Documentation — August 23, 2026
433 files changed, 2127 insertions, 434 deletions — view the commit on the mirror.
A 431-page metadata and structure pass across Cortex XSIAM; UPN becomes a mandatory XDM authentication field
- 366 of the 434 changed files touch nothing but their
description:frontmatter — a metadata pass over almost the whole Cortex XSIAM book. - The XDM authentication mapping reference carries the day’s only substantive change:
xdm.source.user.upnis promoted from optional to mandatory, and a newOPERATION_TYPE_AUDITconstant is added. - Structural cleanup elsewhere: bold pseudo-headings promoted to real
###headings in 22 files, and “Note”/”Notice” sub-headings stripped from 14 callouts. - Five pages moved their numbered procedures into GitBook
{% stepper %}blocks. - Six pages were retitled. No page was added, removed, or moved — every one of the 434 entries is a modification.
Highlights
-
xdm.source.user.upn is now a mandatory XDM authentication field
It moved out of the collapsed "Authentication identity and context" optional section into the mandatory list as field 12, pushing xdm.event.outcome_reason to 13.
-
New XDM_CONST.OPERATION_TYPE_AUDIT constant for authorization and policy evaluation events
An accompanying note tells mappers there is no neutral member: leave the field unmapped when the kind is unclear, and unset for logouts, so logout events do not inflate login metrics.
-
409 pages gained or rewrote a description: frontmatter line
The new descriptions consistently name the product ("in Cortex XSIAM") where the old ones did not, and 366 pages changed in no other way.
-
Six pages were retitled without moving
"About health issues" became "Health issues in Cortex XSIAM", "Extract Indicators" became "Extract indicators in playbooks", and four others; the nav manifest records the new titles against unchanged paths, so no link or bookmark breaks.
-
Numbered procedures converted to GitBook stepper blocks on five pages
Registering an agent action and adding an integration instance both gained per-step headings in the process, but the steps themselves are unchanged.
-
Callout hints lost their redundant "Note" and "Notice" headings
Fourteen occurrences across nine pages, including three legacy data-gb-custom-block divs rewritten to the {% hint %} shorthand.
Bulk change — 433 files. Per-file diffs are not stored for a change this size; view it on the mirror.
Changes
433 files listed, 15 written up and shaded below.
-
▸ ▾ Podman modified +1 −1
xsiam/configure-cortex-xsiam/engines/install-an-engine/podmanRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Change the Container storage modified +1 −1
xsiam/configure-cortex-xsiam/engines/install-an-engine/podman/change-the-container-storageRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Migrate from Docker to Podman modified +1 −1
xsiam/configure-cortex-xsiam/engines/install-an-engine/podman/migrate-from-docker-to-podmanRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Troubleshoot Podman modified +3 −1
xsiam/configure-cortex-xsiam/engines/install-an-engine/podman/troubleshoot-podmanRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Manage engines modified +3 −1
xsiam/configure-cortex-xsiam/engines/manage-enginesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remove an engine modified +1 −3
xsiam/configure-cortex-xsiam/engines/remove-an-engineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Run a script using an engine modified +1 −3
xsiam/configure-cortex-xsiam/engines/run-a-script-using-an-engineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Troubleshoot engines modified +4 −2
xsiam/configure-cortex-xsiam/engines/troubleshoot-enginesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Troubleshoot integrations running on engines modified +4 −0
xsiam/configure-cortex-xsiam/engines/troubleshoot-integrations-running-on-enginesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Upgrade an engine modified +5 −5
xsiam/configure-cortex-xsiam/engines/upgrade-an-engineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Use an engine in an integration modified +2 −2
xsiam/configure-cortex-xsiam/engines/use-an-engine-in-an-integrationRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ What is an engine? modified +6 −0
xsiam/configure-cortex-xsiam/engines/what-is-an-engineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Marketplace modified +5 −5
xsiam/configure-cortex-xsiam/marketplaceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Content changes when upgrading Cortex XSIAM versions modified +3 −1
xsiam/configure-cortex-xsiam/marketplace/content-changes-when-upgrading-cortex-xsiam-versionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Content pack contributions modified +1 −1
xsiam/configure-cortex-xsiam/marketplace/content-pack-contributionsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Content Pack Support Types modified +5 −7
xsiam/configure-cortex-xsiam/marketplace/content-pack-support-typesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Content packs modified +2 −2
xsiam/configure-cortex-xsiam/marketplace/content-packsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cortex Marketplace modified +2 −2
xsiam/configure-cortex-xsiam/marketplace/cortex-marketplaceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Manage content packs modified +1 −1
xsiam/configure-cortex-xsiam/marketplace/manage-content-packsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Marketplace FAQs modified +1 −1
xsiam/configure-cortex-xsiam/marketplace/marketplace-faqsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Agentic AI in Cortex XSIAM modified +3 −3
xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiamRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Agentic Assistant security modified +2 −2
xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiam/agentic-assistant-securityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Agentic Assistant use cases modified +3 −1
xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiam/agentic-assistant-use-casesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Compare Agentic Assistant with Cortex Assistant modified +3 −1
xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiam/compare-agentic-assistant-with-cortex-assistantRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure Cortex XSIAM network parameters modified +7 −7
xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-analytics/configure-cortex-xsiam-network-parametersRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure global agent settings modified +1 −1
xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/configure-global-agent-settingsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Define endpoint groups modified +1 −1
xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/define-endpoint-groupsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Deploy installation packages modified +1 −1
xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/deploy-installation-packagesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Endpoint data collection modified +1 −1
xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/endpoint-data-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Guidelines for keeping Cortex XDR agents and content updated modified +1 −1
xsiam/onboard-cortex-xsiam/deployment-steps/install-cortex-xdr-agents/guidelines-for-keeping-cortex-xdr-agents-and-content-updatedRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Configure external applications for forwarding modified +6 −0
xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwardingRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Forward notifications to Amazon SQS modified +7 −0
xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-sqsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ XDM fields for mapping authentication events modified +25 −16 Makes xdm.source.user.upn mandatory, adds the OPERATION_TYPE_AUDIT constant, and drops a sentence duplicated in the IDP/SP mapping note.
xsiam/reference-and-developer-docs/reference/xdm-fields-for-mapping-authentication-eventsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Diffs are not stored for a change this size — view it on the mirror.