & Response** → **Search** → **Query Builder** → **XQL**. +1. Select **Investigation & Response** → **Search** → **XQL Search**. 2. Run an XQL query. Enter the following query: ```programlisting dataset = xdr_data | fields action_total_upload, _time | limit 10