Documentation — September 01, 2026
99 files changed, 429 insertions, 159 deletions — view the commit on the mirror.
MongoDB Atlas (Posture) onboarding added; the Cloud Posture source list grows to about 100 connectors
- A new MongoDB Atlas (Posture) onboarding page lands, and the Cloud Posture and Runtime Security source list expands from 9 entries to roughly 100.
- Twelve Analytics pages move out of Analytics overview to sit directly under Analytics, breaking existing links to the old paths.
- ITDR deployment gains a required CyberArk ISP step, and compute units are now documented as consumed by XQL queries only.
- 27 Linux kernel support pages gain 96 kernel builds between them, with none withdrawn.
- Around 30 data source pages get description-only rewording from “data sources” to “data source and connectors”, plus a handful of typo fixes.
Highlights
-
MongoDB Atlas (Posture) is documented as a Cloud Posture data source
The new page covers the organization ID and service account client credentials, the generated script to run in the MongoDB CLI, and a regional IP allowlist for accounts behind network policies.
-
The Cloud Posture and Runtime Security source list jumps from 9 entries to about 100
It now names AI and SaaS connectors — Claude, ChatGPT Enterprise, Microsoft 365 Copilot, Copilot Studio, Gemini Enterprise, Cursor and Generic MCP among them — alongside container registries and SIEM connectors.
-
Twelve Analytics pages moved up a level, out of Analytics overview
Analytics engine, sensors, MITRE coverage, Identity Analytics and the whole AI Detection & Response subtree now hang off Analytics directly, so links and bookmarks to the analytics-overview paths break.
-
ITDR deployment now requires the CyberArk ISP integration
It is inserted as step 4 of the checklist, and is what collects the audit events the analytics detectors run on.
-
Compute units are consumed by XQL queries only
A new note states that agentic and LLM information on the usage page is shown for information and does not draw down the quota.
-
96 kernel builds added across 27 Linux support pages, none withdrawn
Amazon Linux 2023, RHEL, AlmaLinux, Rocky, Oracle Linux, Debian 13, SLES 16, CentOS Stream 9 and Ubuntu 18 through 26 all gained rows; every kernel change in the day was an addition.
Changes
99 files listed, 10 written up and shaded below.
-
▸ ▾ README modified +1 −1
READMEGenerated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Navigation manifest (xsiam) modified +94 −89
.meta/xsiamThe book's page tree and ordering — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ AlmaLinux 10 [x86_64] modified +1 −0
linux-kernels/almalinuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -67,8 +67,9 @@ Cortex XDR agent supports the following kernel module versions for AlmaLinux 106.12.0-211.38.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.38.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.39.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.39.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.40.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.40.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.42.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.42.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.43.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.43.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.44.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.44.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.46.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.46.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.47.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.47.1.el10_2.x86_64│8.7.1│—│2390-403336.12.0-211.49.1.el10_2.x86_64│8.7.1│—│2410-40905Show markdown source
@@ -67,8 +67,9 @@ Cortex XDR agent supports the following kernel module versions for AlmaLinux 10 | 6.12.0-211.38.1.el10\_2.x86\_64 | 8.7.1 | — | 2390-40333 | | 6.12.0-211.39.1.el10\_2.x86\_64 | 8.7.1 | — | 2390-40333 | | 6.12.0-211.40.1.el10\_2.x86\_64 | 8.7.1 | — | 2390-40333 | | 6.12.0-211.42.1.el10\_2.x86\_64 | 8.7.1 | — | 2390-40333 | | 6.12.0-211.43.1.el10\_2.x86\_64 | 8.7.1 | — | 2390-40333 | | 6.12.0-211.44.1.el10\_2.x86\_64 | 8.7.1 | — | 2390-40333 | | 6.12.0-211.46.1.el10\_2.x86\_64 | 8.7.1 | — | 2390-40333 | | 6.12.0-211.47.1.el10\_2.x86\_64 | 8.7.1 | — | 2390-40333 | +| 6.12.0-211.49.1.el10\_2.x86\_64 | 8.7.1 | — | 2410-40905 |
-
▸ ▾ AlmaLinux 8 [x86_64] modified +1 −0
linux-kernels/almalinuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -150,9 +150,10 @@ Cortex XDR agent supports the following kernel module versions for AlmaLinux 8 \4.18.0-553.148.1.el8_10.x86_64│7.8│—│2390-397154.18.0-553.148.1.el8_10.x86_64│7.8│—│2390-397154.18.0-553.150.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.150.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.151.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.151.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.153.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.153.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.154.1.el8_10.x86_64│7.8│—│2390-403334.18.0-553.154.1.el8_10.x86_64│7.8│—│2390-403334.18.0-553.155.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.155.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.156.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.156.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.157.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.157.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.158.1.el8_10.x86_64│7.8│—│2410-409054.18.0-553.el8_10.x86_64│7.8│—│1450-871164.18.0-553.el8_10.x86_64│7.8│—│1450-87116Show markdown source
@@ -150,9 +150,10 @@ Cortex XDR agent supports the following kernel module versions for AlmaLinux 8 \ | 4.18.0-553.148.1.el8\_10.x86\_64 | 7.8 | — | 2390-39715 | | 4.18.0-553.150.1.el8\_10.x86\_64 | 7.8 | — | 2380-40068 | | 4.18.0-553.151.1.el8\_10.x86\_64 | 7.8 | — | 2380-40068 | | 4.18.0-553.153.1.el8\_10.x86\_64 | 7.8 | — | 2380-40068 | | 4.18.0-553.154.1.el8\_10.x86\_64 | 7.8 | — | 2390-40333 | | 4.18.0-553.155.1.el8\_10.x86\_64 | 7.8 | — | 2400-40648 | | 4.18.0-553.156.1.el8\_10.x86\_64 | 7.8 | — | 2400-40648 | | 4.18.0-553.157.1.el8\_10.x86\_64 | 7.8 | — | 2400-40648 | +| 4.18.0-553.158.1.el8\_10.x86\_64 | 7.8 | — | 2410-40905 | | 4.18.0-553.el8\_10.x86\_64 | 7.8 | — | 1450-87116 |
-
▸ ▾ AlmaLinux 9 [x86_64] modified +2 −0
linux-kernels/almalinuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -125,8 +125,10 @@ Cortex XDR agent supports the following kernel module versions for AlmaLinux 9 \5.14.0-687.29.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.29.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.30.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.30.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.31.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.31.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.33.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.33.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.34.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.34.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.36.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.36.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.39.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.39.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.41.1.el9_8.x86_64│7.9│—│2410-409055.14.0-687.42.1.el9_8.x86_64│7.9│—│2410-40905Show markdown source
@@ -125,8 +125,10 @@ Cortex XDR agent supports the following kernel module versions for AlmaLinux 9 \ | 5.14.0-687.29.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.30.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.31.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.33.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.34.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.36.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.38.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.39.1.el9\_8.x86\_64 | 7.9 | — | 2400-40648 | +| 5.14.0-687.41.1.el9\_8.x86\_64 | 7.9 | — | 2410-40905 | +| 5.14.0-687.42.1.el9\_8.x86\_64 | 7.9 | — | 2410-40905 |
-
▸ ▾ Amazon Linux 2023 2023 [aarch64] modified +20 −0
linux-kernels/amazon-linux-2023Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -137,8 +137,28 @@ Cortex XDR agent supports the following kernel module versions for Amazon Linux6.12.92-122.168.amzn2023.aarch64│7.9│—│2330-383856.12.92-122.168.amzn2023.aarch64│7.9│—│2330-383856.12.94-123.174.amzn2023.aarch64│7.9│—│2340-387886.12.94-123.174.amzn2023.aarch64│7.9│—│2340-387886.12.94-123.176.amzn2023.aarch64│7.9│—│2340-387886.12.94-123.176.amzn2023.aarch64│7.9│—│2340-387886.12.94-123.180.amzn2023.aarch64│7.9│—│2340-387886.12.94-123.180.amzn2023.aarch64│7.9│—│2340-387886.12.94-123.190.amzn2023.aarch64│7.9│—│2390-397156.12.94-123.190.amzn2023.aarch64│7.9│—│2390-397156.12.94-123.192.amzn2023.aarch64│7.9│—│2390-397156.12.94-123.192.amzn2023.aarch64│7.9│—│2390-397156.12.95-124.187.amzn2023.aarch64│7.9│—│2380-400686.12.95-124.187.amzn2023.aarch64│7.9│—│2380-400686.12.100-125.179.amzn2023.aarch64│7.9│—│2400-406486.12.100-125.179.amzn2023.aarch64│7.9│—│2400-406486.18.8-9.213.amzn2023.aarch64│7.9│—│2410-409056.18.15-14.217.amzn2023.aarch64│7.9│—│2410-409056.18.16-18.222.amzn2023.aarch64│7.9│—│2410-409056.18.20-20.229.amzn2023.aarch64│7.9│—│2410-409056.18.20-41.237.amzn2023.aarch64│7.9│—│2410-409056.18.25-52.107.amzn2023.aarch64│7.9│—│2410-409056.18.25-55.108.amzn2023.aarch64│7.9│—│2410-409056.18.25-57.109.amzn2023.aarch64│7.9│—│2410-409056.18.30-61.116.amzn2023.aarch64│7.9│—│2410-409056.18.30-61.119.amzn2023.aarch64│7.9│—│2410-409056.18.33-63.124.amzn2023.aarch64│7.9│—│2410-409056.18.35-68.127.amzn2023.aarch64│7.9│—│2410-409056.18.35-68.129.amzn2023.aarch64│7.9│—│2410-409056.18.36-69.134.amzn2023.aarch64│7.9│—│2410-409056.18.36-69.136.amzn2023.aarch64│7.9│—│2410-409056.18.36-69.138.amzn2023.aarch64│7.9│—│2410-409056.18.38-73.137.amzn2023.aarch64│7.9│—│2410-409056.18.38-76.139.amzn2023.aarch64│7.9│—│2410-409056.18.39-79.141.amzn2023.aarch64│7.9│—│2410-409056.18.41-94.142.amzn2023.aarch64│7.9│—│2410-40905Show markdown source
@@ -137,8 +137,28 @@ Cortex XDR agent supports the following kernel module versions for Amazon Linux | 6.12.92-122.168.amzn2023.aarch64 | 7.9 | — | 2330-38385 | | 6.12.94-123.174.amzn2023.aarch64 | 7.9 | — | 2340-38788 | | 6.12.94-123.176.amzn2023.aarch64 | 7.9 | — | 2340-38788 | | 6.12.94-123.180.amzn2023.aarch64 | 7.9 | — | 2340-38788 | | 6.12.94-123.190.amzn2023.aarch64 | 7.9 | — | 2390-39715 | | 6.12.94-123.192.amzn2023.aarch64 | 7.9 | — | 2390-39715 | | 6.12.95-124.187.amzn2023.aarch64 | 7.9 | — | 2380-40068 | | 6.12.100-125.179.amzn2023.aarch64 | 7.9 | — | 2400-40648 | +| 6.18.8-9.213.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.15-14.217.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.16-18.222.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.20-20.229.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.20-41.237.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.25-52.107.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.25-55.108.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.25-57.109.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.30-61.116.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.30-61.119.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.33-63.124.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.35-68.127.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.35-68.129.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.36-69.134.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.36-69.136.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.36-69.138.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.38-73.137.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.38-76.139.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.39-79.141.amzn2023.aarch64 | 7.9 | — | 2410-40905 | +| 6.18.41-94.142.amzn2023.aarch64 | 7.9 | — | 2410-40905 |
-
▸ ▾ Amazon Linux 2023 2023 [x86_64] modified +20 −0
linux-kernels/amazon-linux-2023Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -137,8 +137,28 @@ Cortex XDR agent supports the following kernel module versions for Amazon Linux6.12.92-122.168.amzn2023.x86_64│7.9│—│2330-383856.12.92-122.168.amzn2023.x86_64│7.9│—│2330-383856.12.94-123.174.amzn2023.x86_64│7.9│—│2340-387886.12.94-123.174.amzn2023.x86_64│7.9│—│2340-387886.12.94-123.176.amzn2023.x86_64│7.9│—│2340-387886.12.94-123.176.amzn2023.x86_64│7.9│—│2340-387886.12.94-123.180.amzn2023.x86_64│7.9│—│2340-387886.12.94-123.180.amzn2023.x86_64│7.9│—│2340-387886.12.94-123.190.amzn2023.x86_64│7.9│—│2390-397156.12.94-123.190.amzn2023.x86_64│7.9│—│2390-397156.12.94-123.192.amzn2023.x86_64│7.9│—│2390-397156.12.94-123.192.amzn2023.x86_64│7.9│—│2390-397156.12.95-124.187.amzn2023.x86_64│7.9│—│2380-400686.12.95-124.187.amzn2023.x86_64│7.9│—│2380-400686.12.100-125.179.amzn2023.x86_64│7.9│—│2400-406486.12.100-125.179.amzn2023.x86_64│7.9│—│2400-406486.18.8-9.213.amzn2023.x86_64│7.9│—│2410-409056.18.15-14.217.amzn2023.x86_64│7.9│—│2410-409056.18.16-18.222.amzn2023.x86_64│7.9│—│2410-409056.18.20-20.229.amzn2023.x86_64│7.9│—│2410-409056.18.20-41.237.amzn2023.x86_64│7.9│—│2410-409056.18.25-52.107.amzn2023.x86_64│7.9│—│2410-409056.18.25-55.108.amzn2023.x86_64│7.9│—│2410-409056.18.25-57.109.amzn2023.x86_64│7.9│—│2410-409056.18.30-61.116.amzn2023.x86_64│7.9│—│2410-409056.18.30-61.119.amzn2023.x86_64│7.9│—│2410-409056.18.33-63.124.amzn2023.x86_64│7.9│—│2410-409056.18.35-68.127.amzn2023.x86_64│7.9│—│2410-409056.18.35-68.129.amzn2023.x86_64│7.9│—│2410-409056.18.36-69.134.amzn2023.x86_64│7.9│—│2410-409056.18.36-69.136.amzn2023.x86_64│7.9│—│2410-409056.18.36-69.138.amzn2023.x86_64│7.9│—│2410-409056.18.38-73.137.amzn2023.x86_64│7.9│—│2410-409056.18.38-76.139.amzn2023.x86_64│7.9│—│2410-409056.18.39-79.141.amzn2023.x86_64│7.9│—│2410-409056.18.41-94.142.amzn2023.x86_64│7.9│—│2410-40905Show markdown source
@@ -137,8 +137,28 @@ Cortex XDR agent supports the following kernel module versions for Amazon Linux | 6.12.92-122.168.amzn2023.x86\_64 | 7.9 | — | 2330-38385 | | 6.12.94-123.174.amzn2023.x86\_64 | 7.9 | — | 2340-38788 | | 6.12.94-123.176.amzn2023.x86\_64 | 7.9 | — | 2340-38788 | | 6.12.94-123.180.amzn2023.x86\_64 | 7.9 | — | 2340-38788 | | 6.12.94-123.190.amzn2023.x86\_64 | 7.9 | — | 2390-39715 | | 6.12.94-123.192.amzn2023.x86\_64 | 7.9 | — | 2390-39715 | | 6.12.95-124.187.amzn2023.x86\_64 | 7.9 | — | 2380-40068 | | 6.12.100-125.179.amzn2023.x86\_64 | 7.9 | — | 2400-40648 | +| 6.18.8-9.213.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.15-14.217.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.16-18.222.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.20-20.229.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.20-41.237.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.25-52.107.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.25-55.108.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.25-57.109.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.30-61.116.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.30-61.119.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.33-63.124.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.35-68.127.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.35-68.129.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.36-69.134.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.36-69.136.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.36-69.138.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.38-73.137.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.38-76.139.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.39-79.141.amzn2023.x86\_64 | 7.9 | — | 2410-40905 | +| 6.18.41-94.142.amzn2023.x86\_64 | 7.9 | — | 2410-40905 |
-
▸ ▾ CentOS Stream 9 [x86_64] modified +1 −0
linux-kernels/centos-streamRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -156,8 +156,9 @@ Cortex XDR agent supports the following kernel module versions for CentOS Stream5.14.0-719.el9.x86_64│8.1│—│2330-383855.14.0-719.el9.x86_64│8.1│—│2330-383855.14.0-721.el9.x86_64│8.1│—│2340-387885.14.0-721.el9.x86_64│8.1│—│2340-387885.14.0-722.el9.x86_64│8.1│—│2390-397155.14.0-722.el9.x86_64│8.1│—│2390-397155.14.0-725.el9.x86_64│8.1│—│2390-397155.14.0-725.el9.x86_64│8.1│—│2390-397155.14.0-729.el9.x86_64│8.1│—│2390-397155.14.0-729.el9.x86_64│8.1│—│2390-397155.14.0-731.el9.x86_64│8.1│—│2380-400685.14.0-731.el9.x86_64│8.1│—│2380-400685.14.0-734.el9.x86_64│8.1│—│2390-403335.14.0-734.el9.x86_64│8.1│—│2390-403335.14.0-737.el9.x86_64│8.1│—│2400-406485.14.0-737.el9.x86_64│8.1│—│2400-406485.14.0-741.el9.x86_64│8.1│—│2410-40905Show markdown source
@@ -156,8 +156,9 @@ Cortex XDR agent supports the following kernel module versions for CentOS Stream | 5.14.0-719.el9.x86\_64 | 8.1 | — | 2330-38385 | | 5.14.0-721.el9.x86\_64 | 8.1 | — | 2340-38788 | | 5.14.0-722.el9.x86\_64 | 8.1 | — | 2390-39715 | | 5.14.0-725.el9.x86\_64 | 8.1 | — | 2390-39715 | | 5.14.0-729.el9.x86\_64 | 8.1 | — | 2390-39715 | | 5.14.0-731.el9.x86\_64 | 8.1 | — | 2380-40068 | | 5.14.0-734.el9.x86\_64 | 8.1 | — | 2390-40333 | | 5.14.0-737.el9.x86\_64 | 8.1 | — | 2400-40648 | +| 5.14.0-741.el9.x86\_64 | 8.1 | — | 2410-40905 |
-
▸ ▾ Debian 13 [x86_64] modified +4 −0
linux-kernels/debianRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -39,8 +39,12 @@ Cortex XDR agent supports the following kernel module versions for Debian 13 \[x6.12.95+deb13-amd64│8.3.100│—│2340-387886.12.95+deb13-amd64│8.3.100│—│2340-387886.12.95+deb13-cloud-amd64│8.3.100│—│2340-387886.12.95+deb13-cloud-amd64│8.3.100│—│2340-387886.12.96+deb13-amd64│8.3.100│—│2390-397156.12.96+deb13-amd64│8.3.100│—│2390-397156.12.96+deb13-cloud-amd64│8.3.100│—│2390-397156.12.96+deb13-cloud-amd64│8.3.100│—│2390-397156.12.100+deb13-amd64│8.3.100│—│2390-397156.12.100+deb13-amd64│8.3.100│—│2390-397156.12.100+deb13-cloud-amd64│8.3.100│—│2390-397156.12.100+deb13-cloud-amd64│8.3.100│—│2390-397156.12.101+deb13-amd64│8.3.100│—│2380-400686.12.101+deb13-amd64│8.3.100│—│2380-400686.12.101+deb13-cloud-amd64│8.3.100│—│2380-400686.12.101+deb13-cloud-amd64│8.3.100│—│2380-400686.12.105+deb13-amd64│8.3.100│—│2410-409056.12.105+deb13-cloud-amd64│8.3.100│—│2410-409056.12.107+deb13-amd64│8.3.100│—│2410-409056.12.107+deb13-cloud-amd64│8.3.100│—│2410-40905Show markdown source
@@ -39,8 +39,12 @@ Cortex XDR agent supports the following kernel module versions for Debian 13 \[x | 6.12.95+deb13-amd64 | 8.3.100 | — | 2340-38788 | | 6.12.95+deb13-cloud-amd64 | 8.3.100 | — | 2340-38788 | | 6.12.96+deb13-amd64 | 8.3.100 | — | 2390-39715 | | 6.12.96+deb13-cloud-amd64 | 8.3.100 | — | 2390-39715 | | 6.12.100+deb13-amd64 | 8.3.100 | — | 2390-39715 | | 6.12.100+deb13-cloud-amd64 | 8.3.100 | — | 2390-39715 | | 6.12.101+deb13-amd64 | 8.3.100 | — | 2380-40068 | | 6.12.101+deb13-cloud-amd64 | 8.3.100 | — | 2380-40068 | +| 6.12.105+deb13-amd64 | 8.3.100 | — | 2410-40905 | +| 6.12.105+deb13-cloud-amd64 | 8.3.100 | — | 2410-40905 | +| 6.12.107+deb13-amd64 | 8.3.100 | — | 2410-40905 | +| 6.12.107+deb13-cloud-amd64 | 8.3.100 | — | 2410-40905 |
-
▸ ▾ Oracle Linux 8 [aarch64] modified +2 −0
linux-kernels/oracle-linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -227,16 +227,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.15.0-307.178.5.el8uek.aarch64│7.9│—│1740-150565.15.0-307.178.5.el8uek.aarch64│7.9│—│1740-150565.15.0-308.179.6.2.el8uek.aarch64│7.9│—│1780-163705.15.0-308.179.6.2.el8uek.aarch64│7.9│—│1780-163705.15.0-308.179.6.3.el8uek.aarch64│7.9│—│1790-166585.15.0-308.179.6.3.el8uek.aarch64│7.9│—│1790-166585.15.0-308.179.6.7.el8uek.aarch64│7.9│—│1900-208205.15.0-308.179.6.7.el8uek.aarch64│7.9│—│1900-208205.15.0-308.179.6.11.el8uek.aarch64│7.9│—│1900-208205.15.0-308.179.6.11.el8uek.aarch64│7.9│—│1900-208205.15.0-308.179.6.14.el8uek.aarch64│7.9│—│1910-211995.15.0-308.179.6.14.el8uek.aarch64│7.9│—│1910-211995.15.0-308.179.6.16.el8uek.aarch64│7.9│—│1970-241345.15.0-308.179.6.16.el8uek.aarch64│7.9│—│1970-241345.15.0-308.179.6.18.el8uek.aarch64│7.9│—│2390-397155.15.0-308.179.6.18.el8uek.aarch64│7.9│—│2390-397155.15.0-308.179.6.19.el8uek.aarch64│7.9│—│2410-409055.15.0-308.179.6.el8uek.aarch64│7.9│—│1780-163705.15.0-308.179.6.el8uek.aarch64│7.9│—│1780-163705.15.0-309.180.4.2.el8uek.aarch64│7.9│—│1900-208205.15.0-309.180.4.2.el8uek.aarch64│7.9│—│1900-208205.15.0-309.180.4.el8uek.aarch64│7.9│—│1830-182495.15.0-309.180.4.el8uek.aarch64│7.9│—│1830-182495.15.0-310.184.5.2.el8uek.aarch64│7.9│—│1900-208205.15.0-310.184.5.2.el8uek.aarch64│7.9│—│1900-208205.15.0-310.184.5.3.el8uek.aarch64│7.9│—│1910-211995.15.0-310.184.5.3.el8uek.aarch64│7.9│—│1910-211995.15.0-311.185.9.el8uek.aarch64│7.9│—│1930-221855.15.0-311.185.9.el8uek.aarch64│7.9│—│1930-221855.15.0-312.187.5.1.el8uek.aarch64│7.9│—│1960-233965.15.0-312.187.5.1.el8uek.aarch64│7.9│—│1960-233965.15.0-312.187.5.2.el8uek.aarch64│7.9│—│1970-239385.15.0-312.187.5.2.el8uek.aarch64│7.9│—│1970-23938@@ -273,8 +274,9 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.15.0-322.203.3.2.el8uek.aarch64│7.9│—│2340-387885.15.0-322.203.3.2.el8uek.aarch64│7.9│—│2340-387885.15.0-322.203.3.3.el8uek.aarch64│7.9│—│2340-387885.15.0-322.203.3.3.el8uek.aarch64│7.9│—│2340-387885.15.0-322.203.3.4.1.el8uek.aarch64│7.9│—│2390-403335.15.0-322.203.3.4.1.el8uek.aarch64│7.9│—│2390-403335.15.0-322.203.3.4.5.el8uek.aarch64│7.9│—│2380-400685.15.0-322.203.3.4.5.el8uek.aarch64│7.9│—│2380-400685.15.0-322.203.3.4.el8uek.aarch64│7.9│—│2390-397155.15.0-322.203.3.4.el8uek.aarch64│7.9│—│2390-397155.15.0-322.203.3.5.el8uek.aarch64│7.9│—│2390-403335.15.0-322.203.3.5.el8uek.aarch64│7.9│—│2390-403335.15.0-323.211.3.3.el8uek.aarch64│7.9│—│2390-403335.15.0-323.211.3.3.el8uek.aarch64│7.9│—│2390-403335.15.0-323.211.3.4.el8uek.aarch64│7.9│—│2400-406485.15.0-323.211.3.4.el8uek.aarch64│7.9│—│2400-406485.15.0-323.211.3.5.el8uek.aarch64│7.9│—│2410-40905Show markdown source
@@ -227,16 +227,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.15.0-307.178.5.el8uek.aarch64 | 7.9 | — | 1740-15056 | | 5.15.0-308.179.6.2.el8uek.aarch64 | 7.9 | — | 1780-16370 | | 5.15.0-308.179.6.3.el8uek.aarch64 | 7.9 | — | 1790-16658 | | 5.15.0-308.179.6.7.el8uek.aarch64 | 7.9 | — | 1900-20820 | | 5.15.0-308.179.6.11.el8uek.aarch64 | 7.9 | — | 1900-20820 | | 5.15.0-308.179.6.14.el8uek.aarch64 | 7.9 | — | 1910-21199 | | 5.15.0-308.179.6.16.el8uek.aarch64 | 7.9 | — | 1970-24134 | | 5.15.0-308.179.6.18.el8uek.aarch64 | 7.9 | — | 2390-39715 | +| 5.15.0-308.179.6.19.el8uek.aarch64 | 7.9 | — | 2410-40905 | | 5.15.0-308.179.6.el8uek.aarch64 | 7.9 | — | 1780-16370 | | 5.15.0-309.180.4.2.el8uek.aarch64 | 7.9 | — | 1900-20820 | | 5.15.0-309.180.4.el8uek.aarch64 | 7.9 | — | 1830-18249 | | 5.15.0-310.184.5.2.el8uek.aarch64 | 7.9 | — | 1900-20820 | | 5.15.0-310.184.5.3.el8uek.aarch64 | 7.9 | — | 1910-21199 | | 5.15.0-311.185.9.el8uek.aarch64 | 7.9 | — | 1930-22185 | | 5.15.0-312.187.5.1.el8uek.aarch64 | 7.9 | — | 1960-23396 | | 5.15.0-312.187.5.2.el8uek.aarch64 | 7.9 | — | 1970-23938 | @@ -273,8 +274,9 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.15.0-322.203.3.2.el8uek.aarch64 | 7.9 | — | 2340-38788 | | 5.15.0-322.203.3.3.el8uek.aarch64 | 7.9 | — | 2340-38788 | | 5.15.0-322.203.3.4.1.el8uek.aarch64 | 7.9 | — | 2390-40333 | | 5.15.0-322.203.3.4.5.el8uek.aarch64 | 7.9 | — | 2380-40068 | | 5.15.0-322.203.3.4.el8uek.aarch64 | 7.9 | — | 2390-39715 | | 5.15.0-322.203.3.5.el8uek.aarch64 | 7.9 | — | 2390-40333 | | 5.15.0-323.211.3.3.el8uek.aarch64 | 7.9 | — | 2390-40333 | | 5.15.0-323.211.3.4.el8uek.aarch64 | 7.9 | — | 2400-40648 | +| 5.15.0-323.211.3.5.el8uek.aarch64 | 7.9 | — | 2410-40905 |
-
▸ ▾ Oracle Linux 9 [aarch64] modified +2 −0
linux-kernels/oracle-linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -63,16 +63,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.15.0-307.178.5.el9uek.aarch64│8.2│—│1740-150565.15.0-307.178.5.el9uek.aarch64│8.2│—│1740-150565.15.0-308.179.6.2.el9uek.aarch64│8.2│—│1780-163705.15.0-308.179.6.2.el9uek.aarch64│8.2│—│1780-163705.15.0-308.179.6.3.el9uek.aarch64│8.2│—│1790-166585.15.0-308.179.6.3.el9uek.aarch64│8.2│—│1790-166585.15.0-308.179.6.7.el9uek.aarch64│8.2│—│1900-208205.15.0-308.179.6.7.el9uek.aarch64│8.2│—│1900-208205.15.0-308.179.6.11.el9uek.aarch64│8.2│—│1900-208205.15.0-308.179.6.11.el9uek.aarch64│8.2│—│1900-208205.15.0-308.179.6.14.el9uek.aarch64│8.2│—│1910-211995.15.0-308.179.6.14.el9uek.aarch64│8.2│—│1910-211995.15.0-308.179.6.16.el9uek.aarch64│8.2│—│1970-241345.15.0-308.179.6.16.el9uek.aarch64│8.2│—│1970-241345.15.0-308.179.6.18.el9uek.aarch64│8.2│—│2390-397155.15.0-308.179.6.18.el9uek.aarch64│8.2│—│2390-397155.15.0-308.179.6.19.el9uek.aarch64│8.2│—│2410-409055.15.0-308.179.6.el9uek.aarch64│8.2│—│1780-163705.15.0-308.179.6.el9uek.aarch64│8.2│—│1780-163705.15.0-309.180.4.2.el9uek.aarch64│8.2│—│1900-208205.15.0-309.180.4.2.el9uek.aarch64│8.2│—│1900-208205.15.0-309.180.4.el9uek.aarch64│8.2│—│1830-182495.15.0-309.180.4.el9uek.aarch64│8.2│—│1830-182495.15.0-310.184.5.2.el9uek.aarch64│8.2│—│1900-208205.15.0-310.184.5.2.el9uek.aarch64│8.2│—│1900-208205.15.0-310.184.5.3.el9uek.aarch64│8.2│—│1910-211995.15.0-310.184.5.3.el9uek.aarch64│8.2│—│1910-211995.15.0-311.185.9.el9uek.aarch64│8.2│—│1930-221855.15.0-311.185.9.el9uek.aarch64│8.2│—│1930-221855.15.0-312.187.5.1.el9uek.aarch64│8.2│—│1960-233965.15.0-312.187.5.1.el9uek.aarch64│8.2│—│1960-233965.15.0-312.187.5.2.el9uek.aarch64│8.2│—│1970-239385.15.0-312.187.5.2.el9uek.aarch64│8.2│—│1970-23938@@ -109,16 +110,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.15.0-322.203.3.2.el9uek.aarch64│8.2│—│2340-387885.15.0-322.203.3.2.el9uek.aarch64│8.2│—│2340-387885.15.0-322.203.3.3.el9uek.aarch64│8.2│—│2390-397155.15.0-322.203.3.3.el9uek.aarch64│8.2│—│2390-397155.15.0-322.203.3.4.1.el9uek.aarch64│8.2│—│2390-403335.15.0-322.203.3.4.1.el9uek.aarch64│8.2│—│2390-403335.15.0-322.203.3.4.5.el9uek.aarch64│8.2│—│2380-400685.15.0-322.203.3.4.5.el9uek.aarch64│8.2│—│2380-400685.15.0-322.203.3.4.el9uek.aarch64│8.2│—│2390-397155.15.0-322.203.3.4.el9uek.aarch64│8.2│—│2390-397155.15.0-322.203.3.5.el9uek.aarch64│8.2│—│2390-403335.15.0-322.203.3.5.el9uek.aarch64│8.2│—│2390-403335.15.0-323.211.3.3.el9uek.aarch64│8.2│—│2390-403335.15.0-323.211.3.3.el9uek.aarch64│8.2│—│2390-403335.15.0-323.211.3.4.el9uek.aarch64│8.2│—│2400-406485.15.0-323.211.3.4.el9uek.aarch64│8.2│—│2400-406485.15.0-323.211.3.5.el9uek.aarch64│8.2│—│2410-409056.12.0-0.20.20.el9uek.aarch64│8.3.100│—│1930-221856.12.0-0.20.20.el9uek.aarch64│8.3.100│—│1930-221856.12.0-1.23.3.1.el9uek.aarch64│8.3.100│—│1930-221856.12.0-1.23.3.1.el9uek.aarch64│8.3.100│—│1930-221856.12.0-1.23.3.2.el9uek.aarch64│8.3.100│—│1930-221856.12.0-1.23.3.2.el9uek.aarch64│8.3.100│—│1930-221856.12.0-1.23.3.el9uek.aarch64│8.3.100│—│1930-221856.12.0-1.23.3.el9uek.aarch64│8.3.100│—│1930-221856.12.0-100.28.2.2.el9uek.aarch64│8.3.100│—│1930-221856.12.0-100.28.2.2.el9uek.aarch64│8.3.100│—│1930-221856.12.0-100.28.2.el9uek.aarch64│8.3.100│—│1930-221856.12.0-100.28.2.el9uek.aarch64│8.3.100│—│1930-221856.12.0-101.33.4.3.el9uek.aarch64│8.3.100│—│1930-221856.12.0-101.33.4.3.el9uek.aarch64│8.3.100│—│1930-221856.12.0-102.36.5.2.el9uek.aarch64│8.3.100│—│1940-225266.12.0-102.36.5.2.el9uek.aarch64│8.3.100│—│1940-22526Show markdown source
@@ -63,16 +63,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.15.0-307.178.5.el9uek.aarch64 | 8.2 | — | 1740-15056 | | 5.15.0-308.179.6.2.el9uek.aarch64 | 8.2 | — | 1780-16370 | | 5.15.0-308.179.6.3.el9uek.aarch64 | 8.2 | — | 1790-16658 | | 5.15.0-308.179.6.7.el9uek.aarch64 | 8.2 | — | 1900-20820 | | 5.15.0-308.179.6.11.el9uek.aarch64 | 8.2 | — | 1900-20820 | | 5.15.0-308.179.6.14.el9uek.aarch64 | 8.2 | — | 1910-21199 | | 5.15.0-308.179.6.16.el9uek.aarch64 | 8.2 | — | 1970-24134 | | 5.15.0-308.179.6.18.el9uek.aarch64 | 8.2 | — | 2390-39715 | +| 5.15.0-308.179.6.19.el9uek.aarch64 | 8.2 | — | 2410-40905 | | 5.15.0-308.179.6.el9uek.aarch64 | 8.2 | — | 1780-16370 | | 5.15.0-309.180.4.2.el9uek.aarch64 | 8.2 | — | 1900-20820 | | 5.15.0-309.180.4.el9uek.aarch64 | 8.2 | — | 1830-18249 | | 5.15.0-310.184.5.2.el9uek.aarch64 | 8.2 | — | 1900-20820 | | 5.15.0-310.184.5.3.el9uek.aarch64 | 8.2 | — | 1910-21199 | | 5.15.0-311.185.9.el9uek.aarch64 | 8.2 | — | 1930-22185 | | 5.15.0-312.187.5.1.el9uek.aarch64 | 8.2 | — | 1960-23396 | | 5.15.0-312.187.5.2.el9uek.aarch64 | 8.2 | — | 1970-23938 | @@ -109,16 +110,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.15.0-322.203.3.2.el9uek.aarch64 | 8.2 | — | 2340-38788 | | 5.15.0-322.203.3.3.el9uek.aarch64 | 8.2 | — | 2390-39715 | | 5.15.0-322.203.3.4.1.el9uek.aarch64 | 8.2 | — | 2390-40333 | | 5.15.0-322.203.3.4.5.el9uek.aarch64 | 8.2 | — | 2380-40068 | | 5.15.0-322.203.3.4.el9uek.aarch64 | 8.2 | — | 2390-39715 | | 5.15.0-322.203.3.5.el9uek.aarch64 | 8.2 | — | 2390-40333 | | 5.15.0-323.211.3.3.el9uek.aarch64 | 8.2 | — | 2390-40333 | | 5.15.0-323.211.3.4.el9uek.aarch64 | 8.2 | — | 2400-40648 | +| 5.15.0-323.211.3.5.el9uek.aarch64 | 8.2 | — | 2410-40905 | | 6.12.0-0.20.20.el9uek.aarch64 | 8.3.100 | — | 1930-22185 | | 6.12.0-1.23.3.1.el9uek.aarch64 | 8.3.100 | — | 1930-22185 | | 6.12.0-1.23.3.2.el9uek.aarch64 | 8.3.100 | — | 1930-22185 | | 6.12.0-1.23.3.el9uek.aarch64 | 8.3.100 | — | 1930-22185 | | 6.12.0-100.28.2.2.el9uek.aarch64 | 8.3.100 | — | 1930-22185 | | 6.12.0-100.28.2.el9uek.aarch64 | 8.3.100 | — | 1930-22185 | | 6.12.0-101.33.4.3.el9uek.aarch64 | 8.3.100 | — | 1930-22185 | | 6.12.0-102.36.5.2.el9uek.aarch64 | 8.3.100 | — | 1940-22526 |
-
▸ ▾ Oracle Linux 8 [x86_64] modified +5 −0
linux-kernels/oracle-linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -455,18 +455,21 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux4.18.0-553.151.1.0.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.151.1.0.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.151.1.el8_10.x86_64│7.1│—│2380-400684.18.0-553.151.1.el8_10.x86_64│7.1│—│2380-400684.18.0-553.153.1.0.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.153.1.0.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.153.1.el8_10.x86_64│7.1│—│2380-400684.18.0-553.153.1.el8_10.x86_64│7.1│—│2380-400684.18.0-553.154.1.0.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.154.1.0.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.154.1.el8_10.x86_64│7.1│—│2390-403334.18.0-553.154.1.el8_10.x86_64│7.1│—│2390-403334.18.0-553.155.1.0.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.155.1.0.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.155.1.el8_10.x86_64│7.1│—│2390-403334.18.0-553.155.1.el8_10.x86_64│7.1│—│2390-403334.18.0-553.156.1.0.1.el8_10.x86_64│7.1│—│2410-409054.18.0-553.156.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.156.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.157.1.0.1.el8_10.x86_64│7.1│—│2410-409054.18.0-553.157.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.157.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.158.1.el8_10.x86_64│7.1│—│2410-409054.18.0-553.el8_10.x86_64│7.1│—│1460-876304.18.0-553.el8_10.x86_64│7.1│—│1460-876305.4.17-2011.0.7.el8uek.x86_64│7.1│—│450-875565.4.17-2011.0.7.el8uek.x86_64│7.1│—│450-875565.4.17-2011.1.2.el8uek.x86_64│7.1│—│450-875565.4.17-2011.1.2.el8uek.x86_64│7.1│—│450-875565.4.17-2011.2.2.el8uek.x86_64│7.1│—│450-875565.4.17-2011.2.2.el8uek.x86_64│7.1│—│450-875565.4.17-2011.3.2.1.el8uek.x86_64│7.1│—│450-875565.4.17-2011.3.2.1.el8uek.x86_64│7.1│—│450-875565.4.17-2011.4.4.el8uek.x86_64│7.1│—│450-875565.4.17-2011.4.4.el8uek.x86_64│7.1│—│450-875565.4.17-2011.4.6.el8uek.x86_64│7.1│—│450-875565.4.17-2011.4.6.el8uek.x86_64│7.1│—│450-875565.4.17-2011.5.3.el8uek.x86_64│7.1│—│450-875565.4.17-2011.5.3.el8uek.x86_64│7.1│—│450-87556@@ -757,16 +760,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.15.0-307.178.5.el8uek.x86_64│7.1│—│1740-150565.15.0-307.178.5.el8uek.x86_64│7.1│—│1740-150565.15.0-308.179.6.2.el8uek.x86_64│7.1│—│1780-163705.15.0-308.179.6.2.el8uek.x86_64│7.1│—│1780-163705.15.0-308.179.6.3.el8uek.x86_64│7.1│—│1790-166585.15.0-308.179.6.3.el8uek.x86_64│7.1│—│1790-166585.15.0-308.179.6.7.el8uek.x86_64│7.1│—│1900-208205.15.0-308.179.6.7.el8uek.x86_64│7.1│—│1900-208205.15.0-308.179.6.11.el8uek.x86_64│7.1│—│1900-208205.15.0-308.179.6.11.el8uek.x86_64│7.1│—│1900-208205.15.0-308.179.6.14.el8uek.x86_64│7.1│—│1930-221855.15.0-308.179.6.14.el8uek.x86_64│7.1│—│1930-221855.15.0-308.179.6.16.el8uek.x86_64│7.1│—│1970-241345.15.0-308.179.6.16.el8uek.x86_64│7.1│—│1970-241345.15.0-308.179.6.18.el8uek.x86_64│7.1│—│2390-397155.15.0-308.179.6.18.el8uek.x86_64│7.1│—│2390-397155.15.0-308.179.6.19.el8uek.x86_64│7.1│—│2410-409055.15.0-308.179.6.el8uek.x86_64│7.1│—│1780-163705.15.0-308.179.6.el8uek.x86_64│7.1│—│1780-163705.15.0-309.180.4.2.el8uek.x86_64│7.1│—│1900-208205.15.0-309.180.4.2.el8uek.x86_64│7.1│—│1900-208205.15.0-309.180.4.el8uek.x86_64│7.1│—│1830-182495.15.0-309.180.4.el8uek.x86_64│7.1│—│1830-182495.15.0-310.184.5.2.el8uek.x86_64│7.1│—│1900-208205.15.0-310.184.5.2.el8uek.x86_64│7.1│—│1900-208205.15.0-310.184.5.3.el8uek.x86_64│7.1│—│1910-211995.15.0-310.184.5.3.el8uek.x86_64│7.1│—│1910-211995.15.0-311.185.9.el8uek.x86_64│7.1│—│1930-221855.15.0-311.185.9.el8uek.x86_64│7.1│—│1930-221855.15.0-312.187.5.1.el8uek.x86_64│7.1│—│1960-233965.15.0-312.187.5.1.el8uek.x86_64│7.1│—│1960-233965.15.0-312.187.5.2.el8uek.x86_64│7.1│—│1970-239385.15.0-312.187.5.2.el8uek.x86_64│7.1│—│1970-23938@@ -803,8 +807,9 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.15.0-322.203.3.2.el8uek.x86_64│7.1│—│2340-387885.15.0-322.203.3.2.el8uek.x86_64│7.1│—│2340-387885.15.0-322.203.3.3.el8uek.x86_64│7.1│—│2340-387885.15.0-322.203.3.3.el8uek.x86_64│7.1│—│2340-387885.15.0-322.203.3.4.1.el8uek.x86_64│7.1│—│2390-403335.15.0-322.203.3.4.1.el8uek.x86_64│7.1│—│2390-403335.15.0-322.203.3.4.5.el8uek.x86_64│7.1│—│2380-400685.15.0-322.203.3.4.5.el8uek.x86_64│7.1│—│2380-400685.15.0-322.203.3.4.el8uek.x86_64│7.1│—│2390-397155.15.0-322.203.3.4.el8uek.x86_64│7.1│—│2390-397155.15.0-322.203.3.5.el8uek.x86_64│7.1│—│2390-403335.15.0-322.203.3.5.el8uek.x86_64│7.1│—│2390-403335.15.0-323.211.3.3.el8uek.x86_64│7.1│—│2390-403335.15.0-323.211.3.3.el8uek.x86_64│7.1│—│2390-403335.15.0-323.211.3.4.el8uek.x86_64│7.1│—│2400-406485.15.0-323.211.3.4.el8uek.x86_64│7.1│—│2400-406485.15.0-323.211.3.5.el8uek.x86_64│7.1│—│2410-40905Show markdown source
@@ -455,18 +455,21 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 4.18.0-553.151.1.0.1.el8\_10.x86\_64 | 7.1 | — | 2400-40648 | | 4.18.0-553.151.1.el8\_10.x86\_64 | 7.1 | — | 2380-40068 | | 4.18.0-553.153.1.0.1.el8\_10.x86\_64 | 7.1 | — | 2400-40648 | | 4.18.0-553.153.1.el8\_10.x86\_64 | 7.1 | — | 2380-40068 | | 4.18.0-553.154.1.0.1.el8\_10.x86\_64 | 7.1 | — | 2400-40648 | | 4.18.0-553.154.1.el8\_10.x86\_64 | 7.1 | — | 2390-40333 | | 4.18.0-553.155.1.0.1.el8\_10.x86\_64 | 7.1 | — | 2400-40648 | | 4.18.0-553.155.1.el8\_10.x86\_64 | 7.1 | — | 2390-40333 | +| 4.18.0-553.156.1.0.1.el8\_10.x86\_64 | 7.1 | — | 2410-40905 | | 4.18.0-553.156.1.el8\_10.x86\_64 | 7.1 | — | 2400-40648 | +| 4.18.0-553.157.1.0.1.el8\_10.x86\_64 | 7.1 | — | 2410-40905 | | 4.18.0-553.157.1.el8\_10.x86\_64 | 7.1 | — | 2400-40648 | +| 4.18.0-553.158.1.el8\_10.x86\_64 | 7.1 | — | 2410-40905 | | 4.18.0-553.el8\_10.x86\_64 | 7.1 | — | 1460-87630 | | 5.4.17-2011.0.7.el8uek.x86\_64 | 7.1 | — | 450-87556 | | 5.4.17-2011.1.2.el8uek.x86\_64 | 7.1 | — | 450-87556 | | 5.4.17-2011.2.2.el8uek.x86\_64 | 7.1 | — | 450-87556 | | 5.4.17-2011.3.2.1.el8uek.x86\_64 | 7.1 | — | 450-87556 | | 5.4.17-2011.4.4.el8uek.x86\_64 | 7.1 | — | 450-87556 | | 5.4.17-2011.4.6.el8uek.x86\_64 | 7.1 | — | 450-87556 | | 5.4.17-2011.5.3.el8uek.x86\_64 | 7.1 | — | 450-87556 | @@ -757,16 +760,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.15.0-307.178.5.el8uek.x86\_64 | 7.1 | — | 1740-15056 | | 5.15.0-308.179.6.2.el8uek.x86\_64 | 7.1 | — | 1780-16370 | | 5.15.0-308.179.6.3.el8uek.x86\_64 | 7.1 | — | 1790-16658 | | 5.15.0-308.179.6.7.el8uek.x86\_64 | 7.1 | — | 1900-20820 | | 5.15.0-308.179.6.11.el8uek.x86\_64 | 7.1 | — | 1900-20820 | | 5.15.0-308.179.6.14.el8uek.x86\_64 | 7.1 | — | 1930-22185 | | 5.15.0-308.179.6.16.el8uek.x86\_64 | 7.1 | — | 1970-24134 | | 5.15.0-308.179.6.18.el8uek.x86\_64 | 7.1 | — | 2390-39715 | +| 5.15.0-308.179.6.19.el8uek.x86\_64 | 7.1 | — | 2410-40905 | | 5.15.0-308.179.6.el8uek.x86\_64 | 7.1 | — | 1780-16370 | | 5.15.0-309.180.4.2.el8uek.x86\_64 | 7.1 | — | 1900-20820 | | 5.15.0-309.180.4.el8uek.x86\_64 | 7.1 | — | 1830-18249 | | 5.15.0-310.184.5.2.el8uek.x86\_64 | 7.1 | — | 1900-20820 | | 5.15.0-310.184.5.3.el8uek.x86\_64 | 7.1 | — | 1910-21199 | | 5.15.0-311.185.9.el8uek.x86\_64 | 7.1 | — | 1930-22185 | | 5.15.0-312.187.5.1.el8uek.x86\_64 | 7.1 | — | 1960-23396 | | 5.15.0-312.187.5.2.el8uek.x86\_64 | 7.1 | — | 1970-23938 | @@ -803,8 +807,9 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.15.0-322.203.3.2.el8uek.x86\_64 | 7.1 | — | 2340-38788 | | 5.15.0-322.203.3.3.el8uek.x86\_64 | 7.1 | — | 2340-38788 | | 5.15.0-322.203.3.4.1.el8uek.x86\_64 | 7.1 | — | 2390-40333 | | 5.15.0-322.203.3.4.5.el8uek.x86\_64 | 7.1 | — | 2380-40068 | | 5.15.0-322.203.3.4.el8uek.x86\_64 | 7.1 | — | 2390-39715 | | 5.15.0-322.203.3.5.el8uek.x86\_64 | 7.1 | — | 2390-40333 | | 5.15.0-323.211.3.3.el8uek.x86\_64 | 7.1 | — | 2390-40333 | | 5.15.0-323.211.3.4.el8uek.x86\_64 | 7.1 | — | 2400-40648 | +| 5.15.0-323.211.3.5.el8uek.x86\_64 | 7.1 | — | 2410-40905 |
-
▸ ▾ Oracle Linux 9 [x86_64] modified +9 −0
linux-kernels/oracle-linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -158,16 +158,18 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.14.0-284.178.1.el9_2.x86_64│7.9│—│2330-383855.14.0-284.178.1.el9_2.x86_64│7.9│—│2330-383855.14.0-284.179.1.el9_2.x86_64│7.9│—│2340-387885.14.0-284.179.1.el9_2.x86_64│7.9│—│2340-387885.14.0-284.181.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.181.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.182.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.182.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.183.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.183.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.184.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.184.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.186.1.el9_2.x86_64│7.9│—│2380-400685.14.0-284.186.1.el9_2.x86_64│7.9│—│2380-400685.14.0-284.187.1.el9_2.x86_64│7.9│—│2390-403335.14.0-284.187.1.el9_2.x86_64│7.9│—│2390-403335.14.0-284.188.1.el9_2.x86_64│7.9│—│2410-409055.14.0-284.189.1.el9_2.x86_64│7.9│—│2410-409055.14.0-362.8.1.el9_3.x86_64│7.9│—│1190-746835.14.0-362.8.1.el9_3.x86_64│7.9│—│1190-746835.14.0-362.13.0.1.el9_3.x86_64│7.9│—│1200-760065.14.0-362.13.0.1.el9_3.x86_64│7.9│—│1200-760065.14.0-362.13.1.el9_3.x86_64│7.9│—│1200-760065.14.0-362.13.1.el9_3.x86_64│7.9│—│1200-760065.14.0-362.18.0.1.el9_3.x86_64│7.9│—│1250-777135.14.0-362.18.0.1.el9_3.x86_64│7.9│—│1250-777135.14.0-362.18.0.2.el9_3.x86_64│7.9│—│1260-782505.14.0-362.18.0.2.el9_3.x86_64│7.9│—│1260-782505.14.0-362.18.1.el9_3.x86_64│7.9│—│1250-777135.14.0-362.18.1.el9_3.x86_64│7.9│—│1250-777135.14.0-362.24.1.0.1.el9_3.x86_64│7.9│—│1340-812935.14.0-362.24.1.0.1.el9_3.x86_64│7.9│—│1340-812935.14.0-362.24.1.0.2.el9_3.x86_64│7.9│—│1350-819915.14.0-362.24.1.0.2.el9_3.x86_64│7.9│—│1350-81991@@ -264,16 +266,18 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.14.0-427.136.1.el9_4.x86_64│7.9│—│2340-387885.14.0-427.136.1.el9_4.x86_64│7.9│—│2340-387885.14.0-427.137.1.el9_4.x86_64│7.9│—│2340-387885.14.0-427.137.1.el9_4.x86_64│7.9│—│2340-387885.14.0-427.138.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.138.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.139.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.139.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.141.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.141.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.143.1.el9_4.x86_64│7.9│—│2380-400685.14.0-427.143.1.el9_4.x86_64│7.9│—│2380-400685.14.0-427.144.1.el9_4.x86_64│7.9│—│2390-403335.14.0-427.144.1.el9_4.x86_64│7.9│—│2390-403335.14.0-427.145.1.el9_4.x86_64│7.9│—│2400-406485.14.0-427.145.1.el9_4.x86_64│7.9│—│2400-406485.14.0-427.146.1.el9_4.x86_64│7.9│—│2410-409055.14.0-427.147.1.el9_4.x86_64│7.9│—│2410-409055.14.0-503.11.1.0.1.el9_5.x86_64│7.9│—│1900-208205.14.0-503.11.1.0.1.el9_5.x86_64│7.9│—│1900-208205.14.0-503.11.1.el9_5.x86_64│7.9│—│1610-937925.14.0-503.11.1.el9_5.x86_64│7.9│—│1610-937925.14.0-503.14.1.0.1.el9_5.x86_64│7.9│—│1900-208205.14.0-503.14.1.0.1.el9_5.x86_64│7.9│—│1900-208205.14.0-503.14.1.el9_5.x86_64│7.9│—│1610-937925.14.0-503.14.1.el9_5.x86_64│7.9│—│1610-937925.14.0-503.15.1.0.1.el9_5.x86_64│7.9│—│1900-208205.14.0-503.15.1.0.1.el9_5.x86_64│7.9│—│1900-208205.14.0-503.15.1.el9_5.x86_64│7.9│—│1610-937925.14.0-503.15.1.el9_5.x86_64│7.9│—│1610-937925.14.0-503.16.1.0.1.el9_5.x86_64│7.9│—│1900-208205.14.0-503.16.1.0.1.el9_5.x86_64│7.9│—│1900-208205.14.0-503.16.1.el9_5.x86_64│7.9│—│1620-941605.14.0-503.16.1.el9_5.x86_64│7.9│—│1620-94160@@ -420,16 +424,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.14.0-570.125.1.el9_6.x86_64│7.9│—│2330-383855.14.0-570.125.1.el9_6.x86_64│7.9│—│2330-383855.14.0-570.127.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.127.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.128.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.128.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.129.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.129.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.131.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.131.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.132.1.el9_6.x86_64│7.9│—│2390-403335.14.0-570.132.1.el9_6.x86_64│7.9│—│2390-403335.14.0-570.134.1.el9_6.x86_64│7.9│—│2390-403335.14.0-570.134.1.el9_6.x86_64│7.9│—│2390-403335.14.0-570.135.1.el9_6.x86_64│7.9│—│2400-406485.14.0-570.135.1.el9_6.x86_64│7.9│—│2400-406485.14.0-570.136.1.el9_6.x86_64│7.9│—│2410-409055.14.0-611.5.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.5.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.7.1.0.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.7.1.0.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.7.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.7.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.8.1.0.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.8.1.0.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.8.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.8.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.9.1.0.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.9.1.0.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.9.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.9.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.11.1.0.1.el9_7.x86_64│7.9│—│2170-322675.14.0-611.11.1.0.1.el9_7.x86_64│7.9│—│2170-32267@@ -501,17 +506,19 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.14.0-687.34.1.0.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.34.1.0.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.34.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.34.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.36.1.0.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.36.1.0.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.36.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.36.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.0.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.0.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.39.1.0.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.39.1.0.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.39.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.39.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.41.1.0.1.el9_8.x86_64│7.9│—│2410-409055.14.0-687.41.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.41.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.42.1.el9_8.x86_64│7.9│—│2410-409055.15.0-0.30.16.1.el9uek.x86_64│7.9│—│770-251475.15.0-0.30.16.1.el9uek.x86_64│7.9│—│770-251475.15.0-0.30.19.el9uek.x86_64│7.9│—│730-202715.15.0-0.30.19.el9uek.x86_64│7.9│—│730-202715.15.0-0.30.20.1.el9uek.x86_64│7.9│—│720-194645.15.0-0.30.20.1.el9uek.x86_64│7.9│—│720-194645.15.0-0.30.20.el9uek.x86_64│7.9│—│720-194645.15.0-0.30.20.el9uek.x86_64│7.9│—│720-194645.15.0-1.43.4.1.el9uek.x86_64│7.9│—│720-194645.15.0-1.43.4.1.el9uek.x86_64│7.9│—│720-194645.15.0-1.43.4.2.el9uek.x86_64│7.9│—│720-194645.15.0-1.43.4.2.el9uek.x86_64│7.9│—│720-194645.15.0-2.52.3.el9uek.x86_64│7.9│—│730-202715.15.0-2.52.3.el9uek.x86_64│7.9│—│730-202715.15.0-3.60.5.1.el9uek.x86_64│7.9│—│770-251475.15.0-3.60.5.1.el9uek.x86_64│7.9│—│770-25147@@ -576,16 +583,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.15.0-307.178.5.el9uek.x86_64│7.9│—│1740-150565.15.0-307.178.5.el9uek.x86_64│7.9│—│1740-150565.15.0-308.179.6.2.el9uek.x86_64│7.9│—│1780-163705.15.0-308.179.6.2.el9uek.x86_64│7.9│—│1780-163705.15.0-308.179.6.3.el9uek.x86_64│7.9│—│1790-166585.15.0-308.179.6.3.el9uek.x86_64│7.9│—│1790-166585.15.0-308.179.6.7.el9uek.x86_64│7.9│—│1900-208205.15.0-308.179.6.7.el9uek.x86_64│7.9│—│1900-208205.15.0-308.179.6.11.el9uek.x86_64│7.9│—│1900-208205.15.0-308.179.6.11.el9uek.x86_64│7.9│—│1900-208205.15.0-308.179.6.14.el9uek.x86_64│7.9│—│1910-211995.15.0-308.179.6.14.el9uek.x86_64│7.9│—│1910-211995.15.0-308.179.6.16.el9uek.x86_64│7.9│—│1970-241345.15.0-308.179.6.16.el9uek.x86_64│7.9│—│1970-241345.15.0-308.179.6.18.el9uek.x86_64│7.9│—│2390-397155.15.0-308.179.6.18.el9uek.x86_64│7.9│—│2390-397155.15.0-308.179.6.19.el9uek.x86_64│7.9│—│2410-409055.15.0-308.179.6.el9uek.x86_64│7.9│—│1780-163705.15.0-308.179.6.el9uek.x86_64│7.9│—│1780-163705.15.0-309.180.4.2.el9uek.x86_64│7.9│—│1900-208205.15.0-309.180.4.2.el9uek.x86_64│7.9│—│1900-208205.15.0-309.180.4.el9uek.x86_64│7.9│—│1830-182495.15.0-309.180.4.el9uek.x86_64│7.9│—│1830-182495.15.0-310.184.5.2.el9uek.x86_64│7.9│—│1900-208205.15.0-310.184.5.2.el9uek.x86_64│7.9│—│1900-208205.15.0-310.184.5.3.el9uek.x86_64│7.9│—│1910-211995.15.0-310.184.5.3.el9uek.x86_64│7.9│—│1910-211995.15.0-311.185.9.el9uek.x86_64│7.9│—│1930-221855.15.0-311.185.9.el9uek.x86_64│7.9│—│1930-221855.15.0-312.187.5.1.el9uek.x86_64│7.9│—│1960-233965.15.0-312.187.5.1.el9uek.x86_64│7.9│—│1960-233965.15.0-312.187.5.2.el9uek.x86_64│7.9│—│1970-239385.15.0-312.187.5.2.el9uek.x86_64│7.9│—│1970-23938@@ -622,16 +630,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux5.15.0-322.203.3.2.el9uek.x86_64│7.9│—│2340-387885.15.0-322.203.3.2.el9uek.x86_64│7.9│—│2340-387885.15.0-322.203.3.3.el9uek.x86_64│7.9│—│2340-387885.15.0-322.203.3.3.el9uek.x86_64│7.9│—│2340-387885.15.0-322.203.3.4.1.el9uek.x86_64│7.9│—│2390-403335.15.0-322.203.3.4.1.el9uek.x86_64│7.9│—│2390-403335.15.0-322.203.3.4.5.el9uek.x86_64│7.9│—│2380-400685.15.0-322.203.3.4.5.el9uek.x86_64│7.9│—│2380-400685.15.0-322.203.3.4.el9uek.x86_64│7.9│—│2390-397155.15.0-322.203.3.4.el9uek.x86_64│7.9│—│2390-397155.15.0-322.203.3.5.el9uek.x86_64│7.9│—│2390-403335.15.0-322.203.3.5.el9uek.x86_64│7.9│—│2390-403335.15.0-323.211.3.3.el9uek.x86_64│7.9│—│2390-403335.15.0-323.211.3.3.el9uek.x86_64│7.9│—│2390-403335.15.0-323.211.3.4.el9uek.x86_64│7.9│—│2400-406485.15.0-323.211.3.4.el9uek.x86_64│7.9│—│2400-406485.15.0-323.211.3.5.el9uek.x86_64│7.9│—│2410-409056.12.0-0.20.20.el9uek.x86_64│8.3.100│—│1930-221856.12.0-0.20.20.el9uek.x86_64│8.3.100│—│1930-221856.12.0-1.23.3.1.el9uek.x86_64│8.3.100│—│1930-221856.12.0-1.23.3.1.el9uek.x86_64│8.3.100│—│1930-221856.12.0-1.23.3.2.el9uek.x86_64│8.3.100│—│1930-221856.12.0-1.23.3.2.el9uek.x86_64│8.3.100│—│1930-221856.12.0-1.23.3.el9uek.x86_64│8.3.100│—│1930-221856.12.0-1.23.3.el9uek.x86_64│8.3.100│—│1930-221856.12.0-100.28.2.2.el9uek.x86_64│8.3.100│—│1930-221856.12.0-100.28.2.2.el9uek.x86_64│8.3.100│—│1930-221856.12.0-100.28.2.el9uek.x86_64│8.3.100│—│1930-221856.12.0-100.28.2.el9uek.x86_64│8.3.100│—│1930-221856.12.0-101.33.4.3.el9uek.x86_64│8.3.100│—│1930-221856.12.0-101.33.4.3.el9uek.x86_64│8.3.100│—│1930-221856.12.0-102.36.5.2.el9uek.x86_64│8.3.100│—│1940-225266.12.0-102.36.5.2.el9uek.x86_64│8.3.100│—│1940-22526Show markdown source
@@ -158,16 +158,18 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.14.0-284.178.1.el9\_2.x86\_64 | 7.9 | — | 2330-38385 | | 5.14.0-284.179.1.el9\_2.x86\_64 | 7.9 | — | 2340-38788 | | 5.14.0-284.181.1.el9\_2.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-284.182.1.el9\_2.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-284.183.1.el9\_2.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-284.184.1.el9\_2.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-284.186.1.el9\_2.x86\_64 | 7.9 | — | 2380-40068 | | 5.14.0-284.187.1.el9\_2.x86\_64 | 7.9 | — | 2390-40333 | +| 5.14.0-284.188.1.el9\_2.x86\_64 | 7.9 | — | 2410-40905 | +| 5.14.0-284.189.1.el9\_2.x86\_64 | 7.9 | — | 2410-40905 | | 5.14.0-362.8.1.el9\_3.x86\_64 | 7.9 | — | 1190-74683 | | 5.14.0-362.13.0.1.el9\_3.x86\_64 | 7.9 | — | 1200-76006 | | 5.14.0-362.13.1.el9\_3.x86\_64 | 7.9 | — | 1200-76006 | | 5.14.0-362.18.0.1.el9\_3.x86\_64 | 7.9 | — | 1250-77713 | | 5.14.0-362.18.0.2.el9\_3.x86\_64 | 7.9 | — | 1260-78250 | | 5.14.0-362.18.1.el9\_3.x86\_64 | 7.9 | — | 1250-77713 | | 5.14.0-362.24.1.0.1.el9\_3.x86\_64 | 7.9 | — | 1340-81293 | | 5.14.0-362.24.1.0.2.el9\_3.x86\_64 | 7.9 | — | 1350-81991 | @@ -264,16 +266,18 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.14.0-427.136.1.el9\_4.x86\_64 | 7.9 | — | 2340-38788 | | 5.14.0-427.137.1.el9\_4.x86\_64 | 7.9 | — | 2340-38788 | | 5.14.0-427.138.1.el9\_4.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-427.139.1.el9\_4.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-427.141.1.el9\_4.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-427.143.1.el9\_4.x86\_64 | 7.9 | — | 2380-40068 | | 5.14.0-427.144.1.el9\_4.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-427.145.1.el9\_4.x86\_64 | 7.9 | — | 2400-40648 | +| 5.14.0-427.146.1.el9\_4.x86\_64 | 7.9 | — | 2410-40905 | +| 5.14.0-427.147.1.el9\_4.x86\_64 | 7.9 | — | 2410-40905 | | 5.14.0-503.11.1.0.1.el9\_5.x86\_64 | 7.9 | — | 1900-20820 | | 5.14.0-503.11.1.el9\_5.x86\_64 | 7.9 | — | 1610-93792 | | 5.14.0-503.14.1.0.1.el9\_5.x86\_64 | 7.9 | — | 1900-20820 | | 5.14.0-503.14.1.el9\_5.x86\_64 | 7.9 | — | 1610-93792 | | 5.14.0-503.15.1.0.1.el9\_5.x86\_64 | 7.9 | — | 1900-20820 | | 5.14.0-503.15.1.el9\_5.x86\_64 | 7.9 | — | 1610-93792 | | 5.14.0-503.16.1.0.1.el9\_5.x86\_64 | 7.9 | — | 1900-20820 | | 5.14.0-503.16.1.el9\_5.x86\_64 | 7.9 | — | 1620-94160 | @@ -420,16 +424,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.14.0-570.125.1.el9\_6.x86\_64 | 7.9 | — | 2330-38385 | | 5.14.0-570.127.1.el9\_6.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-570.128.1.el9\_6.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-570.129.1.el9\_6.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-570.131.1.el9\_6.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-570.132.1.el9\_6.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-570.134.1.el9\_6.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-570.135.1.el9\_6.x86\_64 | 7.9 | — | 2400-40648 | +| 5.14.0-570.136.1.el9\_6.x86\_64 | 7.9 | — | 2410-40905 | | 5.14.0-611.5.1.el9\_7.x86\_64 | 7.9 | — | 2170-32267 | | 5.14.0-611.7.1.0.1.el9\_7.x86\_64 | 7.9 | — | 2170-32267 | | 5.14.0-611.7.1.el9\_7.x86\_64 | 7.9 | — | 2170-32267 | | 5.14.0-611.8.1.0.1.el9\_7.x86\_64 | 7.9 | — | 2170-32267 | | 5.14.0-611.8.1.el9\_7.x86\_64 | 7.9 | — | 2170-32267 | | 5.14.0-611.9.1.0.1.el9\_7.x86\_64 | 7.9 | — | 2170-32267 | | 5.14.0-611.9.1.el9\_7.x86\_64 | 7.9 | — | 2170-32267 | | 5.14.0-611.11.1.0.1.el9\_7.x86\_64 | 7.9 | — | 2170-32267 | @@ -501,17 +506,19 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.14.0-687.34.1.0.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.34.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.36.1.0.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.36.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.38.1.0.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.38.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.39.1.0.1.el9\_8.x86\_64 | 7.9 | — | 2400-40648 | | 5.14.0-687.39.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | +| 5.14.0-687.41.1.0.1.el9\_8.x86\_64 | 7.9 | — | 2410-40905 | | 5.14.0-687.41.1.el9\_8.x86\_64 | 7.9 | — | 2400-40648 | +| 5.14.0-687.42.1.el9\_8.x86\_64 | 7.9 | — | 2410-40905 | | 5.15.0-0.30.16.1.el9uek.x86\_64 | 7.9 | — | 770-25147 | | 5.15.0-0.30.19.el9uek.x86\_64 | 7.9 | — | 730-20271 | | 5.15.0-0.30.20.1.el9uek.x86\_64 | 7.9 | — | 720-19464 | | 5.15.0-0.30.20.el9uek.x86\_64 | 7.9 | — | 720-19464 | | 5.15.0-1.43.4.1.el9uek.x86\_64 | 7.9 | — | 720-19464 | | 5.15.0-1.43.4.2.el9uek.x86\_64 | 7.9 | — | 720-19464 | | 5.15.0-2.52.3.el9uek.x86\_64 | 7.9 | — | 730-20271 | | 5.15.0-3.60.5.1.el9uek.x86\_64 | 7.9 | — | 770-25147 | @@ -576,16 +583,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.15.0-307.178.5.el9uek.x86\_64 | 7.9 | — | 1740-15056 | | 5.15.0-308.179.6.2.el9uek.x86\_64 | 7.9 | — | 1780-16370 | | 5.15.0-308.179.6.3.el9uek.x86\_64 | 7.9 | — | 1790-16658 | | 5.15.0-308.179.6.7.el9uek.x86\_64 | 7.9 | — | 1900-20820 | | 5.15.0-308.179.6.11.el9uek.x86\_64 | 7.9 | — | 1900-20820 | | 5.15.0-308.179.6.14.el9uek.x86\_64 | 7.9 | — | 1910-21199 | | 5.15.0-308.179.6.16.el9uek.x86\_64 | 7.9 | — | 1970-24134 | | 5.15.0-308.179.6.18.el9uek.x86\_64 | 7.9 | — | 2390-39715 | +| 5.15.0-308.179.6.19.el9uek.x86\_64 | 7.9 | — | 2410-40905 | | 5.15.0-308.179.6.el9uek.x86\_64 | 7.9 | — | 1780-16370 | | 5.15.0-309.180.4.2.el9uek.x86\_64 | 7.9 | — | 1900-20820 | | 5.15.0-309.180.4.el9uek.x86\_64 | 7.9 | — | 1830-18249 | | 5.15.0-310.184.5.2.el9uek.x86\_64 | 7.9 | — | 1900-20820 | | 5.15.0-310.184.5.3.el9uek.x86\_64 | 7.9 | — | 1910-21199 | | 5.15.0-311.185.9.el9uek.x86\_64 | 7.9 | — | 1930-22185 | | 5.15.0-312.187.5.1.el9uek.x86\_64 | 7.9 | — | 1960-23396 | | 5.15.0-312.187.5.2.el9uek.x86\_64 | 7.9 | — | 1970-23938 | @@ -622,16 +630,17 @@ Cortex XDR agent supports the following kernel module versions for Oracle Linux | 5.15.0-322.203.3.2.el9uek.x86\_64 | 7.9 | — | 2340-38788 | | 5.15.0-322.203.3.3.el9uek.x86\_64 | 7.9 | — | 2340-38788 | | 5.15.0-322.203.3.4.1.el9uek.x86\_64 | 7.9 | — | 2390-40333 | | 5.15.0-322.203.3.4.5.el9uek.x86\_64 | 7.9 | — | 2380-40068 | | 5.15.0-322.203.3.4.el9uek.x86\_64 | 7.9 | — | 2390-39715 | | 5.15.0-322.203.3.5.el9uek.x86\_64 | 7.9 | — | 2390-40333 | | 5.15.0-323.211.3.3.el9uek.x86\_64 | 7.9 | — | 2390-40333 | | 5.15.0-323.211.3.4.el9uek.x86\_64 | 7.9 | — | 2400-40648 | +| 5.15.0-323.211.3.5.el9uek.x86\_64 | 7.9 | — | 2410-40905 | | 6.12.0-0.20.20.el9uek.x86\_64 | 8.3.100 | — | 1930-22185 | | 6.12.0-1.23.3.1.el9uek.x86\_64 | 8.3.100 | — | 1930-22185 | | 6.12.0-1.23.3.2.el9uek.x86\_64 | 8.3.100 | — | 1930-22185 | | 6.12.0-1.23.3.el9uek.x86\_64 | 8.3.100 | — | 1930-22185 | | 6.12.0-100.28.2.2.el9uek.x86\_64 | 8.3.100 | — | 1930-22185 | | 6.12.0-100.28.2.el9uek.x86\_64 | 8.3.100 | — | 1930-22185 | | 6.12.0-101.33.4.3.el9uek.x86\_64 | 8.3.100 | — | 1930-22185 | | 6.12.0-102.36.5.2.el9uek.x86\_64 | 8.3.100 | — | 1940-22526 |
-
▸ ▾ Red Hat Enterprise Linux (RHEL) 8 [aarch64] modified +1 −0
linux-kernels/red-hat-enterprise-linux-rhelRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -176,9 +176,10 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter4.18.0-553.148.1.el8_10.aarch64│7.1│—│2390-397154.18.0-553.148.1.el8_10.aarch64│7.1│—│2390-397154.18.0-553.150.1.el8_10.aarch64│7.1│—│2390-397154.18.0-553.150.1.el8_10.aarch64│7.1│—│2390-397154.18.0-553.151.1.el8_10.aarch64│7.1│—│2380-400684.18.0-553.151.1.el8_10.aarch64│7.1│—│2380-400684.18.0-553.153.1.el8_10.aarch64│7.1│—│2380-400684.18.0-553.153.1.el8_10.aarch64│7.1│—│2380-400684.18.0-553.154.1.el8_10.aarch64│7.1│—│2390-403334.18.0-553.154.1.el8_10.aarch64│7.1│—│2390-403334.18.0-553.155.1.el8_10.aarch64│7.1│—│2390-403334.18.0-553.155.1.el8_10.aarch64│7.1│—│2390-403334.18.0-553.156.1.el8_10.aarch64│7.1│—│2400-406484.18.0-553.156.1.el8_10.aarch64│7.1│—│2400-406484.18.0-553.157.1.el8_10.aarch64│7.1│—│2400-406484.18.0-553.157.1.el8_10.aarch64│7.1│—│2400-406484.18.0-553.158.1.el8_10.aarch64│7.1│—│2410-409054.18.0-553.el8_10.aarch64│7.1│—│1420-855554.18.0-553.el8_10.aarch64│7.1│—│1420-85555Show markdown source
@@ -176,9 +176,10 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter | 4.18.0-553.148.1.el8\_10.aarch64 | 7.1 | — | 2390-39715 | | 4.18.0-553.150.1.el8\_10.aarch64 | 7.1 | — | 2390-39715 | | 4.18.0-553.151.1.el8\_10.aarch64 | 7.1 | — | 2380-40068 | | 4.18.0-553.153.1.el8\_10.aarch64 | 7.1 | — | 2380-40068 | | 4.18.0-553.154.1.el8\_10.aarch64 | 7.1 | — | 2390-40333 | | 4.18.0-553.155.1.el8\_10.aarch64 | 7.1 | — | 2390-40333 | | 4.18.0-553.156.1.el8\_10.aarch64 | 7.1 | — | 2400-40648 | | 4.18.0-553.157.1.el8\_10.aarch64 | 7.1 | — | 2400-40648 | +| 4.18.0-553.158.1.el8\_10.aarch64 | 7.1 | — | 2410-40905 | | 4.18.0-553.el8\_10.aarch64 | 7.1 | — | 1420-85555 |
-
▸ ▾ Red Hat Enterprise Linux (RHEL) 9 [aarch64] modified +2 −0
linux-kernels/red-hat-enterprise-linux-rhelRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -181,16 +181,17 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter5.14.0-570.125.1.el9_6.aarch64│8.2│—│2330-383855.14.0-570.125.1.el9_6.aarch64│8.2│—│2330-383855.14.0-570.127.1.el9_6.aarch64│8.2│—│2390-397155.14.0-570.127.1.el9_6.aarch64│8.2│—│2390-397155.14.0-570.128.1.el9_6.aarch64│8.2│—│2390-397155.14.0-570.128.1.el9_6.aarch64│8.2│—│2390-397155.14.0-570.129.1.el9_6.aarch64│8.2│—│2390-397155.14.0-570.129.1.el9_6.aarch64│8.2│—│2390-397155.14.0-570.131.1.el9_6.aarch64│8.2│—│2390-397155.14.0-570.131.1.el9_6.aarch64│8.2│—│2390-397155.14.0-570.132.1.el9_6.aarch64│8.2│—│2390-403335.14.0-570.132.1.el9_6.aarch64│8.2│—│2390-403335.14.0-570.134.1.el9_6.aarch64│8.2│—│2390-403335.14.0-570.134.1.el9_6.aarch64│8.2│—│2390-403335.14.0-570.135.1.el9_6.aarch64│8.2│—│2400-406485.14.0-570.135.1.el9_6.aarch64│8.2│—│2400-406485.14.0-570.136.1.el9_6.aarch64│8.2│—│2410-409055.14.0-611.5.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.5.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.7.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.7.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.8.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.8.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.9.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.9.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.11.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.11.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.13.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.13.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.16.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.16.1.el9_7.aarch64│8.2│—│2090-287615.14.0-611.20.1.el9_7.aarch64│8.2│—│2100-292685.14.0-611.20.1.el9_7.aarch64│8.2│—│2100-29268@@ -227,8 +228,9 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter5.14.0-687.30.1.el9_8.aarch64│8.2│—│2390-397155.14.0-687.30.1.el9_8.aarch64│8.2│—│2390-397155.14.0-687.31.1.el9_8.aarch64│8.2│—│2390-397155.14.0-687.31.1.el9_8.aarch64│8.2│—│2390-397155.14.0-687.33.1.el9_8.aarch64│8.2│—│2390-397155.14.0-687.33.1.el9_8.aarch64│8.2│—│2390-397155.14.0-687.34.1.el9_8.aarch64│8.2│—│2380-400685.14.0-687.34.1.el9_8.aarch64│8.2│—│2380-400685.14.0-687.36.1.el9_8.aarch64│8.2│—│2380-400685.14.0-687.36.1.el9_8.aarch64│8.2│—│2380-400685.14.0-687.38.1.el9_8.aarch64│8.2│—│2390-403335.14.0-687.38.1.el9_8.aarch64│8.2│—│2390-403335.14.0-687.39.1.el9_8.aarch64│8.2│—│2390-403335.14.0-687.39.1.el9_8.aarch64│8.2│—│2390-403335.14.0-687.41.1.el9_8.aarch64│8.2│—│2400-406485.14.0-687.41.1.el9_8.aarch64│8.2│—│2400-406485.14.0-687.42.1.el9_8.aarch64│8.2│—│2410-40905Show markdown source
@@ -181,16 +181,17 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter | 5.14.0-570.125.1.el9\_6.aarch64 | 8.2 | — | 2330-38385 | | 5.14.0-570.127.1.el9\_6.aarch64 | 8.2 | — | 2390-39715 | | 5.14.0-570.128.1.el9\_6.aarch64 | 8.2 | — | 2390-39715 | | 5.14.0-570.129.1.el9\_6.aarch64 | 8.2 | — | 2390-39715 | | 5.14.0-570.131.1.el9\_6.aarch64 | 8.2 | — | 2390-39715 | | 5.14.0-570.132.1.el9\_6.aarch64 | 8.2 | — | 2390-40333 | | 5.14.0-570.134.1.el9\_6.aarch64 | 8.2 | — | 2390-40333 | | 5.14.0-570.135.1.el9\_6.aarch64 | 8.2 | — | 2400-40648 | +| 5.14.0-570.136.1.el9\_6.aarch64 | 8.2 | — | 2410-40905 | | 5.14.0-611.5.1.el9\_7.aarch64 | 8.2 | — | 2090-28761 | | 5.14.0-611.7.1.el9\_7.aarch64 | 8.2 | — | 2090-28761 | | 5.14.0-611.8.1.el9\_7.aarch64 | 8.2 | — | 2090-28761 | | 5.14.0-611.9.1.el9\_7.aarch64 | 8.2 | — | 2090-28761 | | 5.14.0-611.11.1.el9\_7.aarch64 | 8.2 | — | 2090-28761 | | 5.14.0-611.13.1.el9\_7.aarch64 | 8.2 | — | 2090-28761 | | 5.14.0-611.16.1.el9\_7.aarch64 | 8.2 | — | 2090-28761 | | 5.14.0-611.20.1.el9\_7.aarch64 | 8.2 | — | 2100-29268 | @@ -227,8 +228,9 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter | 5.14.0-687.30.1.el9\_8.aarch64 | 8.2 | — | 2390-39715 | | 5.14.0-687.31.1.el9\_8.aarch64 | 8.2 | — | 2390-39715 | | 5.14.0-687.33.1.el9\_8.aarch64 | 8.2 | — | 2390-39715 | | 5.14.0-687.34.1.el9\_8.aarch64 | 8.2 | — | 2380-40068 | | 5.14.0-687.36.1.el9\_8.aarch64 | 8.2 | — | 2380-40068 | | 5.14.0-687.38.1.el9\_8.aarch64 | 8.2 | — | 2390-40333 | | 5.14.0-687.39.1.el9\_8.aarch64 | 8.2 | — | 2390-40333 | | 5.14.0-687.41.1.el9\_8.aarch64 | 8.2 | — | 2400-40648 | +| 5.14.0-687.42.1.el9\_8.aarch64 | 8.2 | — | 2410-40905 |
-
▸ ▾ Red Hat Enterprise Linux (RHEL) 8 [x86_64] modified +1 −0
linux-kernels/red-hat-enterprise-linux-rhelRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -374,9 +374,10 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter4.18.0-553.148.1.el8_10.x86_64│7.1│—│2390-397154.18.0-553.148.1.el8_10.x86_64│7.1│—│2390-397154.18.0-553.150.1.el8_10.x86_64│7.1│—│2390-397154.18.0-553.150.1.el8_10.x86_64│7.1│—│2390-397154.18.0-553.151.1.el8_10.x86_64│7.1│—│2380-400684.18.0-553.151.1.el8_10.x86_64│7.1│—│2380-400684.18.0-553.153.1.el8_10.x86_64│7.1│—│2380-400684.18.0-553.153.1.el8_10.x86_64│7.1│—│2380-400684.18.0-553.154.1.el8_10.x86_64│7.1│—│2390-403334.18.0-553.154.1.el8_10.x86_64│7.1│—│2390-403334.18.0-553.155.1.el8_10.x86_64│7.1│—│2390-403334.18.0-553.155.1.el8_10.x86_64│7.1│—│2390-403334.18.0-553.156.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.156.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.157.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.157.1.el8_10.x86_64│7.1│—│2400-406484.18.0-553.158.1.el8_10.x86_64│7.1│—│2410-409054.18.0-553.el8_10.x86_64│7.1│—│1420-855554.18.0-553.el8_10.x86_64│7.1│—│1420-85555Show markdown source
@@ -374,9 +374,10 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter | 4.18.0-553.148.1.el8\_10.x86\_64 | 7.1 | — | 2390-39715 | | 4.18.0-553.150.1.el8\_10.x86\_64 | 7.1 | — | 2390-39715 | | 4.18.0-553.151.1.el8\_10.x86\_64 | 7.1 | — | 2380-40068 | | 4.18.0-553.153.1.el8\_10.x86\_64 | 7.1 | — | 2380-40068 | | 4.18.0-553.154.1.el8\_10.x86\_64 | 7.1 | — | 2390-40333 | | 4.18.0-553.155.1.el8\_10.x86\_64 | 7.1 | — | 2390-40333 | | 4.18.0-553.156.1.el8\_10.x86\_64 | 7.1 | — | 2400-40648 | | 4.18.0-553.157.1.el8\_10.x86\_64 | 7.1 | — | 2400-40648 | +| 4.18.0-553.158.1.el8\_10.x86\_64 | 7.1 | — | 2410-40905 | | 4.18.0-553.el8\_10.x86\_64 | 7.1 | — | 1420-85555 |
-
▸ ▾ Red Hat Enterprise Linux (RHEL) 9 [x86_64] modified +6 −0
linux-kernels/red-hat-enterprise-linux-rhelRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -147,16 +147,18 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter5.14.0-284.178.1.el9_2.x86_64│7.9│—│2330-383855.14.0-284.178.1.el9_2.x86_64│7.9│—│2330-383855.14.0-284.179.1.el9_2.x86_64│7.9│—│2340-387885.14.0-284.179.1.el9_2.x86_64│7.9│—│2340-387885.14.0-284.181.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.181.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.182.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.182.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.183.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.183.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.184.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.184.1.el9_2.x86_64│7.9│—│2390-397155.14.0-284.186.1.el9_2.x86_64│7.9│—│2380-400685.14.0-284.186.1.el9_2.x86_64│7.9│—│2380-400685.14.0-284.187.1.el9_2.x86_64│7.9│—│2390-403335.14.0-284.187.1.el9_2.x86_64│7.9│—│2390-403335.14.0-284.188.1.el9_2.x86_64│7.9│—│2410-409055.14.0-284.189.1.el9_2.x86_64│7.9│—│2410-409055.14.0-362.8.1.el9_3.x86_64│7.9│—│1190-746835.14.0-362.8.1.el9_3.x86_64│7.9│—│1190-746835.14.0-362.13.1.el9_3.x86_64│7.9│—│1200-760065.14.0-362.13.1.el9_3.x86_64│7.9│—│1200-760065.14.0-362.18.1.el9_3.x86_64│7.9│—│1250-777135.14.0-362.18.1.el9_3.x86_64│7.9│—│1250-777135.14.0-362.24.1.el9_3.x86_64│7.9│—│1310-801555.14.0-362.24.1.el9_3.x86_64│7.9│—│1310-801555.14.0-427.13.1.el9_4.x86_64│7.9│—│1420-855555.14.0-427.13.1.el9_4.x86_64│7.9│—│1420-855555.14.0-427.16.1.el9_4.x86_64│7.9│—│1420-855555.14.0-427.16.1.el9_4.x86_64│7.9│—│1420-855555.14.0-427.18.1.el9_4.x86_64│7.9│—│1420-855555.14.0-427.18.1.el9_4.x86_64│7.9│—│1420-855555.14.0-427.20.1.el9_4.x86_64│7.9│—│1420-855555.14.0-427.20.1.el9_4.x86_64│7.9│—│1420-85555@@ -232,16 +234,18 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter5.14.0-427.136.1.el9_4.x86_64│7.9│—│2340-387885.14.0-427.136.1.el9_4.x86_64│7.9│—│2340-387885.14.0-427.137.1.el9_4.x86_64│7.9│—│2340-387885.14.0-427.137.1.el9_4.x86_64│7.9│—│2340-387885.14.0-427.138.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.138.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.139.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.139.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.141.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.141.1.el9_4.x86_64│7.9│—│2390-397155.14.0-427.143.1.el9_4.x86_64│7.9│—│2380-400685.14.0-427.143.1.el9_4.x86_64│7.9│—│2380-400685.14.0-427.144.1.el9_4.x86_64│7.9│—│2390-403335.14.0-427.144.1.el9_4.x86_64│7.9│—│2390-403335.14.0-427.145.1.el9_4.x86_64│7.9│—│2400-406485.14.0-427.145.1.el9_4.x86_64│7.9│—│2400-406485.14.0-427.146.1.el9_4.x86_64│7.9│—│2410-409055.14.0-427.147.1.el9_4.x86_64│7.9│—│2410-409055.14.0-503.11.1.el9_5.x86_64│7.9│—│1600-920555.14.0-503.11.1.el9_5.x86_64│7.9│—│1600-920555.14.0-503.14.1.el9_5.x86_64│7.9│—│1600-920555.14.0-503.14.1.el9_5.x86_64│7.9│—│1600-920555.14.0-503.15.1.el9_5.x86_64│7.9│—│1610-937925.14.0-503.15.1.el9_5.x86_64│7.9│—│1610-937925.14.0-503.16.1.el9_5.x86_64│7.9│—│1620-941605.14.0-503.16.1.el9_5.x86_64│7.9│—│1620-941605.14.0-503.19.1.el9_5.x86_64│7.9│—│1620-941605.14.0-503.19.1.el9_5.x86_64│7.9│—│1620-941605.14.0-503.21.1.el9_5.x86_64│7.9│—│1630-103755.14.0-503.21.1.el9_5.x86_64│7.9│—│1630-103755.14.0-503.22.1.el9_5.x86_64│7.9│—│1650-111435.14.0-503.22.1.el9_5.x86_64│7.9│—│1650-111435.14.0-503.23.1.el9_5.x86_64│7.9│—│1660-115165.14.0-503.23.1.el9_5.x86_64│7.9│—│1660-11516@@ -314,16 +318,17 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter5.14.0-570.125.1.el9_6.x86_64│7.9│—│2330-383855.14.0-570.125.1.el9_6.x86_64│7.9│—│2330-383855.14.0-570.127.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.127.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.128.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.128.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.129.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.129.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.131.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.131.1.el9_6.x86_64│7.9│—│2390-397155.14.0-570.132.1.el9_6.x86_64│7.9│—│2390-403335.14.0-570.132.1.el9_6.x86_64│7.9│—│2390-403335.14.0-570.134.1.el9_6.x86_64│7.9│—│2390-403335.14.0-570.134.1.el9_6.x86_64│7.9│—│2390-403335.14.0-570.135.1.el9_6.x86_64│7.9│—│2400-406485.14.0-570.135.1.el9_6.x86_64│7.9│—│2400-406485.14.0-570.136.1.el9_6.x86_64│7.9│—│2410-409055.14.0-611.5.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.5.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.7.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.7.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.8.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.8.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.9.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.9.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.11.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.11.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.13.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.13.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.16.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.16.1.el9_7.x86_64│7.9│—│2090-287615.14.0-611.20.1.el9_7.x86_64│7.9│—│2100-292685.14.0-611.20.1.el9_7.x86_64│7.9│—│2100-29268@@ -360,8 +365,9 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter5.14.0-687.30.1.el9_8.x86_64│7.9│—│2390-397155.14.0-687.30.1.el9_8.x86_64│7.9│—│2390-397155.14.0-687.31.1.el9_8.x86_64│7.9│—│2390-397155.14.0-687.31.1.el9_8.x86_64│7.9│—│2390-397155.14.0-687.33.1.el9_8.x86_64│7.9│—│2390-397155.14.0-687.33.1.el9_8.x86_64│7.9│—│2390-397155.14.0-687.34.1.el9_8.x86_64│7.9│—│2380-400685.14.0-687.34.1.el9_8.x86_64│7.9│—│2380-400685.14.0-687.36.1.el9_8.x86_64│7.9│—│2380-400685.14.0-687.36.1.el9_8.x86_64│7.9│—│2380-400685.14.0-687.38.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.39.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.39.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.41.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.41.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.42.1.el9_8.x86_64│7.9│—│2410-40905Show markdown source
@@ -147,16 +147,18 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter | 5.14.0-284.178.1.el9\_2.x86\_64 | 7.9 | — | 2330-38385 | | 5.14.0-284.179.1.el9\_2.x86\_64 | 7.9 | — | 2340-38788 | | 5.14.0-284.181.1.el9\_2.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-284.182.1.el9\_2.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-284.183.1.el9\_2.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-284.184.1.el9\_2.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-284.186.1.el9\_2.x86\_64 | 7.9 | — | 2380-40068 | | 5.14.0-284.187.1.el9\_2.x86\_64 | 7.9 | — | 2390-40333 | +| 5.14.0-284.188.1.el9\_2.x86\_64 | 7.9 | — | 2410-40905 | +| 5.14.0-284.189.1.el9\_2.x86\_64 | 7.9 | — | 2410-40905 | | 5.14.0-362.8.1.el9\_3.x86\_64 | 7.9 | — | 1190-74683 | | 5.14.0-362.13.1.el9\_3.x86\_64 | 7.9 | — | 1200-76006 | | 5.14.0-362.18.1.el9\_3.x86\_64 | 7.9 | — | 1250-77713 | | 5.14.0-362.24.1.el9\_3.x86\_64 | 7.9 | — | 1310-80155 | | 5.14.0-427.13.1.el9\_4.x86\_64 | 7.9 | — | 1420-85555 | | 5.14.0-427.16.1.el9\_4.x86\_64 | 7.9 | — | 1420-85555 | | 5.14.0-427.18.1.el9\_4.x86\_64 | 7.9 | — | 1420-85555 | | 5.14.0-427.20.1.el9\_4.x86\_64 | 7.9 | — | 1420-85555 | @@ -232,16 +234,18 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter | 5.14.0-427.136.1.el9\_4.x86\_64 | 7.9 | — | 2340-38788 | | 5.14.0-427.137.1.el9\_4.x86\_64 | 7.9 | — | 2340-38788 | | 5.14.0-427.138.1.el9\_4.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-427.139.1.el9\_4.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-427.141.1.el9\_4.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-427.143.1.el9\_4.x86\_64 | 7.9 | — | 2380-40068 | | 5.14.0-427.144.1.el9\_4.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-427.145.1.el9\_4.x86\_64 | 7.9 | — | 2400-40648 | +| 5.14.0-427.146.1.el9\_4.x86\_64 | 7.9 | — | 2410-40905 | +| 5.14.0-427.147.1.el9\_4.x86\_64 | 7.9 | — | 2410-40905 | | 5.14.0-503.11.1.el9\_5.x86\_64 | 7.9 | — | 1600-92055 | | 5.14.0-503.14.1.el9\_5.x86\_64 | 7.9 | — | 1600-92055 | | 5.14.0-503.15.1.el9\_5.x86\_64 | 7.9 | — | 1610-93792 | | 5.14.0-503.16.1.el9\_5.x86\_64 | 7.9 | — | 1620-94160 | | 5.14.0-503.19.1.el9\_5.x86\_64 | 7.9 | — | 1620-94160 | | 5.14.0-503.21.1.el9\_5.x86\_64 | 7.9 | — | 1630-10375 | | 5.14.0-503.22.1.el9\_5.x86\_64 | 7.9 | — | 1650-11143 | | 5.14.0-503.23.1.el9\_5.x86\_64 | 7.9 | — | 1660-11516 | @@ -314,16 +318,17 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter | 5.14.0-570.125.1.el9\_6.x86\_64 | 7.9 | — | 2330-38385 | | 5.14.0-570.127.1.el9\_6.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-570.128.1.el9\_6.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-570.129.1.el9\_6.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-570.131.1.el9\_6.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-570.132.1.el9\_6.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-570.134.1.el9\_6.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-570.135.1.el9\_6.x86\_64 | 7.9 | — | 2400-40648 | +| 5.14.0-570.136.1.el9\_6.x86\_64 | 7.9 | — | 2410-40905 | | 5.14.0-611.5.1.el9\_7.x86\_64 | 7.9 | — | 2090-28761 | | 5.14.0-611.7.1.el9\_7.x86\_64 | 7.9 | — | 2090-28761 | | 5.14.0-611.8.1.el9\_7.x86\_64 | 7.9 | — | 2090-28761 | | 5.14.0-611.9.1.el9\_7.x86\_64 | 7.9 | — | 2090-28761 | | 5.14.0-611.11.1.el9\_7.x86\_64 | 7.9 | — | 2090-28761 | | 5.14.0-611.13.1.el9\_7.x86\_64 | 7.9 | — | 2090-28761 | | 5.14.0-611.16.1.el9\_7.x86\_64 | 7.9 | — | 2090-28761 | | 5.14.0-611.20.1.el9\_7.x86\_64 | 7.9 | — | 2100-29268 | @@ -360,8 +365,9 @@ Cortex XDR agent supports the following kernel module versions for Red Hat Enter | 5.14.0-687.30.1.el9\_8.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-687.31.1.el9\_8.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-687.33.1.el9\_8.x86\_64 | 7.9 | — | 2390-39715 | | 5.14.0-687.34.1.el9\_8.x86\_64 | 7.9 | — | 2380-40068 | | 5.14.0-687.36.1.el9\_8.x86\_64 | 7.9 | — | 2380-40068 | | 5.14.0-687.38.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.39.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.41.1.el9\_8.x86\_64 | 7.9 | — | 2400-40648 | +| 5.14.0-687.42.1.el9\_8.x86\_64 | 7.9 | — | 2410-40905 |
-
▸ ▾ Rocky Linux 9 [aarch64] modified +1 −0
linux-kernels/rocky-linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -59,8 +59,9 @@ Cortex XDR agent supports the following kernel module versions for Rocky Linux 95.14.0-687.30.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.30.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.31.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.31.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.33.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.33.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.34.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.34.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.36.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.36.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.38.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.38.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.39.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.39.1.el9_8.aarch64│8.3.100│—│2390-403335.14.0-687.41.1.el9_8.aarch64│8.3.100│—│2400-406485.14.0-687.41.1.el9_8.aarch64│8.3.100│—│2400-406485.14.0-687.42.1.el9_8.aarch64│8.3.100│—│2410-40905Show markdown source
@@ -59,8 +59,9 @@ Cortex XDR agent supports the following kernel module versions for Rocky Linux 9 | 5.14.0-687.30.1.el9\_8.aarch64 | 8.3.100 | — | 2390-40333 | | 5.14.0-687.31.1.el9\_8.aarch64 | 8.3.100 | — | 2390-40333 | | 5.14.0-687.33.1.el9\_8.aarch64 | 8.3.100 | — | 2390-40333 | | 5.14.0-687.34.1.el9\_8.aarch64 | 8.3.100 | — | 2390-40333 | | 5.14.0-687.36.1.el9\_8.aarch64 | 8.3.100 | — | 2390-40333 | | 5.14.0-687.38.1.el9\_8.aarch64 | 8.3.100 | — | 2390-40333 | | 5.14.0-687.39.1.el9\_8.aarch64 | 8.3.100 | — | 2390-40333 | | 5.14.0-687.41.1.el9\_8.aarch64 | 8.3.100 | — | 2400-40648 | +| 5.14.0-687.42.1.el9\_8.aarch64 | 8.3.100 | — | 2410-40905 |
-
▸ ▾ Rocky Linux 8 [x86_64] modified +1 −0
linux-kernels/rocky-linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -98,9 +98,10 @@ Cortex XDR agent supports the following kernel module versions for Rocky Linux 84.18.0-553.148.1.el8_10.x86_64│7.8│—│2390-397154.18.0-553.148.1.el8_10.x86_64│7.8│—│2390-397154.18.0-553.150.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.150.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.151.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.151.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.153.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.153.1.el8_10.x86_64│7.8│—│2380-400684.18.0-553.154.1.el8_10.x86_64│7.8│—│2390-403334.18.0-553.154.1.el8_10.x86_64│7.8│—│2390-403334.18.0-553.155.1.el8_10.x86_64│7.8│—│2390-403334.18.0-553.155.1.el8_10.x86_64│7.8│—│2390-403334.18.0-553.156.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.156.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.157.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.157.1.el8_10.x86_64│7.8│—│2400-406484.18.0-553.158.1.el8_10.x86_64│7.8│—│2410-409054.18.0-553.el8_10.x86_64│7.8│—│1520-896164.18.0-553.el8_10.x86_64│7.8│—│1520-89616Show markdown source
@@ -98,9 +98,10 @@ Cortex XDR agent supports the following kernel module versions for Rocky Linux 8 | 4.18.0-553.148.1.el8\_10.x86\_64 | 7.8 | — | 2390-39715 | | 4.18.0-553.150.1.el8\_10.x86\_64 | 7.8 | — | 2380-40068 | | 4.18.0-553.151.1.el8\_10.x86\_64 | 7.8 | — | 2380-40068 | | 4.18.0-553.153.1.el8\_10.x86\_64 | 7.8 | — | 2380-40068 | | 4.18.0-553.154.1.el8\_10.x86\_64 | 7.8 | — | 2390-40333 | | 4.18.0-553.155.1.el8\_10.x86\_64 | 7.8 | — | 2390-40333 | | 4.18.0-553.156.1.el8\_10.x86\_64 | 7.8 | — | 2400-40648 | | 4.18.0-553.157.1.el8\_10.x86\_64 | 7.8 | — | 2400-40648 | +| 4.18.0-553.158.1.el8\_10.x86\_64 | 7.8 | — | 2410-40905 | | 4.18.0-553.el8\_10.x86\_64 | 7.8 | — | 1520-89616 |
-
▸ ▾ Rocky Linux 9 [x86_64] modified +1 −0
linux-kernels/rocky-linuxRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -105,8 +105,9 @@ Cortex XDR agent supports the following kernel module versions for Rocky Linux 95.14.0-687.30.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.30.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.31.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.31.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.33.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.33.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.34.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.34.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.36.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.36.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.38.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.39.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.39.1.el9_8.x86_64│7.9│—│2390-403335.14.0-687.41.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.41.1.el9_8.x86_64│7.9│—│2400-406485.14.0-687.42.1.el9_8.x86_64│7.9│—│2410-40905Show markdown source
@@ -105,8 +105,9 @@ Cortex XDR agent supports the following kernel module versions for Rocky Linux 9 | 5.14.0-687.30.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.31.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.33.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.34.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.36.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.38.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.39.1.el9\_8.x86\_64 | 7.9 | — | 2390-40333 | | 5.14.0-687.41.1.el9\_8.x86\_64 | 7.9 | — | 2400-40648 | +| 5.14.0-687.42.1.el9\_8.x86\_64 | 7.9 | — | 2410-40905 |
-
▸ ▾ SUSE Linux Enterprise Server 16 [x86_64] modified +1 −0
linux-kernels/suse-linux-enterprise-serverRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -15,8 +15,9 @@ Cortex XDR agent supports the following kernel module versions for SUSE Linux En6.12.0-160000.29-default│8.3.100│—│2270-366576.12.0-160000.29-default│8.3.100│—│2270-366576.12.0-160000.30-default│8.3.100│—│2270-366576.12.0-160000.30-default│8.3.100│—│2270-366576.12.0-160000.31-default│8.3.100│—│2280-368946.12.0-160000.31-default│8.3.100│—│2280-368946.12.0-160000.32-default│8.3.100│—│2280-368946.12.0-160000.32-default│8.3.100│—│2280-368946.12.0-160000.33-default│8.3.100│—│2280-370556.12.0-160000.33-default│8.3.100│—│2280-370556.12.0-160000.34-default│8.3.100│—│2310-377966.12.0-160000.34-default│8.3.100│—│2310-377966.12.0-160000.35-default│8.3.100│—│2310-377966.12.0-160000.35-default│8.3.100│—│2310-377966.12.0-160000.36-default│8.3.100│—│2390-397156.12.0-160000.36-default│8.3.100│—│2390-397156.12.0-160000.37-default│8.3.100│—│2410-40905Show markdown source
@@ -15,8 +15,9 @@ Cortex XDR agent supports the following kernel module versions for SUSE Linux En | 6.12.0-160000.29-default | 8.3.100 | — | 2270-36657 | | 6.12.0-160000.30-default | 8.3.100 | — | 2270-36657 | | 6.12.0-160000.31-default | 8.3.100 | — | 2280-36894 | | 6.12.0-160000.32-default | 8.3.100 | — | 2280-36894 | | 6.12.0-160000.33-default | 8.3.100 | — | 2280-37055 | | 6.12.0-160000.34-default | 8.3.100 | — | 2310-37796 | | 6.12.0-160000.35-default | 8.3.100 | — | 2310-37796 | | 6.12.0-160000.36-default | 8.3.100 | — | 2390-39715 | +| 6.12.0-160000.37-default | 8.3.100 | — | 2410-40905 |
-
▸ ▾ Ubuntu 18 [aarch64] modified +1 −0
linux-kernels/ubuntuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -817,8 +817,9 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 18 \[a5.4.0-1162-azure│7.9│—│2260-362675.4.0-1162-azure│7.9│—│2260-362675.4.0-1162-gcp│7.9│—│2260-362675.4.0-1162-gcp│7.9│—│2260-362675.4.0-1163-azure│7.9│—│2270-366575.4.0-1163-azure│7.9│—│2270-366575.4.0-1163-gcp│7.9│—│2290-372085.4.0-1163-gcp│7.9│—│2290-372085.4.0-1164-azure│7.9│—│2290-372085.4.0-1164-azure│7.9│—│2290-372085.4.0-1164-gcp│7.9│—│2390-397155.4.0-1164-gcp│7.9│—│2390-397155.4.0-1165-gcp│7.9│—│2400-406485.4.0-1165-gcp│7.9│—│2400-406485.4.0-1166-azure│7.9│—│2390-397155.4.0-1166-azure│7.9│—│2390-397155.4.0-1167-azure│7.9│—│2410-40905Show markdown source
@@ -817,8 +817,9 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 18 \[a | 5.4.0-1162-azure | 7.9 | — | 2260-36267 | | 5.4.0-1162-gcp | 7.9 | — | 2260-36267 | | 5.4.0-1163-azure | 7.9 | — | 2270-36657 | | 5.4.0-1163-gcp | 7.9 | — | 2290-37208 | | 5.4.0-1164-azure | 7.9 | — | 2290-37208 | | 5.4.0-1164-gcp | 7.9 | — | 2390-39715 | | 5.4.0-1165-gcp | 7.9 | — | 2400-40648 | | 5.4.0-1166-azure | 7.9 | — | 2390-39715 | +| 5.4.0-1167-azure | 7.9 | — | 2410-40905 |
-
▸ ▾ Ubuntu 22 [aarch64] modified +3 −0
linux-kernels/ubuntuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -403,16 +403,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 22 \[a5.15.0-1108-gcp│7.9│—│2260-362675.15.0-1108-gcp│7.9│—│2260-362675.15.0-1108-gke│7.9│—│2390-397155.15.0-1108-gke│7.9│—│2390-397155.15.0-1108-oracle│8.3│—│2320-381245.15.0-1108-oracle│8.3│—│2320-381245.15.0-1109-aws│7.9│—│2290-372085.15.0-1109-aws│7.9│—│2290-372085.15.0-1109-azure│7.9│—│2220-342425.15.0-1109-azure│7.9│—│2220-342425.15.0-1109-gcp│7.9│—│2290-372085.15.0-1109-gcp│7.9│—│2290-372085.15.0-1109-oracle│8.3│—│2390-397155.15.0-1109-oracle│8.3│—│2390-397155.15.0-1110-azure│7.9│—│2230-347895.15.0-1110-azure│7.9│—│2230-347895.15.0-1110-gke│7.9│—│2410-409055.15.0-1110-oracle│8.3│—│2390-403335.15.0-1110-oracle│8.3│—│2390-403335.15.0-1111-aws│7.9│—│2320-381245.15.0-1111-aws│7.9│—│2320-381245.15.0-1111-azure│7.9│—│2250-358525.15.0-1111-azure│7.9│—│2250-358525.15.0-1111-gcp│7.9│—│2330-383855.15.0-1111-gcp│7.9│—│2330-383855.15.0-1111-oracle│8.3│—│2400-406485.15.0-1111-oracle│8.3│—│2400-406485.15.0-1112-aws│7.9│—│2390-397155.15.0-1112-aws│7.9│—│2390-397155.15.0-1112-gcp│7.9│—│2390-397155.15.0-1112-gcp│7.9│—│2390-397155.15.0-1113-aws│7.9│—│2380-400685.15.0-1113-aws│7.9│—│2380-40068@@ -746,18 +747,20 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 22 \[a6.8.0-1057-aws│7.9│—│2280-368946.8.0-1057-aws│7.9│—│2280-368946.8.0-1057-oracle│8.3│—│2330-383856.8.0-1057-oracle│8.3│—│2330-383856.8.0-1058-gcp│7.9│—│2260-362676.8.0-1058-gcp│7.9│—│2260-362676.8.0-1058-oracle│8.3│—│2390-397156.8.0-1058-oracle│8.3│—│2390-397156.8.0-1059-azure│7.9│—│2300-375236.8.0-1059-azure│7.9│—│2300-375236.8.0-1059-oracle│8.3│—│2400-406486.8.0-1059-oracle│8.3│—│2400-406486.8.0-1060-aws│7.9│—│2330-383856.8.0-1060-aws│7.9│—│2330-383856.8.0-1060-gcp│7.9│—│2280-368946.8.0-1060-gcp│7.9│—│2280-368946.8.0-1060-oracle│8.3│—│2410-409056.8.0-1061-aws│7.9│—│2390-397156.8.0-1061-aws│7.9│—│2390-397156.8.0-1062-aws│7.9│—│2400-406486.8.0-1062-aws│7.9│—│2400-406486.8.0-1062-azure│7.9│—│2340-387886.8.0-1062-azure│7.9│—│2340-387886.8.0-1063-aws│7.9│—│2400-406486.8.0-1063-aws│7.9│—│2400-406486.8.0-1063-azure│7.9│—│2390-397156.8.0-1063-azure│7.9│—│2390-397156.8.0-1063-gcp│7.9│—│2330-383856.8.0-1063-gcp│7.9│—│2330-383856.8.0-1064-azure│7.9│—│2380-400686.8.0-1064-azure│7.9│—│2380-400686.8.0-1064-gcp│7.9│—│2390-397156.8.0-1064-gcp│7.9│—│2390-397156.8.0-1065-azure│7.9│—│2410-409056.8.0-1065-gcp│7.9│—│2380-400686.8.0-1065-gcp│7.9│—│2380-400686.8.0-1066-gcp│7.9│—│2400-406486.8.0-1066-gcp│7.9│—│2400-40648Show markdown source
@@ -403,16 +403,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 22 \[a | 5.15.0-1108-gcp | 7.9 | — | 2260-36267 | | 5.15.0-1108-gke | 7.9 | — | 2390-39715 | | 5.15.0-1108-oracle | 8.3 | — | 2320-38124 | | 5.15.0-1109-aws | 7.9 | — | 2290-37208 | | 5.15.0-1109-azure | 7.9 | — | 2220-34242 | | 5.15.0-1109-gcp | 7.9 | — | 2290-37208 | | 5.15.0-1109-oracle | 8.3 | — | 2390-39715 | | 5.15.0-1110-azure | 7.9 | — | 2230-34789 | +| 5.15.0-1110-gke | 7.9 | — | 2410-40905 | | 5.15.0-1110-oracle | 8.3 | — | 2390-40333 | | 5.15.0-1111-aws | 7.9 | — | 2320-38124 | | 5.15.0-1111-azure | 7.9 | — | 2250-35852 | | 5.15.0-1111-gcp | 7.9 | — | 2330-38385 | | 5.15.0-1111-oracle | 8.3 | — | 2400-40648 | | 5.15.0-1112-aws | 7.9 | — | 2390-39715 | | 5.15.0-1112-gcp | 7.9 | — | 2390-39715 | | 5.15.0-1113-aws | 7.9 | — | 2380-40068 | @@ -746,18 +747,20 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 22 \[a | 6.8.0-1057-aws | 7.9 | — | 2280-36894 | | 6.8.0-1057-oracle | 8.3 | — | 2330-38385 | | 6.8.0-1058-gcp | 7.9 | — | 2260-36267 | | 6.8.0-1058-oracle | 8.3 | — | 2390-39715 | | 6.8.0-1059-azure | 7.9 | — | 2300-37523 | | 6.8.0-1059-oracle | 8.3 | — | 2400-40648 | | 6.8.0-1060-aws | 7.9 | — | 2330-38385 | | 6.8.0-1060-gcp | 7.9 | — | 2280-36894 | +| 6.8.0-1060-oracle | 8.3 | — | 2410-40905 | | 6.8.0-1061-aws | 7.9 | — | 2390-39715 | | 6.8.0-1062-aws | 7.9 | — | 2400-40648 | | 6.8.0-1062-azure | 7.9 | — | 2340-38788 | | 6.8.0-1063-aws | 7.9 | — | 2400-40648 | | 6.8.0-1063-azure | 7.9 | — | 2390-39715 | | 6.8.0-1063-gcp | 7.9 | — | 2330-38385 | | 6.8.0-1064-azure | 7.9 | — | 2380-40068 | | 6.8.0-1064-gcp | 7.9 | — | 2390-39715 | +| 6.8.0-1065-azure | 7.9 | — | 2410-40905 | | 6.8.0-1065-gcp | 7.9 | — | 2380-40068 | | 6.8.0-1066-gcp | 7.9 | — | 2400-40648 |
-
▸ ▾ Ubuntu 26 [aarch64] modified +1 −0
linux-kernels/ubuntuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -28,11 +28,12 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 26 \[a7.0.0-1008-gcp│9.1.0│—│2390-403337.0.0-1008-gcp│9.1.0│—│2390-403337.0.0-1008-oracle│9.1.0│—│2390-403337.0.0-1008-oracle│9.1.0│—│2390-403337.0.0-1009-aws│9.1.0│—│2390-403337.0.0-1009-aws│9.1.0│—│2390-403337.0.0-1009-azure│9.1.0│—│2390-403337.0.0-1009-azure│9.1.0│—│2390-403337.0.0-1009-oracle│9.1.0│—│2390-403337.0.0-1009-oracle│9.1.0│—│2390-403337.0.0-1010-aws│9.1.0│—│2390-403337.0.0-1010-aws│9.1.0│—│2390-403337.0.0-1010-azure│9.1.0│—│2390-403337.0.0-1010-azure│9.1.0│—│2390-403337.0.0-1010-gcp│9.1.0│—│2400-406487.0.0-1010-gcp│9.1.0│—│2400-406487.0.0-1010-oracle│9.1.0│—│2410-409057.0.0-1011-aws│9.1.0│—│2400-406487.0.0-1011-aws│9.1.0│—│2400-406487.0.0-1011-azure│9.1.0│—│2390-403337.0.0-1011-azure│9.1.0│—│2390-403337.0.0-1012-azure│9.1.0│—│2400-406487.0.0-1012-azure│9.1.0│—│2400-40648Show markdown source
@@ -28,11 +28,12 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 26 \[a | 7.0.0-1008-gcp | 9.1.0 | — | 2390-40333 | | 7.0.0-1008-oracle | 9.1.0 | — | 2390-40333 | | 7.0.0-1009-aws | 9.1.0 | — | 2390-40333 | | 7.0.0-1009-azure | 9.1.0 | — | 2390-40333 | | 7.0.0-1009-oracle | 9.1.0 | — | 2390-40333 | | 7.0.0-1010-aws | 9.1.0 | — | 2390-40333 | | 7.0.0-1010-azure | 9.1.0 | — | 2390-40333 | | 7.0.0-1010-gcp | 9.1.0 | — | 2400-40648 | +| 7.0.0-1010-oracle | 9.1.0 | — | 2410-40905 | | 7.0.0-1011-aws | 9.1.0 | — | 2400-40648 | | 7.0.0-1011-azure | 9.1.0 | — | 2390-40333 | | 7.0.0-1012-azure | 9.1.0 | — | 2400-40648 |
-
▸ ▾ Ubuntu 18 [x86_64] modified +2 −0
linux-kernels/ubuntuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1140,16 +1140,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 18 \[x4.15.0-1196-azure│7.1│—│2140-309754.15.0-1196-azure│7.1│—│2140-309754.15.0-1197-azure│7.1│—│2210-339464.15.0-1197-azure│7.1│—│2210-339464.15.0-1199-azure│7.1│—│2220-345414.15.0-1199-azure│7.1│—│2220-345414.15.0-1200-azure│7.1│—│2250-358524.15.0-1200-azure│7.1│—│2250-358524.15.0-1201-azure│7.1│—│2270-366574.15.0-1201-azure│7.1│—│2270-366574.15.0-1202-azure│7.1│—│2290-372084.15.0-1202-azure│7.1│—│2290-372084.15.0-1204-azure│7.1│—│2340-387884.15.0-1204-azure│7.1│—│2340-387884.15.0-1205-azure│7.1│—│2390-403334.15.0-1205-azure│7.1│—│2390-403334.15.0-1206-azure│7.1│—│2410-409054.18.0-13-generic│7.1│—│450-875564.18.0-13-generic│7.1│—│450-875564.18.0-14-generic│7.1│—│450-875564.18.0-14-generic│7.1│—│450-875564.18.0-15-generic│7.1│—│450-875564.18.0-15-generic│7.1│—│450-875564.18.0-16-generic│7.1│—│450-875564.18.0-16-generic│7.1│—│450-875564.18.0-17-generic│7.1│—│450-875564.18.0-17-generic│7.1│—│450-875564.18.0-18-generic│7.1│—│450-875564.18.0-18-generic│7.1│—│450-875564.18.0-20-generic│7.1│—│450-875564.18.0-20-generic│7.1│—│450-875564.18.0-21-generic│7.1│—│450-875564.18.0-21-generic│7.1│—│450-87556@@ -2081,8 +2082,9 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 18 \[x5.4.0-1162-azure│7.1│—│2260-362675.4.0-1162-azure│7.1│—│2260-362675.4.0-1162-gcp│7.1│—│2260-362675.4.0-1162-gcp│7.1│—│2260-362675.4.0-1163-azure│7.1│—│2270-366575.4.0-1163-azure│7.1│—│2270-366575.4.0-1163-gcp│7.1│—│2290-372085.4.0-1163-gcp│7.1│—│2290-372085.4.0-1164-azure│7.1│—│2290-372085.4.0-1164-azure│7.1│—│2290-372085.4.0-1164-gcp│7.1│—│2390-397155.4.0-1164-gcp│7.1│—│2390-397155.4.0-1165-gcp│7.1│—│2400-406485.4.0-1165-gcp│7.1│—│2400-406485.4.0-1166-azure│7.1│—│2390-397155.4.0-1166-azure│7.1│—│2390-397155.4.0-1167-azure│7.1│—│2410-40905Show markdown source
@@ -1140,16 +1140,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 18 \[x | 4.15.0-1196-azure | 7.1 | — | 2140-30975 | | 4.15.0-1197-azure | 7.1 | — | 2210-33946 | | 4.15.0-1199-azure | 7.1 | — | 2220-34541 | | 4.15.0-1200-azure | 7.1 | — | 2250-35852 | | 4.15.0-1201-azure | 7.1 | — | 2270-36657 | | 4.15.0-1202-azure | 7.1 | — | 2290-37208 | | 4.15.0-1204-azure | 7.1 | — | 2340-38788 | | 4.15.0-1205-azure | 7.1 | — | 2390-40333 | +| 4.15.0-1206-azure | 7.1 | — | 2410-40905 | | 4.18.0-13-generic | 7.1 | — | 450-87556 | | 4.18.0-14-generic | 7.1 | — | 450-87556 | | 4.18.0-15-generic | 7.1 | — | 450-87556 | | 4.18.0-16-generic | 7.1 | — | 450-87556 | | 4.18.0-17-generic | 7.1 | — | 450-87556 | | 4.18.0-18-generic | 7.1 | — | 450-87556 | | 4.18.0-20-generic | 7.1 | — | 450-87556 | | 4.18.0-21-generic | 7.1 | — | 450-87556 | @@ -2081,8 +2082,9 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 18 \[x | 5.4.0-1162-azure | 7.1 | — | 2260-36267 | | 5.4.0-1162-gcp | 7.1 | — | 2260-36267 | | 5.4.0-1163-azure | 7.1 | — | 2270-36657 | | 5.4.0-1163-gcp | 7.1 | — | 2290-37208 | | 5.4.0-1164-azure | 7.1 | — | 2290-37208 | | 5.4.0-1164-gcp | 7.1 | — | 2390-39715 | | 5.4.0-1165-gcp | 7.1 | — | 2400-40648 | | 5.4.0-1166-azure | 7.1 | — | 2390-39715 | +| 5.4.0-1167-azure | 7.1 | — | 2410-40905 |
-
▸ ▾ Ubuntu 20 [x86_64] modified +2 −0
linux-kernels/ubuntuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -685,16 +685,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 20 \[x4.15.0-1196-azure│7.1│—│2140-309754.15.0-1196-azure│7.1│—│2140-309754.15.0-1197-azure│7.1│—│2210-339464.15.0-1197-azure│7.1│—│2210-339464.15.0-1199-azure│7.1│—│2220-345414.15.0-1199-azure│7.1│—│2220-345414.15.0-1200-azure│7.1│—│2250-358524.15.0-1200-azure│7.1│—│2250-358524.15.0-1201-azure│7.1│—│2270-366574.15.0-1201-azure│7.1│—│2270-366574.15.0-1202-azure│7.1│—│2290-372084.15.0-1202-azure│7.1│—│2290-372084.15.0-1204-azure│7.1│—│2340-387884.15.0-1204-azure│7.1│—│2340-387884.15.0-1205-azure│7.1│—│2390-403334.15.0-1205-azure│7.1│—│2390-403334.15.0-1206-azure│7.1│—│2410-409054.18.0-13-generic│7.1│—│450-875564.18.0-13-generic│7.1│—│450-875564.18.0-14-generic│7.1│—│450-875564.18.0-14-generic│7.1│—│450-875564.18.0-15-generic│7.1│—│450-875564.18.0-15-generic│7.1│—│450-875564.18.0-16-generic│7.1│—│450-875564.18.0-16-generic│7.1│—│450-875564.18.0-17-generic│7.1│—│450-875564.18.0-17-generic│7.1│—│450-875564.18.0-18-generic│7.1│—│450-875564.18.0-18-generic│7.1│—│450-875564.18.0-20-generic│7.1│—│450-875564.18.0-20-generic│7.1│—│450-875564.18.0-21-generic│7.1│—│450-875564.18.0-21-generic│7.1│—│450-87556@@ -1676,16 +1677,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 20 \[x5.4.0-1162-azure│7.1│—│2260-362675.4.0-1162-azure│7.1│—│2260-362675.4.0-1162-gcp│7.1│—│2260-362675.4.0-1162-gcp│7.1│—│2260-362675.4.0-1163-azure│7.1│—│2270-366575.4.0-1163-azure│7.1│—│2270-366575.4.0-1163-gcp│7.1│—│2290-372085.4.0-1163-gcp│7.1│—│2290-372085.4.0-1164-azure│7.1│—│2290-372085.4.0-1164-azure│7.1│—│2290-372085.4.0-1164-gcp│7.1│—│2390-397155.4.0-1164-gcp│7.1│—│2390-397155.4.0-1165-gcp│7.1│—│2400-406485.4.0-1165-gcp│7.1│—│2400-406485.4.0-1166-azure│7.1│—│2390-397155.4.0-1166-azure│7.1│—│2390-397155.4.0-1167-azure│7.1│—│2410-409055.8.0-23-generic│7.1│—│450-875565.8.0-23-generic│7.1│—│450-875565.8.0-25-generic│7.1│—│450-875565.8.0-25-generic│7.1│—│450-875565.8.0-28-generic│7.1│—│450-875565.8.0-28-generic│7.1│—│450-875565.8.0-29-generic│7.1│—│450-875565.8.0-29-generic│7.1│—│450-875565.8.0-31-generic│7.1│—│450-875565.8.0-31-generic│7.1│—│450-875565.8.0-33-generic│7.1│—│450-875565.8.0-33-generic│7.1│—│450-875565.8.0-34-generic│7.1│—│450-875565.8.0-34-generic│7.1│—│450-875565.8.0-36-generic│7.1│—│450-875565.8.0-36-generic│7.1│—│450-87556Show markdown source
@@ -685,16 +685,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 20 \[x | 4.15.0-1196-azure | 7.1 | — | 2140-30975 | | 4.15.0-1197-azure | 7.1 | — | 2210-33946 | | 4.15.0-1199-azure | 7.1 | — | 2220-34541 | | 4.15.0-1200-azure | 7.1 | — | 2250-35852 | | 4.15.0-1201-azure | 7.1 | — | 2270-36657 | | 4.15.0-1202-azure | 7.1 | — | 2290-37208 | | 4.15.0-1204-azure | 7.1 | — | 2340-38788 | | 4.15.0-1205-azure | 7.1 | — | 2390-40333 | +| 4.15.0-1206-azure | 7.1 | — | 2410-40905 | | 4.18.0-13-generic | 7.1 | — | 450-87556 | | 4.18.0-14-generic | 7.1 | — | 450-87556 | | 4.18.0-15-generic | 7.1 | — | 450-87556 | | 4.18.0-16-generic | 7.1 | — | 450-87556 | | 4.18.0-17-generic | 7.1 | — | 450-87556 | | 4.18.0-18-generic | 7.1 | — | 450-87556 | | 4.18.0-20-generic | 7.1 | — | 450-87556 | | 4.18.0-21-generic | 7.1 | — | 450-87556 | @@ -1676,16 +1677,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 20 \[x | 5.4.0-1162-azure | 7.1 | — | 2260-36267 | | 5.4.0-1162-gcp | 7.1 | — | 2260-36267 | | 5.4.0-1163-azure | 7.1 | — | 2270-36657 | | 5.4.0-1163-gcp | 7.1 | — | 2290-37208 | | 5.4.0-1164-azure | 7.1 | — | 2290-37208 | | 5.4.0-1164-gcp | 7.1 | — | 2390-39715 | | 5.4.0-1165-gcp | 7.1 | — | 2400-40648 | | 5.4.0-1166-azure | 7.1 | — | 2390-39715 | +| 5.4.0-1167-azure | 7.1 | — | 2410-40905 | | 5.8.0-23-generic | 7.1 | — | 450-87556 | | 5.8.0-25-generic | 7.1 | — | 450-87556 | | 5.8.0-28-generic | 7.1 | — | 450-87556 | | 5.8.0-29-generic | 7.1 | — | 450-87556 | | 5.8.0-31-generic | 7.1 | — | 450-87556 | | 5.8.0-33-generic | 7.1 | — | 450-87556 | | 5.8.0-34-generic | 7.1 | — | 450-87556 | | 5.8.0-36-generic | 7.1 | — | 450-87556 |
-
▸ ▾ Ubuntu 22 [x86_64] modified +4 −0
linux-kernels/ubuntuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -638,16 +638,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 22 \[x5.15.0-1109-aws│7.8│—│2290-372085.15.0-1109-aws│7.8│—│2290-372085.15.0-1109-azure│7.8│—│2220-342425.15.0-1109-azure│7.8│—│2220-342425.15.0-1109-gcp│7.8│—│2290-372085.15.0-1109-gcp│7.8│—│2290-372085.15.0-1109-ibm│8.3│—│2400-406485.15.0-1109-ibm│8.3│—│2400-406485.15.0-1109-oracle│8.3│—│2390-397155.15.0-1109-oracle│8.3│—│2390-397155.15.0-1110-aws│7.8│—│2310-377965.15.0-1110-aws│7.8│—│2310-377965.15.0-1110-azure│7.8│—│2220-342425.15.0-1110-azure│7.8│—│2220-342425.15.0-1110-gcp│7.8│—│2290-372085.15.0-1110-gcp│7.8│—│2290-372085.15.0-1110-gke│7.8│—│2410-409055.15.0-1110-oracle│8.3│—│2390-403335.15.0-1110-oracle│8.3│—│2390-403335.15.0-1111-aws│7.8│—│2320-381245.15.0-1111-aws│7.8│—│2320-381245.15.0-1111-azure│7.8│—│2250-358525.15.0-1111-azure│7.8│—│2250-358525.15.0-1111-gcp│7.8│—│2330-383855.15.0-1111-gcp│7.8│—│2330-383855.15.0-1111-gke│7.8│—│2400-406485.15.0-1111-gke│7.8│—│2400-406485.15.0-1111-oracle│8.3│—│2400-406485.15.0-1111-oracle│8.3│—│2400-406485.15.0-1112-aws│7.8│—│2330-383855.15.0-1112-aws│7.8│—│2330-383855.15.0-1112-azure│7.8│—│2230-347895.15.0-1112-azure│7.8│—│2230-34789@@ -1092,25 +1093,28 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 22 \[x6.8.0-1058-ibm│8.3│—│2290-372086.8.0-1058-ibm│8.3│—│2290-372086.8.0-1058-oracle│8.3│—│2390-397156.8.0-1058-oracle│8.3│—│2390-397156.8.0-1059-azure│7.8│—│2300-375236.8.0-1059-azure│7.8│—│2300-375236.8.0-1059-oracle│8.3│—│2400-406486.8.0-1059-oracle│8.3│—│2400-406486.8.0-1060-aws│7.8│—│2330-383856.8.0-1060-aws│7.8│—│2330-383856.8.0-1060-azure│7.8│—│2310-377966.8.0-1060-azure│7.8│—│2310-377966.8.0-1060-gcp│7.8│—│2280-368946.8.0-1060-gcp│7.8│—│2280-368946.8.0-1060-ibm│8.3│—│2330-383856.8.0-1060-ibm│8.3│—│2330-383856.8.0-1060-oracle│8.3│—│2410-409056.8.0-1061-aws│7.8│—│2390-397156.8.0-1061-aws│7.8│—│2390-397156.8.0-1061-gcp│7.8│—│2310-377966.8.0-1061-gcp│7.8│—│2310-377966.8.0-1061-ibm│8.3│—│2390-397156.8.0-1061-ibm│8.3│—│2390-397156.8.0-1061-oracle│8.3│—│2400-406486.8.0-1061-oracle│8.3│—│2400-406486.8.0-1062-aws│7.8│—│2400-406486.8.0-1062-aws│7.8│—│2400-406486.8.0-1062-azure│7.8│—│2340-387886.8.0-1062-azure│7.8│—│2340-387886.8.0-1062-ibm│8.3│—│2380-400686.8.0-1062-ibm│8.3│—│2380-400686.8.0-1063-aws│7.8│—│2400-406486.8.0-1063-aws│7.8│—│2400-406486.8.0-1063-azure│7.8│—│2390-397156.8.0-1063-azure│7.8│—│2390-397156.8.0-1063-gcp│7.8│—│2330-383856.8.0-1063-gcp│7.8│—│2330-383856.8.0-1063-ibm│8.3│—│2410-409056.8.0-1064-aws│7.8│—│2400-406486.8.0-1064-aws│7.8│—│2400-406486.8.0-1064-azure│7.8│—│2380-400686.8.0-1064-azure│7.8│—│2380-400686.8.0-1064-gcp│7.8│—│2390-397156.8.0-1064-gcp│7.8│—│2390-397156.8.0-1065-azure│7.8│—│2410-409056.8.0-1065-gcp│7.8│—│2380-400686.8.0-1065-gcp│7.8│—│2380-400686.8.0-1066-gcp│7.8│—│2400-406486.8.0-1066-gcp│7.8│—│2400-406486.8.0-1067-azure│7.8│—│2400-406486.8.0-1067-azure│7.8│—│2400-406486.8.0-1067-gcp│7.8│—│2390-403336.8.0-1067-gcp│7.8│—│2390-40333Show markdown source
@@ -638,16 +638,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 22 \[x | 5.15.0-1109-aws | 7.8 | — | 2290-37208 | | 5.15.0-1109-azure | 7.8 | — | 2220-34242 | | 5.15.0-1109-gcp | 7.8 | — | 2290-37208 | | 5.15.0-1109-ibm | 8.3 | — | 2400-40648 | | 5.15.0-1109-oracle | 8.3 | — | 2390-39715 | | 5.15.0-1110-aws | 7.8 | — | 2310-37796 | | 5.15.0-1110-azure | 7.8 | — | 2220-34242 | | 5.15.0-1110-gcp | 7.8 | — | 2290-37208 | +| 5.15.0-1110-gke | 7.8 | — | 2410-40905 | | 5.15.0-1110-oracle | 8.3 | — | 2390-40333 | | 5.15.0-1111-aws | 7.8 | — | 2320-38124 | | 5.15.0-1111-azure | 7.8 | — | 2250-35852 | | 5.15.0-1111-gcp | 7.8 | — | 2330-38385 | | 5.15.0-1111-gke | 7.8 | — | 2400-40648 | | 5.15.0-1111-oracle | 8.3 | — | 2400-40648 | | 5.15.0-1112-aws | 7.8 | — | 2330-38385 | | 5.15.0-1112-azure | 7.8 | — | 2230-34789 | @@ -1092,25 +1093,28 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 22 \[x | 6.8.0-1058-ibm | 8.3 | — | 2290-37208 | | 6.8.0-1058-oracle | 8.3 | — | 2390-39715 | | 6.8.0-1059-azure | 7.8 | — | 2300-37523 | | 6.8.0-1059-oracle | 8.3 | — | 2400-40648 | | 6.8.0-1060-aws | 7.8 | — | 2330-38385 | | 6.8.0-1060-azure | 7.8 | — | 2310-37796 | | 6.8.0-1060-gcp | 7.8 | — | 2280-36894 | | 6.8.0-1060-ibm | 8.3 | — | 2330-38385 | +| 6.8.0-1060-oracle | 8.3 | — | 2410-40905 | | 6.8.0-1061-aws | 7.8 | — | 2390-39715 | | 6.8.0-1061-gcp | 7.8 | — | 2310-37796 | | 6.8.0-1061-ibm | 8.3 | — | 2390-39715 | | 6.8.0-1061-oracle | 8.3 | — | 2400-40648 | | 6.8.0-1062-aws | 7.8 | — | 2400-40648 | | 6.8.0-1062-azure | 7.8 | — | 2340-38788 | | 6.8.0-1062-ibm | 8.3 | — | 2380-40068 | | 6.8.0-1063-aws | 7.8 | — | 2400-40648 | | 6.8.0-1063-azure | 7.8 | — | 2390-39715 | | 6.8.0-1063-gcp | 7.8 | — | 2330-38385 | +| 6.8.0-1063-ibm | 8.3 | — | 2410-40905 | | 6.8.0-1064-aws | 7.8 | — | 2400-40648 | | 6.8.0-1064-azure | 7.8 | — | 2380-40068 | | 6.8.0-1064-gcp | 7.8 | — | 2390-39715 | +| 6.8.0-1065-azure | 7.8 | — | 2410-40905 | | 6.8.0-1065-gcp | 7.8 | — | 2380-40068 | | 6.8.0-1066-gcp | 7.8 | — | 2400-40648 | | 6.8.0-1067-azure | 7.8 | — | 2400-40648 | | 6.8.0-1067-gcp | 7.8 | — | 2390-40333 |
-
▸ ▾ Ubuntu 24 [x86_64] modified +1 −0
linux-kernels/ubuntuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -311,16 +311,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 24 \[x6.8.0-1061-gke│8.3.100│—│2400-406486.8.0-1061-gke│8.3.100│—│2400-406486.8.0-1061-ibm│8.3.100│—│2390-397156.8.0-1061-ibm│8.3.100│—│2390-397156.8.0-1062-aws│8.3.100│—│2380-400686.8.0-1062-aws│8.3.100│—│2380-400686.8.0-1062-azure│8.3.100│—│2340-387886.8.0-1062-azure│8.3.100│—│2340-387886.8.0-1062-ibm│8.3.100│—│2380-400686.8.0-1062-ibm│8.3.100│—│2380-400686.8.0-1063-aws│8.3.100│—│2400-406486.8.0-1063-aws│8.3.100│—│2400-406486.8.0-1063-azure│8.3.100│—│2390-397156.8.0-1063-azure│8.3.100│—│2390-397156.8.0-1063-gcp│8.3.100│—│2330-383856.8.0-1063-gcp│8.3.100│—│2330-383856.8.0-1063-ibm│8.3.100│—│2410-409056.8.0-1064-azure│8.3.100│—│2380-400686.8.0-1064-azure│8.3.100│—│2380-400686.8.0-1064-gcp│8.3.100│—│2390-397156.8.0-1064-gcp│8.3.100│—│2390-397156.8.0-1065-azure│8.3.100│—│2400-406486.8.0-1065-azure│8.3.100│—│2400-406486.8.0-1065-gcp│8.3.100│—│2380-400686.8.0-1065-gcp│8.3.100│—│2380-400686.8.0-1066-gcp│8.3.100│—│2400-406486.8.0-1066-gcp│8.3.100│—│2400-406486.11.0-17-generic│8.3.100│—│1830-182496.11.0-17-generic│8.3.100│—│1830-182496.11.0-19-generic│8.3.100│—│1830-182496.11.0-19-generic│8.3.100│—│1830-182496.11.0-21-generic│8.3.100│—│1830-182496.11.0-21-generic│8.3.100│—│1830-18249Show markdown source
@@ -311,16 +311,17 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 24 \[x | 6.8.0-1061-gke | 8.3.100 | — | 2400-40648 | | 6.8.0-1061-ibm | 8.3.100 | — | 2390-39715 | | 6.8.0-1062-aws | 8.3.100 | — | 2380-40068 | | 6.8.0-1062-azure | 8.3.100 | — | 2340-38788 | | 6.8.0-1062-ibm | 8.3.100 | — | 2380-40068 | | 6.8.0-1063-aws | 8.3.100 | — | 2400-40648 | | 6.8.0-1063-azure | 8.3.100 | — | 2390-39715 | | 6.8.0-1063-gcp | 8.3.100 | — | 2330-38385 | +| 6.8.0-1063-ibm | 8.3.100 | — | 2410-40905 | | 6.8.0-1064-azure | 8.3.100 | — | 2380-40068 | | 6.8.0-1064-gcp | 8.3.100 | — | 2390-39715 | | 6.8.0-1065-azure | 8.3.100 | — | 2400-40648 | | 6.8.0-1065-gcp | 8.3.100 | — | 2380-40068 | | 6.8.0-1066-gcp | 8.3.100 | — | 2400-40648 | | 6.11.0-17-generic | 8.3.100 | — | 1830-18249 | | 6.11.0-19-generic | 8.3.100 | — | 1830-18249 | | 6.11.0-21-generic | 8.3.100 | — | 1830-18249 |
-
▸ ▾ Ubuntu 26 [x86_64] modified +1 −0
linux-kernels/ubuntuRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -32,13 +32,14 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 26 \[x7.0.0-1009-aws│9.1.0│—│2390-403337.0.0-1009-aws│9.1.0│—│2390-403337.0.0-1009-azure│9.1.0│—│2390-403337.0.0-1009-azure│9.1.0│—│2390-403337.0.0-1009-ibm│9.1.0│—│2390-403337.0.0-1009-ibm│9.1.0│—│2390-403337.0.0-1009-oracle│9.1.0│—│2390-403337.0.0-1009-oracle│9.1.0│—│2390-403337.0.0-1010-aws│9.1.0│—│2390-403337.0.0-1010-aws│9.1.0│—│2390-403337.0.0-1010-azure│9.1.0│—│2390-403337.0.0-1010-azure│9.1.0│—│2390-403337.0.0-1010-gcp│9.1.0│—│2400-406487.0.0-1010-gcp│9.1.0│—│2400-406487.0.0-1010-ibm│9.1.0│—│2390-403337.0.0-1010-ibm│9.1.0│—│2390-403337.0.0-1010-oracle│9.1.0│—│2410-409057.0.0-1011-aws│9.1.0│—│2400-406487.0.0-1011-aws│9.1.0│—│2400-406487.0.0-1011-azure│9.1.0│—│2390-403337.0.0-1011-azure│9.1.0│—│2390-403337.0.0-1011-ibm│9.1.0│—│2390-403337.0.0-1011-ibm│9.1.0│—│2390-403337.0.0-1012-azure│9.1.0│—│2400-406487.0.0-1012-azure│9.1.0│—│2400-406487.0.0-1012-ibm│9.1.0│—│2400-406487.0.0-1012-ibm│9.1.0│—│2400-40648Show markdown source
@@ -32,13 +32,14 @@ Cortex XDR agent supports the following kernel module versions for Ubuntu 26 \[x | 7.0.0-1009-aws | 9.1.0 | — | 2390-40333 | | 7.0.0-1009-azure | 9.1.0 | — | 2390-40333 | | 7.0.0-1009-ibm | 9.1.0 | — | 2390-40333 | | 7.0.0-1009-oracle | 9.1.0 | — | 2390-40333 | | 7.0.0-1010-aws | 9.1.0 | — | 2390-40333 | | 7.0.0-1010-azure | 9.1.0 | — | 2390-40333 | | 7.0.0-1010-gcp | 9.1.0 | — | 2400-40648 | | 7.0.0-1010-ibm | 9.1.0 | — | 2390-40333 | +| 7.0.0-1010-oracle | 9.1.0 | — | 2410-40905 | | 7.0.0-1011-aws | 9.1.0 | — | 2400-40648 | | 7.0.0-1011-azure | 9.1.0 | — | 2390-40333 | | 7.0.0-1011-ibm | 9.1.0 | — | 2390-40333 | | 7.0.0-1012-azure | 9.1.0 | — | 2400-40648 | | 7.0.0-1012-ibm | 9.1.0 | — | 2400-40648 |
-
▸ ▾ Manage instances modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instancesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Manage data source and integration instances in Cortex XSIAM.description: Manage data source and connector instances in Cortex XSIAM.------# Manage instances# Manage instancesIn Cortex XSIAM, you can manage the instances configured for a data source on the Data Sources & Integrations page. You can edit, delete, enable, or disable instances, and refresh log data.In Cortex XSIAM, you can manage the instances configured for a data source on the Data Sources & Integrations page. You can edit, delete, enable, or disable instances, and refresh log data.1. Navigate to Settings → Data Sources & Integrations.1. Navigate to Settings → Data Sources & Integrations.2. Find an integration by clicking on a data source name in the table or filtering for it, then select the data source.2. Find an integration by clicking on a data source name in the table or filtering for it, then select the data source.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Manage data source and integration instances in Cortex XSIAM. +description: Manage data source and connector instances in Cortex XSIAM. --- # Manage instances In Cortex XSIAM, you can manage the instances configured for a data source on the **Data Sources & Integrations** page. You can edit, delete, enable, or disable instances, and refresh log data. 1. Navigate to Settings → Data Sources & Integrations. 2. Find an integration by clicking on a data source name in the table or filtering for it, then select the data source.
-
▸ ▾ Add a new data source or instance modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/administration-and-troubleshooting/manage-instances/add-a-new-data-source-or-instanceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Add a data source or integration instance in Cortex XSIAM.description: Add a data source or connector instance in Cortex XSIAM.------# Add a new data source or instance# Add a new data source or instanceYou can add a new data source with the Data Source Onboarder. The Onboarder installs the data source, sets up an instance, configures playbooks and scripts, and other recommended content. The Onboarder offers default (customizable) options and displays all configured content in a summary screen at the end of the process.You can add a new data source with the Data Source Onboarder. The Onboarder installs the data source, sets up an instance, configures playbooks and scripts, and other recommended content. The Onboarder offers default (customizable) options and displays all configured content in a summary screen at the end of the process.1. Navigate to the Settings → Data Sources & Integrations page.1. Navigate to the Settings → Data Sources & Integrations page.2. Select one of the following options:2. Select one of the following options:Show markdown source
@@ -1,10 +1,10 @@ --- -description: Add a data source or integration instance in Cortex XSIAM. +description: Add a data source or connector instance in Cortex XSIAM. --- # Add a new data source or instance You can add a new data source with the Data Source Onboarder. The Onboarder installs the data source, sets up an instance, configures playbooks and scripts, and other recommended content. The Onboarder offers default (customizable) options and displays all configured content in a summary screen at the end of the process. 1. Navigate to the Settings → Data Sources & Integrations page. 2. Select one of the following options:
-
▸ ▾ Cloud Posture and Runtime Security data sources modified +97 −3 The supported list grows from 9 entries to roughly 100 and is retitled "data sources and connectors".
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sourcesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -15,19 +15,113 @@ Cloud Posture Management and Cloud Runtime Security have their own data sourcesRelevant Cloud Posture and Runtime data source types:Relevant Cloud Posture and Runtime data source types:• Container Registry connectors: A Runtime data source category that integrates with supported container registries like Amazon ECR, Docker Hub, and JFrog to automatically scan container images for vulnerabilities and other security risks.• Container Registry connectors: A Runtime data source category that integrates with supported container registries like Amazon ECR, Docker Hub, and JFrog to automatically scan container images for vulnerabilities and other security risks.• Posture management connectors: Provides specialized onboarding to identify misconfigurations in SaaS and data platforms like Snowflake and Microsoft 365 (Posture).• Posture management connectors: Provides specialized onboarding to identify misconfigurations in SaaS and data platforms like Snowflake and Microsoft 365 (Posture).• Discovery engine: Performs regular scans and uses Event Assisted Ingestion (EAI) to track near-real-time changes to cloud assets and VMs.• Discovery engine: Performs regular scans and uses Event Assisted Ingestion (EAI) to track near-real-time changes to cloud assets and VMs.• Serverless function security: Provides agentless scanning for vulnerabilities in serverless code and pipelines for AWS Lambda, GCP, and Azure functions.• Serverless function security: Provides agentless scanning for vulnerabilities in serverless code and pipelines for AWS Lambda, GCP, and Azure functions.• Cloud data security (DSPM): Discovers and classifies sensitive data across managed storage, such as S3 and Cloud SQL, and self-managed databases.• Cloud data security (DSPM): Discovers and classifies sensitive data across managed storage, such as S3 and Cloud SQL, and self-managed databases.The following Cloud Posture and Runtime Security data sources are supported:The following Cloud Posture and Runtime Security data sources and connectors are supported:• AbuseIPDB• Aha!• AIOps• Anomali• Apollo.io• AppSec Transporter applet• AppSec Transporter applet• Articulate Global• Asana• Atlassian• Automox• Azure Log Analytics• Azure Services• Box• Businessmap• Celonis• ChatGPT Enterprise• Cisco Duo• Cisco Meraki• Claude• ClickUp• Contentful• Coveo• Cribl• Cursor• CyberArk• Databricks• Databricks• DataDog• Docker Hub registry• Docker V2-compliant registry• DSPM Database applet• DSPM Database applet• DSPM Fileshare applet• DSPM Fileshare applet• Microsoft 365• ElasticSearch• Okta• Forcepoint• Gainsight• Gemini Enterprise• Generic MCP• Generic SQL• GitHub• GitLab container registry• GitLab• Google Workspace connector• Google Workspace Automation and Collection• Harbor registry• Harness• IBM QRadar• Intercom• iZOOlogic• Jamf Pro• JFrog container registry• JumpCloud• Koi• Kubernetes• Kustomer• LastPass• Mail Utilities• Microsoft 365 (new)• Microsoft365 (legacy)• Microsoft 365 (Posture)• Microsoft 365 Copilot• Microsoft Active Directory• Microsoft Copilot Studio• Microsoft Entra ID• Microsoft Graph• Microsoft Identity• Microsoft Security Automation and Collection• Microsoft Teams• M365 Automation and Collection• Monday• Monday.com• MongoDB Atlas• MongoDB Atlas (Posture)• MuleSoft• Mural• Nintex Workflow Cloud• Okta• Oracle• PagerDuty• Ping Identity• Pipedrive• Qualtrics• Redis Labs• Registry Scanner applet• Registry Scanner applet• Salesforce• SAP Ariba• Sentry• ServiceNow automation and collection• ServiceNow• Shopify• Slack• SMB• Snowflake• Snowflake• Sonatype Nexus registry• Splunk• Sumo Logic• Terraform• VMware• Workday Automation and Collection• Workday• YouTrack• Zendesk• Zscaler• AppSec Transporter• AppSec TransporterShow markdown source
@@ -15,19 +15,113 @@ Cloud Posture Management and Cloud Runtime Security have their own data sources **Relevant Cloud Posture and Runtime data source types:** * **Container Registry connectors**: A Runtime data source category that integrates with supported container registries like Amazon ECR, Docker Hub, and JFrog to automatically scan container images for vulnerabilities and other security risks. * **Posture management connectors**: Provides specialized onboarding to identify misconfigurations in SaaS and data platforms like Snowflake and Microsoft 365 (Posture). * **Discovery engine**: Performs regular scans and uses Event Assisted Ingestion (EAI) to track near-real-time changes to cloud assets and VMs. * **Serverless function security**: Provides agentless scanning for vulnerabilities in serverless code and pipelines for AWS Lambda, GCP, and Azure functions. * **Cloud data security (DSPM)**: Discovers and classifies sensitive data across managed storage, such as S3 and Cloud SQL, and self-managed databases. -The following Cloud Posture and Runtime Security data sources are supported: +The following Cloud Posture and Runtime Security data sources and connectors are supported: +* [AbuseIPDB](vendor-specific-data-sources-and-connectors/abuseipdb/abuseipdb) +* [Aha!](vendor-specific-data-sources-and-connectors/aha/aha) +* [AIOps](vendor-specific-data-sources-and-connectors/aiops/aiops) +* [Anomali](vendor-specific-data-sources-and-connectors/anomali/anomali) +* [Apollo.io](vendor-specific-data-sources-and-connectors/apollo.io/apollo.io) * [AppSec Transporter applet](generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporter) +* [Articulate Global](vendor-specific-data-sources-and-connectors/articulate-global/articulate-global) +* [Asana](vendor-specific-data-sources-and-connectors/asana/asana) +* [Atlassian](vendor-specific-data-sources-and-connectors/atlassian) +* [Automox](vendor-specific-data-sources-and-connectors/automox/automox) +* [Azure Log Analytics](vendor-specific-data-sources-and-connectors/microsoft/azure-log-analytics) +* [Azure Services](vendor-specific-data-sources-and-connectors/microsoft/azure-services) +* [Box](vendor-specific-data-sources-and-connectors/box/box) +* [Businessmap](vendor-specific-data-sources-and-connectors/businessmap/businessmap) +* [Celonis](vendor-specific-data-sources-and-connectors/celonis/celonis) +* [ChatGPT Enterprise](vendor-specific-data-sources-and-connectors/chatgpt-enterprise/chatgpt-enterprise) +* [Cisco Duo](vendor-specific-data-sources-and-connectors/cisco/cisco-duo) +* [Cisco Meraki](vendor-specific-data-sources-and-connectors/cisco/cisco-meraki) +* [Claude](vendor-specific-data-sources-and-connectors/anthropic/claude) +* [ClickUp](vendor-specific-data-sources-and-connectors/clickup/clickup) +* [Contentful](vendor-specific-data-sources-and-connectors/contentful/contentful) +* [Coveo](vendor-specific-data-sources-and-connectors/coveo/coveo) +* [Cribl](vendor-specific-data-sources-and-connectors/cribl/cribl-connector) +* [Cursor](vendor-specific-data-sources-and-connectors/cursor/cursor) +* [CyberArk](vendor-specific-data-sources-and-connectors/cyberark/cyberark) * [Databricks](vendor-specific-data-sources-and-connectors/databricks/how-to-onboard-databricks) +* [DataDog](vendor-specific-data-sources-and-connectors/datadog/datadog) +* [Docker Hub registry](vendor-specific-data-sources-and-connectors/docker/connect-docker-hub-registry) +* [Docker V2-compliant registry](vendor-specific-data-sources-and-connectors/docker/connect-docker-hub-registry) * [DSPM Database applet](generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-database) * [DSPM Fileshare applet](generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-database) -* [Microsoft 365](vendor-specific-data-sources-and-connectors/microsoft/microsoft-365-posture/how-to-onboard-microsoft-365) -* [Okta](vendor-specific-data-sources-and-connectors/okta/ingest-logs-and-data-from-okta) +* [ElasticSearch](vendor-specific-data-sources-and-connectors/elastic/elasticsearch) +* [Forcepoint](vendor-specific-data-sources-and-connectors/forcepoint/forcepoint) +* [Gainsight](vendor-specific-data-sources-and-connectors/gainsight/gainsight) +* [Gemini Enterprise](vendor-specific-data-sources-and-connectors/gemini-enterprise/gemini-enterprise) +* [Generic MCP](vendor-specific-data-sources-and-connectors/generic/generic-mcp) +* [Generic SQL](vendor-specific-data-sources-and-connectors/generic/generic-sql) +* [GitHub](vendor-specific-data-sources-and-connectors/github/github) +* [GitLab container registry](vendor-specific-data-sources-and-connectors/gitlab/connect-gitlab-container-registry) +* [GitLab](vendor-specific-data-sources-and-connectors/gitlab/gitlab) +* [Google Workspace connector](vendor-specific-data-sources-and-connectors/google/google-workspace/google-workspace-connector) +* [Google Workspace Automation and Collection](vendor-specific-data-sources-and-connectors/google/google-workspace/google-workspace-automation-and-collection) +* [Harbor registry](vendor-specific-data-sources-and-connectors/harbor/connect-harbor-registry) +* [Harness](vendor-specific-data-sources-and-connectors/harness/harness) +* [IBM QRadar](vendor-specific-data-sources-and-connectors/ibm/ibm-qradar) +* [Intercom](vendor-specific-data-sources-and-connectors/intercom/intercom) +* [iZOOlogic](vendor-specific-data-sources-and-connectors/izoologic/izoologic) +* [Jamf Pro](vendor-specific-data-sources-and-connectors/jamf/jamf-pro) +* [JFrog container registry](vendor-specific-data-sources-and-connectors/jfrog/connect-jfrog-container-registry) +* [JumpCloud](vendor-specific-data-sources-and-connectors/jumpcloud/jumpcloud) +* [Koi](vendor-specific-data-sources-and-connectors/koi/koi) +* [Kubernetes](vendor-specific-data-sources-and-connectors/kubernetes) +* [Kustomer](vendor-specific-data-sources-and-connectors/kustomer/kustomer) +* [LastPass](vendor-specific-data-sources-and-connectors/lastpass/lastpass) +* [Mail Utilities](vendor-specific-data-sources-and-connectors/mail-utilities/mail-utilities) +* [Microsoft 365 (new)](vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-365-new) +* [Microsoft365 (legacy)](vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft365-legacy) +* [Microsoft 365 (Posture)](vendor-specific-data-sources-and-connectors/microsoft/microsoft-365-posture/how-to-onboard-microsoft-365) +* [Microsoft 365 Copilot](vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-365-copilot) +* [Microsoft Active Directory](vendor-specific-data-sources-and-connectors/microsoft/microsoft-active-directory) +* [Microsoft Copilot Studio](vendor-specific-data-sources-and-connectors/microsoft/microsoft-copilot-studio) +* [Microsoft Entra ID](vendor-specific-data-sources-and-connectors/microsoft/microsoft-entra-id) +* [Microsoft Graph](vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-graph) +* [Microsoft Identity](vendor-specific-data-sources-and-connectors/microsoft/microsoft-identity) +* [Microsoft Security Automation and Collection](vendor-specific-data-sources-and-connectors/microsoft/microsoft-security-automation-and-collection) +* [Microsoft Teams](vendor-specific-data-sources-and-connectors/microsoft/microsoft-teams) +* [M365 Automation and Collection](vendor-specific-data-sources-and-connectors/microsoft/m365-automation-and-collection) +* [Monday](vendor-specific-data-sources-and-connectors/monday/monday) +* [Monday.com](vendor-specific-data-sources-and-connectors/monday/monday.com) +* [MongoDB Atlas](vendor-specific-data-sources-and-connectors/mongodb/mongodb-atlas) +* [MongoDB Atlas (Posture)](vendor-specific-data-sources-and-connectors/mongodb/how-to-onboard-mongodb-atlas) +* [MuleSoft](vendor-specific-data-sources-and-connectors/mulesoft/mulesoft) +* [Mural](vendor-specific-data-sources-and-connectors/mural/mural) +* [Nintex Workflow Cloud](vendor-specific-data-sources-and-connectors/nintex-workflow-cloud/nintex-workflow-cloud) +* [Okta](vendor-specific-data-sources-and-connectors/okta) +* [Oracle](vendor-specific-data-sources-and-connectors/oracle/oracle) +* [PagerDuty](vendor-specific-data-sources-and-connectors/pagerduty) +* [Ping Identity](vendor-specific-data-sources-and-connectors/ping-identity/pingone/ping-identity) +* [Pipedrive](vendor-specific-data-sources-and-connectors/pipedrive) +* [Qualtrics](vendor-specific-data-sources-and-connectors/qualtrics/qualtrics) +* [Redis Labs](vendor-specific-data-sources-and-connectors/redis-labs/redis-labs) * [Registry Scanner applet](generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-registry-scanner) +* [Salesforce](vendor-specific-data-sources-and-connectors/salesforce) +* [SAP Ariba](vendor-specific-data-sources-and-connectors/sap/sap-ariba) +* [Sentry](vendor-specific-data-sources-and-connectors/sentry/sentry) +* [ServiceNow automation and collection](vendor-specific-data-sources-and-connectors/servicenow/servicenow-automation-and-collection) +* [ServiceNow](vendor-specific-data-sources-and-connectors/servicenow/servicenow) +* [Shopify](vendor-specific-data-sources-and-connectors/shopify/shopify) +* [Slack](vendor-specific-data-sources-and-connectors/slack) +* [SMB](vendor-specific-data-sources-and-connectors/smb/smb) * [Snowflake](vendor-specific-data-sources-and-connectors/snowflake/how-to-onboard-snowflake) +* [Sonatype Nexus registry](vendor-specific-data-sources-and-connectors/sonatype-nexus/connect-sonatype-nexus-registry) +* [Splunk](vendor-specific-data-sources-and-connectors/splunk) +* [Sumo Logic](vendor-specific-data-sources-and-connectors/sumo-logic/sumo-logic) +* [Terraform](vendor-specific-data-sources-and-connectors/terraform/terraform) +* [VMware](vendor-specific-data-sources-and-connectors/vmware/vmware) +* [Workday Automation and Collection](vendor-specific-data-sources-and-connectors/workday/workday-automation-and-collection) +* [Workday](vendor-specific-data-sources-and-connectors/workday/workday) +* [YouTrack](vendor-specific-data-sources-and-connectors/youtrack/youtrack) +* [Zendesk](vendor-specific-data-sources-and-connectors/zendesk/zendesk) +* [Zscaler](vendor-specific-data-sources-and-connectors/zscaler/zscaler) * [AppSec Transporter](generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporter) +
-
▸ ▾ How to onboard Microsoft Azure modified +5 −2 Warns that scanning private serverless functions requires downloading and re-running the Terraform template to apply the extra permissions.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/microsoft-azure-cloud-onboarding/how-to-onboard-microsoft-azureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -73,18 +73,21 @@ Cortex XSIAM performs a live verification of each tenant's approval status again• Instance Name: Enter a unique instance name or leave it empty to be automatically populated. The automatic naming convention isAzure-<tenantID>orAzure-<subscriptionID>. Cortex XSIAM does not prevent you from reusing instance names, but it is best practice to use a unique name for every cloud instance.• Instance Name: Enter a unique instance name or leave it empty to be automatically populated. The automatic naming convention isAzure-<tenantID>orAzure-<subscriptionID>. Cortex XSIAM does not prevent you from reusing instance names, but it is best practice to use a unique name for every cloud instance.• Deployment Method: Select whether you want to onboard with a Cortex-generated IaC template or to perform a manual deployment:• Deployment Method: Select whether you want to onboard with a Cortex-generated IaC template or to perform a manual deployment:• Infrastructure as Code: (Recommended) Automatically provisions all required cloud resources and permissions using an IaC template.• Infrastructure as Code: (Recommended) Automatically provisions all required cloud resources and permissions using an IaC template.• Manual: Select this option if your organization requires manual provisioning to meet internal security and compliance policies. If you choose to onboard manually, follow the manual onboarding instructions.• Manual: Select this option if your organization requires manual provisioning to meet internal security and compliance policies. If you choose to onboard manually, follow the manual onboarding instructions.• Scope Modifications: Use these settings to fine-tune your Microsoft Azure scope. You can modify the scope by including or excluding specific regions. If you selected a Government environment, only Microsoft Azure Government regions are displayed. Additionally, if you selected a tenant or management group as the scope, you can modify the scope by including or excluding specific management groups or subscriptions. For more details, see Apply region or account filters. Scope modifications are not available when you are onboarding Microsoft Entra ID only.• Scope Modifications: Use these settings to fine-tune your Microsoft Azure scope. You can modify the scope by including or excluding specific regions. If you selected a Government environment, only Microsoft Azure Government regions are displayed. Additionally, if you selected a tenant or management group as the scope, you can modify the scope by including or excluding specific management groups or subscriptions. For more details, see Apply region or account filters. Scope modifications are not available when you are onboarding Microsoft Entra ID only.• Additional Security Capabilities: Choose which security capabilities you want to benefit from. Some security capabilities are enabled by default and can be modified. Adding security capability typically requires additional cloud provider permissions. For detailed information on the permissions required, see Cloud service provider permissions. When you are onboarding Microsoft Entra ID only, only XSIAM analytics is supported as an additional security capability.• Additional Security Capabilities: Choose which security capabilities you want to benefit from. Some security capabilities are enabled by default and can be modified. Adding security capability typically requires additional cloud provider permissions. For detailed information on the permissions required, see Cloud service provider permissions. When you are onboarding Microsoft Entra ID only, only XSIAM analytics is supported as an additional security capability.• Data security posture management: An agentless data security scanner that discovers, classifies, protects, and governs sensitive data. DSPM is not currently available in Microsoft Azure Government environments.• Data security posture management: An agentless data security scanner that discovers, classifies, protects, and governs sensitive data. DSPM is not currently available in Microsoft Azure Government environments.• Registry scanning: A container registry scanner that scans registry images for vulnerabilities, malware, and secrets. For more details, see Configure registry scanning for cloud accounts.• Registry scanning: A container registry scanner that scans registry images for vulnerabilities, malware, and secrets. For more details, see Configure registry scanning for cloud accounts.• Serverless functions scanning: Implement serverless scanning to detect and remediate vulnerabilities within serverless functions during the development lifecycle. Seamless integration into CI/CD pipelines enables automated security scans for a continuously secure pre-production environment.• Serverless functions scanning: Implement serverless scanning to detect and remediate vulnerabilities within serverless functions during the development lifecycle. Seamless integration into CI/CD pipelines enables automated security scans for a continuously secure pre-production environment.• Allow connection to private serverless functions: (Optional - only available with outpost scan) When serverless scanning runs from the outpost environment, it uses a dynamic IP address. Azure Functions with IP-based network restrictions will block the scanner. Enabling this option assigns a fixed IP address that can be whitelisted.• Allow connection to private serverless functions: (Optional - only available with outpost scan) When serverless scanning runs from the outpost environment, it uses a dynamic IP address. Azure Functions with IP-based network restrictions will block the scanner. Enabling this option assigns a fixed IP address that can be whitelisted.<div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Enabling this feature requires additional permissions. Download and run the Terraform template again to apply the permissions required to scan private serverless resources. Private serverless resources are resources that are accessible only through private networks and aren’t publicly accessible.</p></div>• Automation: Use automation to pre-configure a list of integrations and associated commands to automate security issue responses. Commands can be utilized individually or as part of custom playbooks for issue remediation.• Automation: Use automation to pre-configure a list of integrations and associated commands to automate security issue responses. Commands can be utilized individually or as part of custom playbooks for issue remediation.• Log Level: (Optional - for Automation only) Configure the automation integration logging level. Possible values are:• Log Level: (Optional - for Automation only) Configure the automation integration logging level. Possible values are:• Off (Default)• Off (Default)• Debug• Debug• Verbose• Verbose• Agentless disk scanning: (Recommended) Implement agentless disk scanning to remotely detect and remediate vulnerabilities during the development lifecycle.• Agentless disk scanning: (Recommended) Implement agentless disk scanning to remotely detect and remediate vulnerabilities during the development lifecycle.• Cloud Tags: Define tags and tag values to be added to any new resource created by Cortex XSIAM in Microsoft Azure. Note: Themanaged_by = paloaltonetworkstag is automatically added to all resources. This tag is mandatory. You cannot edit or remove this tag.• Cloud Tags: Define tags and tag values to be added to any new resource created by Cortex XSIAM in Microsoft Azure. Note: Themanaged_by = paloaltonetworkstag is automatically added to all resources. This tag is mandatory. You cannot edit or remove this tag.• Log Collection Configuration: To maximize security coverage, include the collection of audit logs using Event Hub. Select the collection method:• Log Collection Configuration: To maximize security coverage, include the collection of audit logs using Event Hub. Select the collection method:Show markdown source
@@ -73,18 +73,21 @@ Cortex XSIAM performs a live verification of each tenant's approval status again * **Instance Name:** Enter a unique instance name or leave it empty to be automatically populated. The automatic naming convention is `Azure-<tenantID>` or `Azure-<subscriptionID>`. Cortex XSIAM does not prevent you from reusing instance names, but it is best practice to use a unique name for every cloud instance. * **Deployment Method:** Select whether you want to onboard with a Cortex-generated IaC template or to perform a manual deployment: * **Infrastructure as Code:** (Recommended) Automatically provisions all required cloud resources and permissions using an IaC template. * **Manual:** Select this option if your organization requires manual provisioning to meet internal security and compliance policies. If you choose to onboard manually, follow the [manual onboarding instructions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/EGgPqu5Pm2LdBLfMWLeZ/). * **Scope Modifications:** Use these settings to fine-tune your Microsoft Azure scope. You can modify the scope by including or excluding specific regions. If you selected a Government environment, only Microsoft Azure Government regions are displayed. Additionally, if you selected a tenant or management group as the scope, you can modify the scope by including or excluding specific management groups or subscriptions. For more details, see [Apply region or account filters](../..#step-5-apply-region-or-account-filters-optional). Scope modifications are not available when you are onboarding Microsoft Entra ID only. * **Additional Security Capabilities:** Choose which security capabilities you want to benefit from. Some security capabilities are enabled by default and can be modified. Adding security capability typically requires additional cloud provider permissions. For detailed information on the permissions required, see [Cloud service provider permissions](../cloud-service-provider-permissions). When you are onboarding Microsoft Entra ID only, only XSIAM analytics is supported as an additional security capability. * **Data security posture management:** An agentless data security scanner that discovers, classifies, protects, and governs sensitive data. DSPM is not currently available in Microsoft Azure Government environments. * **Registry scanning:** A container registry scanner that scans registry images for vulnerabilities, malware, and secrets. For more details, see [Configure registry scanning for cloud accounts](../../cloud-posture-and-runtime-security-data-sources/container-registry-scanning/configure-registry-scanning-for-cloud-accounts). - * **Serverless functions scanning:** Implement serverless scanning to detect and remediate vulnerabilities within serverless functions during the development lifecycle. Seamless integration into CI/CD pipelines enables automated security scans for a continuously secure pre-production environment. - * **Allow connection to private serverless functions:** (Optional - only available with outpost scan) When serverless scanning runs from the outpost environment, it uses a dynamic IP address. Azure Functions with IP-based network restrictions will block the scanner. Enabling this option assigns a fixed IP address that can be whitelisted. + * **Serverless functions scanning:** Implement serverless scanning to detect and remediate vulnerabilities within serverless functions during the development lifecycle. Seamless integration into CI/CD pipelines enables automated security scans for a continuously secure pre-production environment. + + * **Allow connection to private serverless functions:** (Optional - only available with outpost scan) When serverless scanning runs from the outpost environment, it uses a dynamic IP address. Azure Functions with IP-based network restrictions will block the scanner. Enabling this option assigns a fixed IP address that can be whitelisted. + + <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p>Enabling this feature requires additional permissions. Download and run the Terraform template again to apply the permissions required to scan private serverless resources. Private serverless resources are resources that are accessible only through private networks and aren’t publicly accessible.</p></div> * **Automation:** Use automation to pre-configure a list of integrations and associated commands to automate security issue responses. Commands can be utilized individually or as part of custom playbooks for issue remediation. * **Log Level:** (Optional - for Automation only) Configure the automation integration logging level. Possible values are: * Off (Default) * Debug * Verbose * **Agentless disk scanning:** (Recommended) Implement agentless disk scanning to remotely detect and remediate vulnerabilities during the development lifecycle. * **Cloud Tags:** Define tags and tag values to be added to any new resource created by Cortex XSIAM in Microsoft Azure. Note: The `managed_by = paloaltonetworks` tag is automatically added to all resources. This tag is mandatory. You cannot edit or remove this tag. * **Log Collection Configuration:** To maximize security coverage, include the collection of audit logs using Event Hub. Select the collection method: -
▸ ▾ Activate Apache Kafka Collector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-apache-kafka-collectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure this collector for Cortex XSIAM.description: Configure the Apache Kafka Collector applet for Cortex XSIAM.------# Activate Apache Kafka Collector# Activate Apache Kafka CollectorApache Kafka is an open-source distributed event streaming platform for high-performance data pipelines, streaming analytics and data integration. Kafka records are organized into Topics. The partitions for each Topic are spread across the bootstrap servers in the Kafka cluster. The bootstrap servers are responsible for transferring data from Producers to Consumer Groups, which enable the Kafka server to save offsets of each partition in the Topic consumed by each group.Apache Kafka is an open-source distributed event streaming platform for high-performance data pipelines, streaming analytics and data integration. Kafka records are organized into Topics. The partitions for each Topic are spread across the bootstrap servers in the Kafka cluster. The bootstrap servers are responsible for transferring data from Producers to Consumer Groups, which enable the Kafka server to save offsets of each partition in the Topic consumed by each group.The Broker VM provides a Kafka Collector applet that enables you to monitor and collect events from Topics on self-managed on-prem Kafka clusters directly to your log repository for query and visualization purposes. The applet supports Kafka setups with no authentication, with SSL authentication, and SASL SSL authentication.The Broker VM provides a Kafka Collector applet that enables you to monitor and collect events from Topics on self-managed on-prem Kafka clusters directly to your log repository for query and visualization purposes. The applet supports Kafka setups with no authentication, with SSL authentication, and SASL SSL authentication.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure this collector for Cortex XSIAM. +description: Configure the Apache Kafka Collector applet for Cortex XSIAM. --- # Activate Apache Kafka Collector Apache Kafka is an open-source distributed event streaming platform for high-performance data pipelines, streaming analytics and data integration. Kafka records are organized into Topics. The partitions for each Topic are spread across the bootstrap servers in the Kafka cluster. The bootstrap servers are responsible for transferring data from Producers to Consumer Groups, which enable the Kafka server to save offsets of each partition in the Topic consumed by each group. The Broker VM provides a Kafka Collector applet that enables you to monitor and collect events from Topics on self-managed on-prem Kafka clusters directly to your log repository for query and visualization purposes. The applet supports Kafka setups with no authentication, with SSL authentication, and SASL SSL authentication.
-
▸ ▾ Activate Cortex Network Scanner modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-cortex-network-scannerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure this scanner for Cortex XSIAM.description: Configure the Cortex Network Scanner applet for Cortex XSIAM.------# Activate Cortex Network Scanner# Activate Cortex Network ScannerThe Cortex Network Scanner identifies and analyzes devices, services, and vulnerabilities in your internal network. It discovers responsive hosts within specified IP ranges, including on-premises and cloud environments. The scanner supports both non-authenticated and authenticated vulnerability scanning, with authenticated scans providing deeper insights through credential-based access. Scan results are seamlessly integrated into the inventory and vulnerability management views in Cortex XSIAM, providing a centralized view of all discovered assets, vulnerabilities, and issues.The Cortex Network Scanner identifies and analyzes devices, services, and vulnerabilities in your internal network. It discovers responsive hosts within specified IP ranges, including on-premises and cloud environments. The scanner supports both non-authenticated and authenticated vulnerability scanning, with authenticated scans providing deeper insights through credential-based access. Scan results are seamlessly integrated into the inventory and vulnerability management views in Cortex XSIAM, providing a centralized view of all discovered assets, vulnerabilities, and issues.Cortex Network Scanner is installed as an applet on a Broker VM.Cortex Network Scanner is installed as an applet on a Broker VM.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure this scanner for Cortex XSIAM. +description: Configure the Cortex Network Scanner applet for Cortex XSIAM. --- # Activate Cortex Network Scanner The Cortex Network Scanner identifies and analyzes devices, services, and vulnerabilities in your internal network. It discovers responsive hosts within specified IP ranges, including on-premises and cloud environments. The scanner supports both non-authenticated and authenticated vulnerability scanning, with authenticated scans providing deeper insights through credential-based access. Scan results are seamlessly integrated into the inventory and vulnerability management views in Cortex XSIAM, providing a centralized view of all discovered assets, vulnerabilities, and issues. Cortex Network Scanner is installed as an applet on a Broker VM.
-
▸ ▾ Activate CSV Collector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-csv-collectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure this collector for Cortex XSIAM.description: Configure the CSV Collector applet for Cortex XSIAM.------# Activate CSV Collector# Activate CSV CollectorThe Broker VM provides a CSV Collector applet that enables you to monitor and collect CSV (comma-separated values) log files from a shared Windows directory directly to your log repository for query and visualization purposes. After you activate the CSV Collector applet on a Broker VM in your network, you can ingest CSV files as datasets by defining the list of folders mounted to the Broker VM and setting the list of CSV files to monitor and upload to Cortex XSIAM using a username and password.The Broker VM provides a CSV Collector applet that enables you to monitor and collect CSV (comma-separated values) log files from a shared Windows directory directly to your log repository for query and visualization purposes. After you activate the CSV Collector applet on a Broker VM in your network, you can ingest CSV files as datasets by defining the list of folders mounted to the Broker VM and setting the list of CSV files to monitor and upload to Cortex XSIAM using a username and password.### Prerequisite### PrerequisiteShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure this collector for Cortex XSIAM. +description: Configure the CSV Collector applet for Cortex XSIAM. --- # Activate CSV Collector The Broker VM provides a CSV Collector applet that enables you to monitor and collect CSV (comma-separated values) log files from a shared Windows directory directly to your log repository for query and visualization purposes. After you activate the CSV Collector applet on a Broker VM in your network, you can ingest CSV files as datasets by defining the list of folders mounted to the Broker VM and setting the list of CSV files to monitor and upload to Cortex XSIAM using a username and password. ### Prerequisite
-
▸ ▾ Activate Database Collector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-database-collectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure this collector for Cortex XSIAM.description: Configure the Database Collector applet for Cortex XSIAM.------# Activate Database Collector# Activate Database CollectorThe Broker VM provides a Database Collector applet that enables you to collect data from a client relational database directly to your log repository for query and visualization purposes. After you activate the Database Collector applet on a Broker VM in your network, you can collect records as datasets (<Vendor>_<Product>_raw) by defining the following.The Broker VM provides a Database Collector applet that enables you to collect data from a client relational database directly to your log repository for query and visualization purposes. After you activate the Database Collector applet on a Broker VM in your network, you can collect records as datasets (<Vendor>_<Product>_raw) by defining the following.• Database connection details, where the connection type can be MySQL, PostgreSQL, MSSQL, and Oracle. Cortex XSIAM uses Open Database Connectivity (ODBC) to access the databases.• Database connection details, where the connection type can be MySQL, PostgreSQL, MSSQL, and Oracle. Cortex XSIAM uses Open Database Connectivity (ODBC) to access the databases.• Settings related to the query details for collecting the data from the database to monitor and upload to Cortex XSIAM.• Settings related to the query details for collecting the data from the database to monitor and upload to Cortex XSIAM.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure this collector for Cortex XSIAM. +description: Configure the Database Collector applet for Cortex XSIAM. --- # Activate Database Collector The Broker VM provides a Database Collector applet that enables you to collect data from a client relational database directly to your log repository for query and visualization purposes. After you activate the Database Collector applet on a Broker VM in your network, you can collect records as datasets (**`<Vendor>_<Product>_raw`**) by defining the following. * Database connection details, where the connection type can be MySQL, PostgreSQL, MSSQL, and Oracle. Cortex XSIAM uses Open Database Connectivity (ODBC) to access the databases. * Settings related to the query details for collecting the data from the database to monitor and upload to Cortex XSIAM.
-
▸ ▾ Activate DSPM Database modified +4 −0
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-databaseRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Configure the DSPM Database applet for Cortex XSIAM.---# Activate DSPM Database# Activate DSPM Databasehint infohint infoLicenseLicenseThis feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on.This feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on.endhintendhintShow markdown source
@@ -1,8 +1,12 @@ +--- +description: Configure the DSPM Database applet for Cortex XSIAM. +--- + # Activate DSPM Database {% hint style="info" %} **License** This feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on. {% endhint %} -
▸ ▾ Activate DSPM Fileshare modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-dspm-fileshareRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure this data source for Cortex XSIAM.description: Configure the DSPM Fileshare applet for Cortex XSIAM.------# Activate DSPM Fileshare# Activate DSPM Filesharehint infohint infoLicenseLicenseThis feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on.This feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure this data source for Cortex XSIAM. +description: Configure the DSPM Fileshare applet for Cortex XSIAM. --- # Activate DSPM Fileshare {% hint style="info" %} **License** This feature is included with a Cortex XSIAM Premium license. It is also included with a Cortex XSIAM NG SIEM and Cortex XSIAM Enterprise license that has the Cloud Posture Security or Cloud Runtime Security add-on. -
▸ ▾ Activate Files and Folders Collector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-files-and-folders-collectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure this collector for Cortex XSIAM.description: Configure the Files and Folders Collector applet for Cortex XSIAM.------# Activate Files and Folders Collector# Activate Files and Folders CollectorThe Broker VM provides a Files and Folders Collector applet that enables you to monitor and collect logs from files and folders in a network share for a Windows or Linux directory, directly to your log repository for query and visualization purposes. The Files and Folders collector applet only starts to collect files that are more than 256 bytes and is only supported with a Network File System version 4 (NFSv4). After you activate the Files and Folders Collector applet, you can collect files as datasets (<Vendor>_<Product>_raw) by defining the following.The Broker VM provides a Files and Folders Collector applet that enables you to monitor and collect logs from files and folders in a network share for a Windows or Linux directory, directly to your log repository for query and visualization purposes. The Files and Folders collector applet only starts to collect files that are more than 256 bytes and is only supported with a Network File System version 4 (NFSv4). After you activate the Files and Folders Collector applet, you can collect files as datasets (<Vendor>_<Product>_raw) by defining the following.• Details of the folder path on the network share containing the files that you want to monitor and upload to Cortex XSIAM.• Details of the folder path on the network share containing the files that you want to monitor and upload to Cortex XSIAM.• Settings related to the list of files to monitor and upload to Cortex XSIAM, where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco.• Settings related to the list of files to monitor and upload to Cortex XSIAM, where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure this collector for Cortex XSIAM. +description: Configure the Files and Folders Collector applet for Cortex XSIAM. --- # Activate Files and Folders Collector The Broker VM provides a Files and Folders Collector applet that enables you to monitor and collect logs from files and folders in a network share for a Windows or Linux directory, directly to your log repository for query and visualization purposes. The Files and Folders collector applet only starts to collect files that are more than 256 bytes and is only supported with a Network File System version 4 (NFSv4). After you activate the Files and Folders Collector applet, you can collect files as datasets (**`<Vendor>_<Product>_raw`**) by defining the following. * Details of the folder path on the network share containing the files that you want to monitor and upload to Cortex XSIAM. * Settings related to the list of files to monitor and upload to Cortex XSIAM, where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco.
-
▸ ▾ Activate FTP Collector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-ftp-collectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure this collector for Cortex XSIAM.description: Configure the FTP Collector applet for Cortex XSIAM.------# Activate FTP Collector# Activate FTP CollectorThe Broker VM provides a FTP Collector applet that enables you to monitor and collect logs from files and folders via FTP, FTPS, and SFTP directly to your log repository for query and visualization purposes. A maximum file size of 500 MB is supported. After you activate the FTP Collector applet on a Broker VM in your network, you can collect files as datasets (<Vendor>_<Product>_raw) by defining the following.The Broker VM provides a FTP Collector applet that enables you to monitor and collect logs from files and folders via FTP, FTPS, and SFTP directly to your log repository for query and visualization purposes. A maximum file size of 500 MB is supported. After you activate the FTP Collector applet on a Broker VM in your network, you can collect files as datasets (<Vendor>_<Product>_raw) by defining the following.• FTP, FTPS, or SFTP (default) connection details with the path to the folder containing the files that you want to monitor and upload to Cortex XSIAM .• FTP, FTPS, or SFTP (default) connection details with the path to the folder containing the files that you want to monitor and upload to Cortex XSIAM .• Settings related to the list of files to monitor and upload to Cortex XSIAM , where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco. Once the files are uploaded to Cortex XSIAM , you can define whether in the source directory the files are renamed or deleted.• Settings related to the list of files to monitor and upload to Cortex XSIAM , where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco. Once the files are uploaded to Cortex XSIAM , you can define whether in the source directory the files are renamed or deleted.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure this collector for Cortex XSIAM. +description: Configure the FTP Collector applet for Cortex XSIAM. --- # Activate FTP Collector The Broker VM provides a FTP Collector applet that enables you to monitor and collect logs from files and folders via FTP, FTPS, and SFTP directly to your log repository for query and visualization purposes. A maximum file size of 500 MB is supported. After you activate the FTP Collector applet on a Broker VM in your network, you can collect files as datasets (`<Vendor>_<Product>_raw`) by defining the following. * FTP, FTPS, or SFTP (default) connection details with the path to the folder containing the files that you want to monitor and upload to Cortex XSIAM . * Settings related to the list of files to monitor and upload to Cortex XSIAM , where the log format is either Raw (default), JSON, CSV, TSV, PSV, CEF, LEEF, Corelight, or Cisco. Once the files are uploaded to Cortex XSIAM , you can define whether in the source directory the files are renamed or deleted.
-
▸ ▾ Activate Local Agent Settings modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-local-agent-settingsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure local agent settings for Cortex XSIAM.description: Configure the Local Agent Settings applet for Cortex XSIAM.------# Activate Local Agent Settings# Activate Local Agent Settingshint infohint infoLicenseLicenseThis feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security.This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure local agent settings for Cortex XSIAM. +description: Configure the Local Agent Settings applet for Cortex XSIAM. --- # Activate Local Agent Settings {% hint style="info" %} **License** This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security. -
▸ ▾ Activate NetFlow Collector modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-netflow-collectorRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure this collector for Cortex XSIAM.description: Configure the NetFlow Collector applet for Cortex XSIAM.------# Activate NetFlow Collector# Activate NetFlow CollectorTo receive NetFlow flow records from an external source, you must first set up the NetFlow Collector applet on a Broker VM within your network. NetFlow versions 5, 9, and IPFIX are supported.To receive NetFlow flow records from an external source, you must first set up the NetFlow Collector applet on a Broker VM within your network. NetFlow versions 5, 9, and IPFIX are supported.To increase the log ingestion rate, you can add additional CPUs to the Broker VM. The NetFlow Collector listens for flow records on specific ports either from any, or from specific IP addresses.To increase the log ingestion rate, you can add additional CPUs to the Broker VM. The NetFlow Collector listens for flow records on specific ports either from any, or from specific IP addresses.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure this collector for Cortex XSIAM. +description: Configure the NetFlow Collector applet for Cortex XSIAM. --- # Activate NetFlow Collector To receive NetFlow flow records from an external source, you must first set up the NetFlow Collector applet on a Broker VM within your network. NetFlow versions 5, 9, and IPFIX are supported. To increase the log ingestion rate, you can add additional CPUs to the Broker VM. The NetFlow Collector listens for flow records on specific ports either from any, or from specific IP addresses.
-
▸ ▾ Activate Network Mapper modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-network-mapperRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure Network Mapper for Cortex XSIAM.description: Configure the Network Mapper applet for Cortex XSIAM.------# Activate Network Mapper# Activate Network Mapperhint infohint infoThis feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security.This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security.endhintendhintShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure Network Mapper for Cortex XSIAM. +description: Configure the Network Mapper applet for Cortex XSIAM. --- # Activate Network Mapper {% hint style="info" %} This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that includes endpoints or Cortex Cloud Runtime Security. {% endhint %} -
▸ ▾ Activate Transporter modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporterRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure Transporter for Cortex XSIAM.description: Configure Transporter applet for Cortex XSIAM.------# Activate Transporter# Activate Transporter## Activate Transporter## Activate Transporterhint infohint info### Notice### NoticeShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure Transporter for Cortex XSIAM. +description: Configure Transporter applet for Cortex XSIAM. --- # Activate Transporter ## **Activate Transporter** {% hint style="info" %} ### Notice -
▸ ▾ AWS Automation and Collection modified +4 −0
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/aws-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,8 +1,12 @@---description: Use AWS Automation and Collection in Cortex XSIAM.---# AWS Automation and Collection# AWS Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.endhintendhintShow markdown source
@@ -1,8 +1,12 @@ +--- +description: Use AWS Automation and Collection in Cortex XSIAM. +--- + # AWS Automation and Collection {% hint style="warning" %} **Important** This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). {% endhint %} -
▸ ▾ Ingest Azure APIM modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/api-security/ingest-data-for-api-security/ingest-azure-apimRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Collect Azure APIM data withdescription: Collect Azure APIM data with Cortex XSIAM.------# Ingest Azure APIM# Ingest Azure APIMIntegrate Azure APIM with Cortex XSIAM to start scanning its APIs for potential threats and vulnerabilities.Integrate Azure APIM with Cortex XSIAM to start scanning its APIs for potential threats and vulnerabilities.You need to set up a policy that enables you to customize the behavior of managed APIs. You can configure the sending of HTTP request/response data to Cortex XSIAM. The data is saved and analyzed by API security modules, which provide information on the security risks associated with the APIs.You need to set up a policy that enables you to customize the behavior of managed APIs. You can configure the sending of HTTP request/response data to Cortex XSIAM. The data is saved and analyzed by API security modules, which provide information on the security risks associated with the APIs.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Collect Azure APIM data with +description: Collect Azure APIM data with Cortex XSIAM. --- # Ingest Azure APIM Integrate Azure APIM with Cortex XSIAM to start scanning its APIs for potential threats and vulnerabilities. You need to set up a policy that enables you to customize the behavior of managed APIs. You can configure the sending of HTTP request/response data to Cortex XSIAM. The data is saved and analyzed by API security modules, which provide information on the security risks associated with the APIs.
-
▸ ▾ Data souce UUIDs modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/cribl/ingest-data-from-cribl/data-souce-uuidsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -17,17 +17,17 @@ Any data source can be ingested using the generic UUID collector with the correc### Amazon### AmazonProduct│UUID│Datasets│Collection MethodProduct│UUID│Datasets│Collection Method| ----------------- | ------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || ----------------- | ------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |AWS audit logs│c19f87b6262f48259b3d5d2a2c691802│amazon_aws_raw│These AWS logs are collected via Amazon S3. To ensure compatibility, see Ingest audit logs from AWS Cloud Trail.AWS audit logs│c19f87b6262f48259b3d5d2a2c691802│amazon_aws_raw│These AWS logs are collected via Amazon S3. To ensure compatibility, see Ingest audit logs from AWS Cloud Trail.AWS EKS│fb8a9d4922cb4095b76d71e921d2d999│amazon_eks_raw│These AWS logs are collected via Amazon CloudWatch. To ensure collector compatibility, see Ingest logs from Amazon CloudWatch.AWS EKS│fb8a9d4922cb4095b76d71e921d2d999│amazon_eks_raw│These AWS logs are collected via Amazon CloudWatch. To ensure collector compatibility, see Ingest logs from Amazon CloudWatch.AWS flow logs│667083aa68544eee8b67cdd2d4cc327b│amazon_aws_raw│These logs are collected via Amazon S3. To ensure collector compatibility, see Ingest network flow logs from Amazon S3.AWS flow logs│667083aa68544eee8b67cdd2d4cc327b│amazon_aws_raw│These logs are collected via Amazon S3. To ensure collector compatibility, see Ingest network flow logs from Amazon S3.AWS generic logs│0498f8a24de04b3e85102e742f6783f8│amazon_aws_raw│These logs are collected via Amazon S3. To ensure collector compatibility, see Ingest generic logs from Amazon S3.AWS generic logs│0498f8a24de04b3e85102e742f6783f8│amazon_aws_raw│These logs are collected via Amazon S3. To ensure collector compatibility, see Ingest generic logs from Amazon S3.AWS prompt logs│a53edad7ef0c46ffb5037fb2e21520cb│amazon_aws_raw│For setup details, see Prompt log collection in AWS.AWS prompt logs│a53edad7ef0c46ffb5037fb2e21520cb│amazon_aws_raw│For setup details, see Prompt log collection in AWS.AWS Route 53 logs│- d57ae82c1e2a4d138fc34084d159b09e (old)
- 0a7544038b444998a20e698669817e3d (new)
amazon_route53_raw(via old UUID)amazon_route53_raw(via new UUID)
AWS Route 53 logs│- d57ae82c1e2a4d138fc34084d159b09e (old)
- 0a7544038b444998a20e698669817e3d (new)
amazon_route53_raw(via old UUID)amazon_route53_raw(via new UUID)
### Box### BoxProduct│UUID│Datasets│Collection MethodProduct│UUID│Datasets│Collection Method| ------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || ------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |Box│3ef05d14ae9349f8bbd48c8a4797334a│- Events (admin_logs):
box_admin_logs_raw - Box Shield Alerts:
box_shield_alerts_raw - Users:
box_users_raw - Groups:
box_groups_raw
BOX_DIRECTORIESconnector queries the following Box API endpoints:Users
- Endpoint:
https://api.box.com/2.0/users - Purpose: To fetch the list of users in Box enterprise.
- Endpoint:
Groups
- Endpoint:
https://api.box.com/2.0/groups - Purpose: To fetch the list of groups in Box enterprise.
- Endpoint:
For setup details, see Ingest logs and data from Box.
Box│3ef05d14ae9349f8bbd48c8a4797334a│- Events (admin_logs):
box_admin_logs_raw - Box Shield Alerts:
box_shield_alerts_raw - Users:
box_users_raw - Groups:
box_groups_raw
BOX_DIRECTORIESconnector queries the following Box API endpoints:Users
- Endpoint:
https://api.box.com/2.0/users - Purpose: To fetch the list of users in Box enterprise.
- Endpoint:
Groups
- Endpoint:
https://api.box.com/2.0/groups - Purpose: To fetch the list of groups in Box enterprise.
- Endpoint:
For setup details, see Ingest logs and data from Box.
Show markdown source
@@ -17,17 +17,17 @@ Any data source can be ingested using the generic UUID collector with the correc ### Amazon | Product | UUID | Datasets | Collection Method | | ----------------- | ------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | AWS audit logs | c19f87b6262f48259b3d5d2a2c691802 | `amazon_aws_raw` | These AWS logs are collected via Amazon S3. To ensure compatibility, see [Ingest audit logs from AWS Cloud Trail](../../amazon/amazon-s3/ingest-audit-logs-from-aws-cloudtrail). | | AWS EKS | fb8a9d4922cb4095b76d71e921d2d999 | `amazon_eks_raw` | These AWS logs are collected via Amazon CloudWatch. To ensure collector compatibility, see [Ingest logs from Amazon CloudWatch](../../amazon/amazon-cloud-watch/ingest-logs-from-amazon-cloudwatch). | | AWS flow logs | 667083aa68544eee8b67cdd2d4cc327b | `amazon_aws_raw` | These logs are collected via Amazon S3. To ensure collector compatibility, see [Ingest network flow logs from Amazon S3](../../amazon/amazon-s3/ingest-network-flow-logs-from-amazon-s3). | | AWS generic logs | 0498f8a24de04b3e85102e742f6783f8 | `amazon_aws_raw` | These logs are collected via Amazon S3. To ensure collector compatibility, see [Ingest generic logs from Amazon S3](../../amazon/amazon-s3/ingest-generic-logs-from-amazon-s3). | -| AWS prompt logs | a53edad7ef0c46ffb5037fb2e21520cb | `amazon_aws_raw` | For setup details, see [Prompt log collection in AWS](../../../../../detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-aws). | +| AWS prompt logs | a53edad7ef0c46ffb5037fb2e21520cb | `amazon_aws_raw` | For setup details, see [Prompt log collection in AWS](../../../../../detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-aws). | | AWS Route 53 logs | <ul><li>d57ae82c1e2a4d138fc34084d159b09e (old)</li><li>0a7544038b444998a20e698669817e3d (new)</li></ul> | <ul><li><code>amazon_route53_raw</code> (via old UUID)</li><li><code>amazon_route53_raw</code> (via new UUID)</li></ul> | These logs are collected via Amazon S3. Using the old UUID routes data to the generic AWS dataset. For native routing to the Route 53 dataset, use the new dedicated UUID. To ensure collector compatibility, see [Ingest network Route 53 logs from Amazon S3](../../amazon/amazon-s3/ingest-network-route-53-logs-from-amazon-s3). | ### Box | Product | UUID | Datasets | Collection Method | | ------- | -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Box | 3ef05d14ae9349f8bbd48c8a4797334a | <ul><li>Events (admin_logs): <code>box_admin_logs_raw</code></li><li>Box Shield Alerts: <code>box_shield_alerts_raw</code></li><li>Users: <code>box_users_raw</code></li><li>Groups: <code>box_groups_raw</code></li></ul> | <p>The <code>BOX_DIRECTORIES</code> connector queries the following Box API endpoints:</p><ul><li><p><strong>Users</strong></p><ul><li>Endpoint: <code>https://api.box.com/2.0/users</code></li><li>Purpose: To fetch the list of users in Box enterprise.</li></ul></li><li><p><strong>Groups</strong></p><ul><li>Endpoint: <code>https://api.box.com/2.0/groups</code></li><li>Purpose: To fetch the list of groups in Box enterprise.</li></ul></li></ul><p>For setup details, see <a href="../../box/ingest-logs-and-data-from-box">Ingest logs and data from Box</a>.</p> |
-
▸ ▾ Ingest logs from Google Kubernetes Engine modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/google/google-kubernetes-engine/ingest-logs-from-google-kubernetes-engineRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Collect Google Kuberbetes Engine data with Cortex XSIAM.description: Collect Google Kubernetes Engine data with Cortex XSIAM.------# Ingest logs from Google Kubernetes Engine# Ingest logs from Google Kubernetes EngineInstead of forwarding Google Kubernetes Engine (GKE) logs directly to Google StackDrive, Cortex XSIAM can ingest container logs from GKE using Elasticsearch Filebeat. To receive logs, you must install Filebeat on your containers and enable Data Collection settings for Filebeat.Instead of forwarding Google Kubernetes Engine (GKE) logs directly to Google StackDrive, Cortex XSIAM can ingest container logs from GKE using Elasticsearch Filebeat. To receive logs, you must install Filebeat on your containers and enable Data Collection settings for Filebeat.When Cortex XSIAM begins receiving logs, the app automatically creates an Cortex Query Language (XQL) dataset using the vendor and product name that you specify during Filebeat setup. It is recommended to specify a descriptive name. For example, if you specifygoogleas the vendor andkubernetesas the product, the dataset name will begoogle_kubernetes_raw. If you leave the product and vendor blank, Cortex XSIAM assigns the dataset a name ofcontainer_container_raw.When Cortex XSIAM begins receiving logs, the app automatically creates an Cortex Query Language (XQL) dataset using the vendor and product name that you specify during Filebeat setup. It is recommended to specify a descriptive name. For example, if you specifygoogleas the vendor andkubernetesas the product, the dataset name will begoogle_kubernetes_raw. If you leave the product and vendor blank, Cortex XSIAM assigns the dataset a name ofcontainer_container_raw.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Collect Google Kuberbetes Engine data with Cortex XSIAM. +description: Collect Google Kubernetes Engine data with Cortex XSIAM. --- # Ingest logs from Google Kubernetes Engine Instead of forwarding Google Kubernetes Engine (GKE) logs directly to Google StackDrive, Cortex XSIAM can ingest container logs from GKE using Elasticsearch Filebeat. To receive logs, you must install Filebeat on your containers and enable Data Collection settings for Filebeat. When Cortex XSIAM begins receiving logs, the app automatically creates an Cortex Query Language (XQL) dataset using the vendor and product name that you specify during Filebeat setup. It is recommended to specify a descriptive name. For example, if you specify `google` as the vendor and `kubernetes` as the product, the dataset name will be `google_kubernetes_raw`. If you leave the product and vendor blank, Cortex XSIAM assigns the dataset a name of `container_container_raw`.
-
▸ ▾ How to onboard Microsoft 365 modified +2 −2 Now says Microsoft 365 is added as a third-party data source in Cortex XSIAM rather than in Cortex Cloud Data Security.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-365-posture/how-to-onboard-microsoft-365Read it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,21 +1,21 @@------description: >-description: >-Learn more about adding Microsoft 365 as a third-party data source in CortexLearn more about adding Microsoft 365 as a third-party data source in CortexCloud Data Security.XSIAM.------# How to onboard Microsoft 365# How to onboard Microsoft 365hint infohint infoThis feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that has the Cloud Posture Security or Cloud Runtime Security add-on.This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that has the Cloud Posture Security or Cloud Runtime Security add-on.endhintendhintYou can add Microsoft 365 as a third-party data source in Cortex Cloud Data Security.You can add Microsoft 365 as a third-party data source in Cortex XSIAM.• You have generated a Globally Unique Identifier (GUID), also known as a Universally Unique Identifier (UUID). You will need this ID for the tenant you want to use for the Microsoft 365 instance.• You have generated a Globally Unique Identifier (GUID), also known as a Universally Unique Identifier (UUID). You will need this ID for the tenant you want to use for the Microsoft 365 instance.• In order to use Microsoft 365, you must be registered with Microsoft Azure.• In order to use Microsoft 365, you must be registered with Microsoft Azure.#### Configuration#### Configuration1. Navigate to Settings → Data Sources & Integrations.1. Navigate to Settings → Data Sources & Integrations.2. On the Data Sources & Integrations page, click + Add New.2. On the Data Sources & Integrations page, click + Add New.Show markdown source
@@ -1,21 +1,21 @@ --- description: >- Learn more about adding Microsoft 365 as a third-party data source in Cortex - Cloud Data Security. + XSIAM. --- # How to onboard Microsoft 365 {% hint style="info" %} This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that has the Cloud Posture Security or Cloud Runtime Security add-on. {% endhint %} -You can add Microsoft 365 as a third-party data source in Cortex Cloud Data Security. +You can add Microsoft 365 as a third-party data source in Cortex XSIAM. * You have generated a Globally Unique Identifier (GUID), also known as a Universally Unique Identifier (UUID). You will need this ID for the tenant you want to use for the Microsoft 365 instance. * In order to use Microsoft 365, you must be registered with Microsoft Azure. #### **Configuration** 1. Navigate to Settings → Data Sources & Integrations. 2. On the Data Sources & Integrations page, click + Add New. -
▸ ▾ Microsoft 365 (new) modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft-365-newRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Use Microsoft 365 data with Cortex XSIAM.description: Use Microsoft 365 (new) data with Cortex XSIAM.------# Microsoft 365 (new)# Microsoft 365 (new)Secure sensitive data, monitor configurations, and track identity risks across your Microsoft 365 environment, including OneDrive, SharePoint, Teams, and Entra ID.Secure sensitive data, monitor configurations, and track identity risks across your Microsoft 365 environment, including OneDrive, SharePoint, Teams, and Entra ID.This connector includes the following capabilities and sub-capabilities (if applicable):This connector includes the following capabilities and sub-capabilities (if applicable):Show markdown source
@@ -1,10 +1,10 @@ --- -description: Use Microsoft 365 data with Cortex XSIAM. +description: Use Microsoft 365 (new) data with Cortex XSIAM. --- # Microsoft 365 (new) Secure sensitive data, monitor configurations, and track identity risks across your Microsoft 365 environment, including OneDrive, SharePoint, Teams, and Entra ID. This connector includes the following capabilities and sub-capabilities (if applicable):
-
▸ ▾ Microsoft365 (legacy) modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/microsoft-office-365/microsoft365-legacyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Use Microsoft365 data with Cortex XSIAM.description: Use Microsoft365 (legacy) data with Cortex XSIAM.------# Microsoft365 (legacy)# Microsoft365 (legacy)hint warninghint warningImportantImportantWe recommend using the new Microsoft 365 connector for the latest capabilities. For more information about how to migrate, see Migrate to the new Microsoft 365 connector.We recommend using the new Microsoft 365 connector for the latest capabilities. For more information about how to migrate, see Migrate to the new Microsoft 365 connector.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Use Microsoft365 data with Cortex XSIAM. +description: Use Microsoft365 (legacy) data with Cortex XSIAM. --- # Microsoft365 (legacy) {% hint style="warning" %} **Important** We recommend using the new [**Microsoft 365**](microsoft-365-new) connector for the latest capabilities. For more information about how to migrate, see [**Migrate to the new Microsoft 365 connector**](microsoft365-legacy/migrate-to-new-microsoft-365-connector). -
▸ ▾ MongoDB modified +2 −1 The section index gains the new MongoDB Atlas (Posture) entry.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mongodbRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,11 @@------description: Configure the MongoDB connectors for Cortex XSIAM.description: Configure the MongoDB data source and connectors for Cortex XSIAM.------# MongoDB# MongoDBHere are the articles in this section:Here are the articles in this section:• how-to-onboard-mongodb-atlas• mongodb• mongodb• mongodb-atlas• mongodb-atlasShow markdown source
@@ -1,10 +1,11 @@ --- -description: Configure the MongoDB connectors for Cortex XSIAM. +description: Configure the MongoDB data source and connectors for Cortex XSIAM. --- # MongoDB Here are the articles in this section: +* [how-to-onboard-mongodb-atlas](mongodb/how-to-onboard-mongodb-atlas "mention") * [mongodb](mongodb/mongodb "mention") * [mongodb-atlas](mongodb/mongodb-atlas "mention")
-
▸ ▾ How to onboard MongoDB Atlas (Posture) added +49 −0 New page: onboarding MongoDB Atlas (Posture) with an organization ID and service account credentials, plus an IP allowlist step for network-protected accounts.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/mongodb/how-to-onboard-mongodb-atlasRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -0,0 +1,49 @@---description: Use MongoDB Atlas (Posture) data with Cortex XSIAM.---# How to onboard MongoDB Atlas (Posture)## OverviewIntegrate Cloud Security with your MongoDB Atlas account to gain comprehensive visibility into any data and posture risk existing in your MongoDB Atlas environment. This integration enables automated scanning of all assets in MongoDB Atlas, including data classification and risk assessment.## Prerequisites• You are an administrator.• You have the following information:• Organization ID• Service account client ID• Service account client secret• You have created a service principal and granted it permissions.## Add configuration details1. Go to Settings > Data Sources & Integrations and then on the Data Sources & Integrations screen, click + Add New.2. On the Add Data Sources or Integrations page, click Show More > Database and then click on the MongoDB Atlas (Posture) card and then click Add.\Alternatively, you can enter “Mongo” in the Search Sources filter field, and then click on the MongoDB Atlas (Posture) card > Add as mentioned above.3. In the MongoDB Atlas (Posture) Instance screen, enter the following:• Display Name• MongoDB Atlas Organization ID• Client ID• Client Secret4. Optional: If your MongoDB Atlas account is protected by network policies, turn on the toggle, then select the required regions for each cloud provider (AWS, Azure, GCP).5. Click Next.## Establish a connection1. In the IP List, select the IPs from the regions that you had selected that you want to whitelist. A tooltip shows the selected regions for the cloud platforms you are using.2. A script is generated that needs to be run in the MongoDB Atlas account.### Set up your MongoDB Atlas connection1. Open your MongoDB console in a new tab.2. Copy or download the script provided in step 2 above and run it in the MongoDB CLI.3. Proceed to verifying the connection.## Verify the connection1. Click Verify Connection.\NOTE: Keep the screen open for the duration of the connection verification.2. Once you see the Instance Created Successfully message on the screen, you can click Close.3. You can now go back to the Data Sources & Integrations screen and MongoDB Atlas (Posture) should appear in the list with relevant details such as Vendor and Instances Status. To see more details, click on the row and a pane opens with further account details such as connection status and more.Show markdown source
@@ -0,0 +1,49 @@ +--- +description: Use MongoDB Atlas (Posture) data with Cortex XSIAM. +--- + +# How to onboard MongoDB Atlas (Posture) + +## Overview + +Integrate Cloud Security with your MongoDB Atlas account to gain comprehensive visibility into any data and posture risk existing in your MongoDB Atlas environment. This integration enables automated scanning of all assets in MongoDB Atlas, including data classification and risk assessment. + +## Prerequisites + +* You are an administrator. +* You have the following information: + * Organization ID + * Service account client ID + * Service account client secret +* You have created a service principal and granted it permissions. + +## Add configuration details + +1. Go to **Settings > Data Sources & Integrations** and then on the **Data Sources & Integrations** screen, click **+ Add New**. +2. On the **Add Data Sources or Integrations** page, click **Show More > Database** and then click on the **MongoDB Atlas (Posture)** card and then click **Add**.\ + Alternatively, you can enter “Mongo” in the **Search Sources** filter field, and then click on the **MongoDB Atlas (Posture)** card > **Add** as mentioned above. +3. In the **MongoDB Atlas (Posture) Instance** screen, enter the following: + * Display Name + * MongoDB Atlas Organization ID + * Client ID + * Client Secret +4. Optional: If your MongoDB Atlas account is protected by network policies, turn on the toggle, then select the required regions for each cloud provider (AWS, Azure, GCP). +5. Click **Next**. + +## Establish a connection + +1. In the **IP List**, select the IPs from the regions that you had selected that you want to whitelist. A tooltip shows the selected regions for the cloud platforms you are using. +2. A script is generated that needs to be run in the MongoDB Atlas account. + +### Set up your MongoDB Atlas connection + +1. Open your MongoDB console in a new tab. +2. Copy or download the script provided in step 2 above and run it in the MongoDB CLI. +3. Proceed to verifying the connection. + +## Verify the connection + +1. Click **Verify Connection**.\ + **NOTE**: Keep the screen open for the duration of the connection verification. +2. Once you see the **Instance Created Successfully** message on the screen, you can click **Close**. +3. You can now go back to the **Data Sources & Integrations** screen and **MongoDB Atlas (Posture)** should appear in the list with relevant details such as **Vendor** and **Instances Status**. To see more details, click on the row and a pane opens with further account details such as connection status and more.
-
▸ ▾ Okta modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oktaRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Okta data sources for Cortex XSIAM.description: Configure the Okta data source and connectors for Cortex XSIAM.------# Okta# OktaYou can configure collecting Okta logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:You can configure collecting Okta logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors:Collection Method│DescriptionCollection Method│Description| --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Okta data sources for Cortex XSIAM. +description: Configure the Okta data source and connectors for Cortex XSIAM. --- # Okta You can configure collecting Okta logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connectors: | Collection Method | Description | | --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-
▸ ▾ OneLogin modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oneloginRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the OneLogin data sources for Cortex XSIAM.description: Configure the OneLogin data source and connector for Cortex XSIAM.------# OneLogin# OneLoginYou can configure collecting OneLogin logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):You can configure collecting OneLogin logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026):Collection Method│DescriptionCollection Method│Description| --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the OneLogin data sources for Cortex XSIAM. +description: Configure the OneLogin data source and connector for Cortex XSIAM. --- # OneLogin You can configure collecting OneLogin logs and data using a Standard Collector, content pack integration (onboarded prior to July 26, 2026), or connector (onboarded after July 26, 2026): | Collection Method | Description | | --------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-
▸ ▾ OpenText modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/opentextRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the OpenText data sources for Cortex XSIAM.description: Configure the OpenText connectors for Cortex XSIAM.------# OpenText# OpenTextHere are the articles in this section:Here are the articles in this section:• opentext-encase-endpoint-security• opentext-encase-endpoint-security• opentext-service-manager• opentext-service-managerShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the OpenText data sources for Cortex XSIAM. +description: Configure the OpenText connectors for Cortex XSIAM. --- # OpenText Here are the articles in this section: * [opentext-encase-endpoint-security](opentext/opentext-encase-endpoint-security "mention") * [opentext-service-manager](opentext/opentext-service-manager "mention")
-
▸ ▾ Oracle modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oracleRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Oracle data sources for Cortex XSIAM.description: Configure the Oracle data source and connector for Cortex XSIAM.------# Oracle# OracleHere are the articles in this section:Here are the articles in this section:• oracle-cloud-infrastructure• oracle-cloud-infrastructure• oracle• oracleShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Oracle data sources for Cortex XSIAM. +description: Configure the Oracle data source and connector for Cortex XSIAM. --- # Oracle Here are the articles in this section: * [oracle-cloud-infrastructure](oracle/oracle-cloud-infrastructure "mention") * [oracle](oracle/oracle "mention")
-
▸ ▾ Oracle Cloud Infrastructure modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/oracle/oracle-cloud-infrastructureRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure Oracle Cloud Infrastructure data sources for Cortex XSIAM.description: Configure Oracle Cloud Infrastructure data source for Cortex XSIAM.------# Oracle Cloud Infrastructure# Oracle Cloud InfrastructureFollow a wizard to onboard your Oracle Cloud Infrastructure (OCI) environment. The OCI onboarding wizard is designed to facilitate the seamless setup of OCI data into Cortex XSIAM.Follow a wizard to onboard your Oracle Cloud Infrastructure (OCI) environment. The OCI onboarding wizard is designed to facilitate the seamless setup of OCI data into Cortex XSIAM.Collection Method│DescriptionCollection Method│Description| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure Oracle Cloud Infrastructure data sources for Cortex XSIAM. +description: Configure Oracle Cloud Infrastructure data source for Cortex XSIAM. --- # Oracle Cloud Infrastructure Follow a wizard to onboard your Oracle Cloud Infrastructure (OCI) environment. The OCI onboarding wizard is designed to facilitate the seamless setup of OCI data into Cortex XSIAM. | Collection Method | Description | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-
▸ ▾ PagerDuty modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/pagerdutyRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the PagerDuty data sources for Cortex XSIAM.description: Configure the PagerDuty connectors for Cortex XSIAM.------# PagerDuty# PagerDutyHere are the articles in this section:Here are the articles in this section:• pagerduty-automation-and-collection• pagerduty-automation-and-collection• pagerduty• pagerdutyShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the PagerDuty data sources for Cortex XSIAM. +description: Configure the PagerDuty connectors for Cortex XSIAM. --- # PagerDuty Here are the articles in this section: * [pagerduty-automation-and-collection](pagerduty/pagerduty-automation-and-collection "mention") * [pagerduty](pagerduty/pagerduty "mention")
-
▸ ▾ Ping Identity modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/ping-identityRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Ping Identity data sources for Cortex XSIAM.description: Configure the Ping Identity data sources and connector for Cortex XSIAM.------# Ping Identity# Ping IdentityHere are the articles in this section:Here are the articles in this section:• pingfederate• pingfederate• pingone• pingoneShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Ping Identity data sources for Cortex XSIAM. +description: Configure the Ping Identity data sources and connector for Cortex XSIAM. --- # Ping Identity Here are the articles in this section: * [pingfederate](ping-identity/pingfederate "mention") * [pingone](ping-identity/pingone "mention")
-
▸ ▾ Proofpoint modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/proofpointRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Proofpoint data sources for Cortex XSIAM.description: Configure the Proofpoint data source and connector for Cortex XSIAM.------# Proofpoint# ProofpointHere are the articles in this section:Here are the articles in this section:• proofpoint-targeted-attack-protection• proofpoint-targeted-attack-protection• proofpoint• proofpointShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Proofpoint data sources for Cortex XSIAM. +description: Configure the Proofpoint data source and connector for Cortex XSIAM. --- # Proofpoint Here are the articles in this section: * [proofpoint-targeted-attack-protection](proofpoint/proofpoint-targeted-attack-protection "mention") * [proofpoint](proofpoint/proofpoint "mention")
-
▸ ▾ Salesforce modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/salesforceRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Salesforce data sources for Cortex XSIAM.description: Configure the Salesforce data source and connector for Cortex XSIAM.------# Salesforce# SalesforceYou can configure collecting Salesforce logs and data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:You can configure collecting Salesforce logs and data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:Collection Method│DescriptionCollection Method│Description| --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Salesforce data sources for Cortex XSIAM. +description: Configure the Salesforce data source and connector for Cortex XSIAM. --- # Salesforce You can configure collecting Salesforce logs and data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector: | Collection Method | Description | | --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-
▸ ▾ SAP modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sapRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the SAP data sources for Cortex XSIAM.description: Configure the SAP connectors for Cortex XSIAM.------# SAP# SAPHere are the articles in this section:Here are the articles in this section:• sap• sap• sap-ariba• sap-aribaShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the SAP data sources for Cortex XSIAM. +description: Configure the SAP connectors for Cortex XSIAM. --- # SAP Here are the articles in this section: * [sap](sap/sap "mention") * [sap-ariba](sap/sap-ariba "mention")
-
▸ ▾ SentinelOne modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentineloneRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the SentinelOne data sources for Cortex XSIAM.description: Configure the SentinelOne data source and connector for Cortex XSIAM.------# SentinelOne# SentinelOneHere are the articles in this section:Here are the articles in this section:• sentinelone-deepvisibility• sentinelone-deepvisibility• sentinelone• sentineloneShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the SentinelOne data sources for Cortex XSIAM. +description: Configure the SentinelOne data source and connector for Cortex XSIAM. --- # SentinelOne Here are the articles in this section: * [sentinelone-deepvisibility](sentinelone/sentinelone-deepvisibility "mention") * [sentinelone](sentinelone/sentinelone "mention")
-
▸ ▾ SentinelOne modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/sentinelone/sentineloneRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Use SentinelOne data inCortex XSIAM.description: Use SentinelOne data in Cortex XSIAM.------# SentinelOne# SentinelOnehint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Use SentinelOne data inCortex XSIAM. +description: Use SentinelOne data in Cortex XSIAM. --- # SentinelOne {% hint style="warning" %} **Important** This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). -
▸ ▾ ServiceNow modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/servicenowRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the ServiceNow data sources for Cortex XSIAM.description: Configure the ServiceNow data source and connectors for Cortex XSIAM.------# ServiceNow# ServiceNowHere are the articles in this section:Here are the articles in this section:• servicenow-cdmb• servicenow-cdmb• servicenow-automation-and-collection• servicenow-automation-and-collectionShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the ServiceNow data sources for Cortex XSIAM. +description: Configure the ServiceNow data source and connectors for Cortex XSIAM. --- # ServiceNow Here are the articles in this section: * [servicenow-cdmb](servicenow/servicenow-cdmb "mention") * [servicenow-automation-and-collection](servicenow/servicenow-automation-and-collection "mention")
-
▸ ▾ Slack modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/slackRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Slack data sources for Cortex XSIAM.description: Configure the Slack connectors for Cortex XSIAM.------# Slack# SlackHere are the articles in this section:Here are the articles in this section:• slack-automation-and-collection• slack-automation-and-collection• slack-enterprise• slack-enterpriseShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Slack data sources for Cortex XSIAM. +description: Configure the Slack connectors for Cortex XSIAM. --- # Slack Here are the articles in this section: * [slack-automation-and-collection](slack/slack-automation-and-collection "mention") * [slack-enterprise](slack/slack-enterprise "mention")
-
▸ ▾ Snowflake modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/snowflakeRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Snowflake data sources for Cortex XSIAM.description: Configure the Snowflake data source and connector for Cortex XSIAM.------# Snowflake# SnowflakeYou can configure collecting Snowflake data using a Cloud Posture and Runtime Security data source or connector (onboarded after July 26, 2026):You can configure collecting Snowflake data using a Cloud Posture and Runtime Security data source or connector (onboarded after July 26, 2026):Collection Method│DescriptionCollection Method│Description| ------------------------------------------------------------------- | ------------------------------------------------------------------------------------ || ------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Snowflake data sources for Cortex XSIAM. +description: Configure the Snowflake data source and connector for Cortex XSIAM. --- # Snowflake You can configure collecting Snowflake data using a Cloud Posture and Runtime Security data source or connector (onboarded after July 26, 2026): | Collection Method | Description | | ------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
-
▸ ▾ Splunk modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/splunkRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Splunk data sources for Cortex XSIAM.description: Configure the Splunk connectors for Cortex XSIAM.------# Splunk# SplunkHere are the articles in this section:Here are the articles in this section:• splunk-automation-and-collection• splunk-automation-and-collection• splunk• splunkShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Splunk data sources for Cortex XSIAM. +description: Configure the Splunk connectors for Cortex XSIAM. --- # Splunk Here are the articles in this section: * [splunk-automation-and-collection](splunk/splunk-automation-and-collection "mention") * [splunk](splunk/splunk "mention")
-
▸ ▾ Trellix modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/trellixRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Trellix data sources for Cortex XSIAM.description: Configure the Trellix connectors for Cortex XSIAM.------# Trellix# TrellixHere are the articles in this section:Here are the articles in this section:• trellix-database-security• trellix-database-security• trellix-email-security-etp• trellix-email-security-etpShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Trellix data sources for Cortex XSIAM. +description: Configure the Trellix connectors for Cortex XSIAM. --- # Trellix Here are the articles in this section: * [trellix-database-security](trellix/trellix-database-security "mention") * [trellix-email-security-etp](trellix/trellix-email-security-etp "mention")
-
▸ ▾ VMware modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/vmwareRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the VMware data sources for Cortex XSIAM.description: Configure the VMware connectors for Cortex XSIAM.------# VMware# VMwareHere are the articles in this section:Here are the articles in this section:• vmware-automation-and-collection• vmware-automation-and-collection• vmware• vmwareShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the VMware data sources for Cortex XSIAM. +description: Configure the VMware connectors for Cortex XSIAM. --- # VMware Here are the articles in this section: * [vmware-automation-and-collection](vmware/vmware-automation-and-collection "mention") * [vmware](vmware/vmware "mention")
-
▸ ▾ Workday modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workdayRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Workday data sources in Cortex XSIAM.description: Configure the Workday data source and connectors in Cortex XSIAM.------# Workday# WorkdayYou can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:You can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector:Collection Method│DescriptionCollection Method│Description| ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Workday data sources in Cortex XSIAM. +description: Configure the Workday data source and connectors in Cortex XSIAM. --- # Workday You can configure collecting Workday report data using a standard collector, content pack integration (onboarded prior to July 26, 2026), or connector: | Collection Method | Description | | ---------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-
▸ ▾ Workday Automation and Collection modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/workday/workday-automation-and-collectionRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure Workday automation and data collection for Cortex XSIAM.description: Configure Workday automation and collection data for Cortex XSIAM.------# Workday Automation and Collection# Workday Automation and Collectionhint warninghint warningImportantImportantThis connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see Marketplace.Show markdown source
@@ -1,10 +1,10 @@ --- -description: Configure Workday automation and data collection for Cortex XSIAM. +description: Configure Workday automation and collection data for Cortex XSIAM. --- # Workday Automation and Collection {% hint style="warning" %} **Important** This connector is only available for tenants that onboarded after July 26, 2026. For tenants that onboarded before this date, use Marketplace to access the standalone integration. For more information, see [Marketplace](../../../marketplace). -
▸ ▾ Zscaler modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/zscalerRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,10 +1,10 @@------description: Configure the Zscaler data sources for Cortex XSIAM.description: Configure the Zscaler data sources and connector for Cortex XSIAM.------# Zscaler# ZscalerHere are the articles in this section:Here are the articles in this section:• zscaler-internet-access• zscaler-internet-access• zscaler-private-access• zscaler-private-accessShow markdown source
@@ -1,10 +1,10 @@ --- -description: Configure the Zscaler data sources for Cortex XSIAM. +description: Configure the Zscaler data sources and connector for Cortex XSIAM. --- # Zscaler Here are the articles in this section: * [zscaler-internet-access](zscaler/zscaler-internet-access "mention") * [zscaler-private-access](zscaler/zscaler-private-access "mention")
-
▸ ▾ Compute units usage modified +13 −5 States that compute unit consumption currently applies only to XQL queries, and adds an MSSP tenant selection note to the usage table.
xsiam/configure-cortex-xsiam/data-management/manage-compute-units/compute-units-usageRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,15 +1,19 @@---description: Monitor compute unit usage in Cortex XSIAM.---# Compute units usage# Compute units usageCortex XSIAM provides a free daily quota of compute units (CU) allocated according to your license size. Queries called without enough quota will fail. To expand your investigation capabilities, you can purchase additional CU by enabling the Compute Unit add-on. After purchasing the additional CU, you can enable the add-on by selecting Settings → Cortex XSIAM License → Addons, hovering over the Extended Compute Units tile and clicking Enable.Cortex XSIAM provides a free daily quota of compute units (CU) allocated according to your license size. Queries called without enough quota will fail.hint info### ImportantCompute units consumption currently applies only to XQL queries. Agentic and LLM information is shown only for informational purposes and does not consume compute units.endhintTo expand your investigation capabilities, you can purchase additional CU by enabling the Compute Unit add-on. After purchasing the additional CU, you can enable the add-on by selecting Settings → Cortex XSIAM License → Addons, hovering over the Extended Compute Units tile and clicking Enable.\\The Compute Unit add-on provides an additional 1 compute unit per day for a year, in addition to your free annual quota. For example, if you have allocated 1,825 free annual CU, with the add-on, you will have a total of 2,190 annual compute units. The Compute Unit add-on is calculated on an annual basis, starting from the procurement of your add-on license. The minimum purchase amount is 50 compute units.The Compute Unit add-on provides an additional 1 compute unit per day for a year, in addition to your free annual quota. For example, if you have allocated 1,825 free annual CU, with the add-on, you will have a total of 2,190 annual compute units. The Compute Unit add-on is calculated on an annual basis, starting from the procurement of your add-on license. The minimum purchase amount is 50 compute units.You can configure the daily consumption limit for your compute units according to your organizational needs and change it when needed. For example, you can set a lower limit on a daily basis, and during an incident investigation, you can change it to a higher limit that enables you to consume more compute units.You can configure the daily consumption limit for your compute units according to your organizational needs and change it when needed. For example, you can set a lower limit on a daily basis, and during an incident investigation, you can change it to a higher limit that enables you to consume more compute units.Your unused compute unit balance cannot be transferred from one licensing period to the next.Your unused compute unit balance cannot be transferred from one licensing period to the next.@@ -67,13 +71,17 @@ In the **Compute Units Usage** table, you can filter all the requests that were• For automated actions: Rule or playbook.• For automated actions: Rule or playbook.• Query/Prompt: The query or prompt.• Query/Prompt: The query or prompt.• Compute Unit Usage: How many units were used.• Compute Unit Usage: How many units were used.• Category: XQL Queries, Agents & LLM.• Category: XQL Queries, Agents & LLM.• Trigger Type: The type of source of the query or prompt. For example, automation rule or playbook.• Trigger Type: The type of source of the query or prompt. For example, automation rule or playbook.• Billable: Whether the query was deducted from your compute units. Requests that are non-billable are displayed for informational purposes and do not affect your daily limit or compute units balance.• Billable: Whether the query was deducted from your compute units. Requests that are non-billable are displayed for informational purposes and do not affect your daily limit or compute units balance.• Tenant: Appears only in a Managed Security tenant. Displays which tenant executed the query.• Tenant: Appears only in a Managed Security tenant. Displays which tenant executed the query.hint infoNOTE: For Managed Security tenants, select a tenant from the MSSP Tenant Selection drop-down menu to display information for that tenant.endhint### Investigate the XQL API results.### Investigate the XQL API results.In the Compute Units Usage table, locate an XQL API query, right-click, and select Show results.In the Compute Units Usage table, locate an XQL API query, right-click, and select Show results.The query is displayed in the query field of the Query Builder, where you can view the query results. For more information, see How to build XQL queries.The query is displayed in the query field of the Query Builder, where you can view the query results. For more information, see How to build XQL queries.Show markdown source
@@ -1,15 +1,19 @@ ---- -description: Monitor compute unit usage in Cortex XSIAM. ---- - # Compute units usage -Cortex XSIAM provides a free daily quota of compute units (CU) allocated according to your license size. Queries called without enough quota will fail. To expand your investigation capabilities, you can purchase additional CU by enabling the Compute Unit add-on. After purchasing the additional CU, you can enable the add-on by selecting **Settings → Cortex XSIAM License → Addons**, hovering over the **Extended Compute Units** tile and clicking **Enable**. +Cortex XSIAM provides a free daily quota of compute units (CU) allocated according to your license size. Queries called without enough quota will fail.  + +{% hint style="info" %} +### Important + +Compute units consumption currently applies only to XQL queries. Agentic and LLM information is shown only for informational purposes and does not consume compute units. +{% endhint %} + +To expand your investigation capabilities, you can purchase additional CU by enabling the Compute Unit add-on. After purchasing the additional CU, you can enable the add-on by selecting **Settings → Cortex XSIAM License → Addons**, hovering over the **Extended Compute Units** tile and clicking **Enable**. \ The Compute Unit add-on provides an additional 1 compute unit per day for a year, in addition to your free annual quota. For example, if you have allocated 1,825 free annual CU, with the add-on, you will have a total of 2,190 annual compute units. The Compute Unit add-on is calculated on an annual basis, starting from the procurement of your add-on license. The minimum purchase amount is 50 compute units. You can configure the daily consumption limit for your compute units according to your organizational needs and change it when needed. For example, you can set a lower limit on a daily basis, and during an incident investigation, you can change it to a higher limit that enables you to consume more compute units. Your unused compute unit balance cannot be transferred from one licensing period to the next. @@ -67,13 +71,17 @@ In the **Compute Units Usage** table, you can filter all the requests that were * For automated actions: Rule or playbook. * **Query/Prompt**: The query or prompt. * **Compute Unit Usage**: How many units were used. * **Category:** XQL Queries, Agents & LLM. * **Trigger Type:** The type of source of the query or prompt. For example, automation rule or playbook. * **Billable:** Whether the query was deducted from your compute units. Requests that are non-billable are displayed for informational purposes and do not affect your daily limit or compute units balance. * **Tenant:** Appears only in a Managed Security tenant. Displays which tenant executed the query. +{% hint style="info" %} +**NOTE:** For Managed Security tenants, select a tenant from the MSSP Tenant Selection drop-down menu to display information for that tenant. +{% endhint %} + ### Investigate the XQL API results. In the **Compute Units Usage** table, locate an XQL API query, right-click, and select **Show results**. The query is displayed in the query field of the Query Builder, where you can view the query results. For more information, see [How to build XQL queries](../../../reference-and-developer-docs/cortex-agentix-xql). -
▸ ▾ Get started with ITDR modified +2 −1 Adds a step: set up the CyberArk ISP integration, which collects the audit events for the analytics detectors.
xsiam/detect-investigate-and-respond-to-threats/identity-threat-module-itdr/get-started-with-itdrRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -6,17 +6,18 @@ description: >-# Get started with ITDR# Get started with ITDRTo deploy and configure the Identity Threat Detection and Response module features, follow the steps below.To deploy and configure the Identity Threat Detection and Response module features, follow the steps below.1. Activate the ITDR add-on license from Settings -> Cortex XSIAM License. This activates the identity analytics features automatically.1. Activate the ITDR add-on license from Settings -> Cortex XSIAM License. This activates the identity analytics features automatically.2. Activate and onboard the Cloud Identity Engine.2. Activate and onboard the Cloud Identity Engine.3. Set up the dedicated Identity permissions and roles in Settings -> Configurations -> Access Management -> Roles -> Identity Security. For more information, see RBAC in ITDR.3. Set up the dedicated Identity permissions and roles in Settings -> Configurations -> Access Management -> Roles -> Identity Security. For more information, see RBAC in ITDR.4. Configure Identity Profiles to unify AD-SPM, Conditional Access, and LDAP Protection controls in one centralized hub.4. Set up the CyberArk ISP integration which collects the audit events for the analytics detectors.5. Configure Identity Profiles to unify AD-SPM, Conditional Access, and LDAP Protection controls in one centralized hub.## Set up Identity Profiles## Set up Identity ProfilesThe Identity Profile centralizes identity security policies for Domain Controllers. It supports consistent security controls across your environment. After configuration, the profile must be mapped to policies for Domain Controller endpoints.The Identity Profile centralizes identity security policies for Domain Controllers. It supports consistent security controls across your environment. After configuration, the profile must be mapped to policies for Domain Controller endpoints.hint infohint info### Note### NoteShow markdown source
@@ -6,17 +6,18 @@ description: >- # Get started with ITDR To deploy and configure the Identity Threat Detection and Response module features, follow the steps below. 1. Activate the ITDR add-on license from **Settings -> Cortex XSIAM License**. This activates the identity analytics features automatically. 2. Activate and onboard the [Cloud Identity Engine](https://docs.paloaltonetworks.com/identity/activation-and-onboarding/get-started-with-the-cloud-identity-engine). 3. Set up the dedicated Identity permissions and roles in **Settings -> Configurations -> Access Management -> Roles -> Identity Security**. For more information, see [RBAC in ITDR](manage-role-based-access-control-rbac-in-itdr). -4. Configure Identity Profiles to unify AD-SPM, Conditional Access, and LDAP Protection controls in one centralized hub. +4. Set up the [CyberArk ISP integration](https://xsoar.pan.dev/docs/reference/integrations/cyber-ark-isp) which collects the audit events for the analytics detectors. +5. Configure Identity Profiles to unify AD-SPM, Conditional Access, and LDAP Protection controls in one centralized hub. ## Set up Identity Profiles The Identity Profile centralizes identity security policies for Domain Controllers. It supports consistent security controls across your environment. After configuration, the profile must be mapped to policies for Domain Controller endpoints. {% hint style="info" %} ### Note -
▸ ▾ System dashboards modified +1 −1
xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports/dashboard-reference/system-dashboardsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -5,9 +5,9 @@ description: >-------# System dashboards# System dashboardsSystem dashboards help you monitor and evaluate various aspects of your environment. You can access your default view by navigating to Dashboards & Reports → Dashboard. To change the displayed dashboard, click the dashboard name and select from the dashboard menu.System dashboards help you monitor and evaluate various aspects of your environment. You can access your default view by navigating to Dashboards & Reports → Dashboard. To change the displayed dashboard, click the dashboard name and select from the dashboard menu.Because system dashboards are managed by the platform and cannot be edited or deleted, you can duplicate any dashboard in the Dashboard Manager. This creates a customizable version you can modify freely while keeping the original template intact.Because system dashboards are managed by the platform and cannot be edited or deleted, you can duplicate any dashboard in the Dashboard Manager. This creates a customizable version you can modify freely while keeping the original template intact.Dashboard Improved Description Agent Management Track the status, content versions, and OS distribution of all deployed agents across your organization.
Note
Requires Cortex XSIAM Premium, Enterprise, or any license with the Enterprise Runtime or Cloud Runtime Security add-on.
AI Security Assess your organization’s AI ecosystem and security posture to guide governance decisions and prioritize risk-mitigation steps.
Note
For more details, see What is Cortex Cloud AI Security?.
API Security Management Identify and mitigate threats and vulnerabilities across cloud services by monitoring risky API funnels, regional attack patterns, attack traffic trends, and sensitive data exposure. Application Security Evaluate your application security posture through targeted insights into exposed assets, code vulnerabilities, and CI/CD pipeline issues. Attack Surface Management Pinpoint internet-exposed assets and analyze related exposure cases to reduce your external attack vector.
Note
Requires Cortex XSIAM Premium or any license with the Attack Surface Management (ASM) add-on.
Automation Insights Review high-level automation performance, tracking automatically closed issues and execution trends over time. Cloud Inventory Audit and manage your organization's cloud-based assets across all environments.
Note
Requires a Cortex XSIAM Enterprise Plus license.
Compliance Overview Review your organization’s compliance performance against industry standards and internal security frameworks.
Note
For more details, see Compliance Overview Dashboard.
Cortex Cloud Consumption Track your cloud consumption with a detailed breakdown by workload type, date range, and other usage details across all your cloud accounts.
Note
For more details, see Cortex Cloud Consumption.
Cloud Security Operations Assess and resolve high-impact cloud security issues quickly to maintain a strong security operational posture.
Note
For more details, see Cloud Security Operations.
Data Ingestion Monitor data ingestion rates, vendor/product breakdowns, and daily quota consumption across your system. For more information, see Data Ingestion.
Note
Data prior to July 2023 is inaccessible on this dashboard due to metric updates, but remains queryable via XQL on the metrics_center dataset.
Data Security Discover and visualize all your data assets across the different cloud services, which will help you understand where the sensitive data is, how it is used and how it is moving across the organization.
Note
For more details, see Cortex Data Security.
Identity Security Secure your identity estate by monitoring your identity inventory, detecting critical findings, identifying the top critical issues and findings in your environment, detecting risky identities, discovering admins and admins at risk, and analyzing 3rd-party access.
Note
For more details, see What is Cloud Identity Security?.
IT Metrics Analyze Cortex XDR agent performance metrics—including CPU/memory utilization, connectivity status, hard reboots, and application crashes.
Note
The Applications Crashing widget is supported for Windows agents only. Requires Cortex XSIAM Premium, Enterprise, or an Enterprise Runtime add-on.
KSPM (Kubernetes Security Posture Management) Investigate Kubernetes clusters, assets, and resources to locate unprotected areas, vulnerabilities, malware, and exposed secrets.
Note
Full access requires 'All assets' scoping or Instance Administrator privileges. Restricted access applies under granular SBAC scoping. For details, see Onboard the Kubernetes connector and Manage user scope.
MITRE ATT&CK Framework Coverage Review Cortex XSIAM's content and detection capabilities against the techniques and tactics of the MITRE ATT&CK framework.
Note
For more details, see Review MITRE ATT&CK framework coverage.
My Dashboard Manage personal case assignments and monitor individual Mean Time to Respond (MTTR) performance. Network Traffic Analysis (NTA) Analyze network traffic patterns and anomalies to highlight potential threats and unusual network behavior. NGFW Ingestion Track Next-Generation Firewall (NGFW) log ingestion statuses, daily quota consumption, and individual log type breakdowns. Risk Management Evaluate risk exposure by investigating compromised accounts and insider threats. The issues displayed in this dashboard are tagged by the research as Identity Threat issues or Identity Analytics issues. A case is displayed if any of its associated issues are tagged as an Identity threat or an Identity Analytics threat.
Note
Requires the ITDR add-on.
Security Manager Supervise operational case management and agent health across your environment. Monitor 30-day open cases by severity, top 10 open cases, and workload distribution by assignee (aged vs. total open cases), alongside top 5 agent version distributions and overall agent status breakdowns. Threat Intel Management Investigate malicious or suspicious indicators linked to active security cases.
Note
Requires the Cortex XSIAM Premium license or any other XSIAM license with the Threat Intel Management (TIM) add-on.
Troubleshooting Instances Diagnose integration failures by analyzing command and execution errors at the individual instance level. Troubleshooting Playbooks Debug playbook and task execution errors using focused runtime metrics and failure analysis. Dashboard Improved Description Agent Management Track the status, content versions, and OS distribution of all deployed agents across your organization.
Note
Requires Cortex XSIAM Premium, Enterprise, or any license with the Enterprise Runtime or Cloud Runtime Security add-on.
AI Security Assess your organization’s AI ecosystem and security posture to guide governance decisions and prioritize risk-mitigation steps.
Note
For more details, see What is Cortex Cloud AI Security?.
API Security Management Identify and mitigate threats and vulnerabilities across cloud services by monitoring risky API funnels, regional attack patterns, attack traffic trends, and sensitive data exposure. Application Security Evaluate your application security posture through targeted insights into exposed assets, code vulnerabilities, and CI/CD pipeline issues. Attack Surface Management Pinpoint internet-exposed assets and analyze related exposure cases to reduce your external attack vector.
Note
Requires Cortex XSIAM Premium or any license with the Attack Surface Management (ASM) add-on.
Automation Insights Review high-level automation performance, tracking automatically closed issues and execution trends over time. Cloud Inventory Audit and manage your organization's cloud-based assets across all environments.
Note
Requires a Cortex XSIAM Enterprise Plus license.
Compliance Overview Review your organization’s compliance performance against industry standards and internal security frameworks.
Note
For more details, see Compliance Overview Dashboard.
Cortex Cloud Consumption Track your cloud consumption with a detailed breakdown by workload type, date range, and other usage details across all your cloud accounts.
Note
For more details, see Cortex Cloud Consumption.
Cloud Security Operations Assess and resolve high-impact cloud security issues quickly to maintain a strong security operational posture.
Note
For more details, see Cloud Security Operations.
Data Ingestion Monitor data ingestion rates, vendor/product breakdowns, and daily quota consumption across your system. For more information, see Data Ingestion.
Note
Data prior to July 2023 is inaccessible on this dashboard due to metric updates, but remains queryable via XQL on the metrics_center dataset.
Data Security Discover and visualize all your data assets across the different cloud services, which will help you understand where the sensitive data is, how it is used and how it is moving across the organization.
Note
For more details, see Cortex Data Security.
Identity Security Secure your identity estate by monitoring your identity inventory, detecting critical findings, identifying the top critical issues and findings in your environment, detecting risky identities, discovering admins and admins at risk, and analyzing 3rd-party access.
Note
For more details, see What is Cloud Identity Security?.
IT Metrics Analyze Cortex XDR agent performance metrics—including CPU/memory utilization, connectivity status, hard reboots, and application crashes.
Note
The Applications Crashing widget is supported for Windows agents only. Requires Cortex XSIAM Premium, Enterprise, or an Enterprise Runtime add-on.
KSPM (Kubernetes Security Posture Management) Investigate Kubernetes clusters, assets, and resources to locate unprotected areas, vulnerabilities, malware, and exposed secrets.
Note
Full access requires 'All assets' scoping or Instance Administrator privileges. Restricted access applies under granular SBAC scoping. For details, see Onboard the Kubernetes connector and Manage user scope.
MITRE ATT&CK Framework Coverage Review Cortex XSIAM's content and detection capabilities against the techniques and tactics of the MITRE ATT&CK framework.
Note
For more details, see Review MITRE ATT&CK framework coverage.
My Dashboard Manage personal case assignments and monitor individual Mean Time to Respond (MTTR) performance. Network Traffic Analysis (NTA) Analyze network traffic patterns and anomalies to highlight potential threats and unusual network behavior. NGFW Ingestion Track Next-Generation Firewall (NGFW) log ingestion statuses, daily quota consumption, and individual log type breakdowns. Risk Management Evaluate risk exposure by investigating compromised accounts and insider threats. The issues displayed in this dashboard are tagged by the research as Identity Threat issues or Identity Analytics issues. A case is displayed if any of its associated issues are tagged as an Identity threat or an Identity Analytics threat.
Note
Requires the ITDR add-on.
Security Manager Supervise operational case management and agent health across your environment. Monitor 30-day open cases by severity, top 10 open cases, and workload distribution by assignee (aged vs. total open cases), alongside top 5 agent version distributions and overall agent status breakdowns. Threat Intel Management Investigate malicious or suspicious indicators linked to active security cases.
Note
Requires the Cortex XSIAM Premium license or any other XSIAM license with the Threat Intel Management (TIM) add-on.
Troubleshooting Instances Diagnose integration failures by analyzing command and execution errors at the individual instance level. Troubleshooting Playbooks Debug playbook and task execution errors using focused runtime metrics and failure analysis. Show markdown source
@@ -5,9 +5,9 @@ description: >- --- # System dashboards System dashboards help you monitor and evaluate various aspects of your environment. You can access your default view by navigating to **Dashboards & Reports → Dashboard**. To change the displayed dashboard, click the dashboard name and select from the dashboard menu. Because system dashboards are managed by the platform and cannot be edited or deleted, you can duplicate any dashboard in the **Dashboard Manager**. This creates a customizable version you can modify freely while keeping the original template intact. -<table><thead><tr><th width="135">Dashboard</th><th>Improved Description</th></tr></thead><tbody><tr><td><strong>Agent Management</strong></td><td><p><strong>Track</strong> the status, content versions, and OS distribution of all deployed agents across your organization.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires Cortex XSIAM Premium, Enterprise, or any license with the Enterprise Runtime or Cloud Runtime Security add-on.</p></div></td></tr><tr><td><strong>AI Security</strong></td><td><p><strong>Assess</strong> your organization’s AI ecosystem and security posture to guide governance decisions and prioritize risk-mitigation steps.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../../cloud-security/cortex-cloud-ai-security/what-is-cortex-cloud-ai-security">What is Cortex Cloud AI Security?</a>.</p></div></td></tr><tr><td><strong>API Security Management</strong></td><td><strong>Identify</strong> and mitigate threats and vulnerabilities across cloud services by monitoring risky API funnels, regional attack patterns, attack traffic trends, and sensitive data exposure.</td></tr><tr><td><strong>Application Security</strong></td><td><strong>Evaluate</strong> your application security posture through targeted insights into exposed assets, code vulnerabilities, and CI/CD pipeline issues.</td></tr><tr><td><strong>Attack Surface Management</strong></td><td><p><strong>Pinpoint</strong> internet-exposed assets and analyze related exposure cases to reduce your external attack vector.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires Cortex XSIAM Premium or any license with the Attack Surface Management (ASM) add-on.</p></div></td></tr><tr><td><strong>Automation Insights</strong></td><td><strong>Review</strong> high-level automation performance, tracking automatically closed issues and execution trends over time.</td></tr><tr><td><strong>Cloud Inventory</strong></td><td><p><strong>Audit</strong> and manage your organization's cloud-based assets across all environments.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires a Cortex XSIAM Enterprise Plus license.</p></div></td></tr><tr><td><strong>Compliance Overview</strong></td><td><p><strong>Review</strong> your organization’s compliance performance against industry standards and internal security frameworks.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../../cloud-security/monitor-and-track-compliance-adherence/compliance-overview-dashboard">Compliance Overview Dashboard</a>.</p></div></td></tr><tr><td><strong>Cortex Cloud Consumption</strong></td><td><p><strong>Track</strong> your cloud consumption with a detailed breakdown by workload type, date range, and other usage details across all your cloud accounts.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="system-dashboards/cortex-cloud-consumption">Cortex Cloud Consumption</a>.</p></div></td></tr><tr><td><strong>Cloud Security Operations</strong></td><td><p><strong>Assess</strong> and resolve high-impact cloud security issues quickly to maintain a strong security operational posture.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="system-dashboards/cloud-security-operations">Cloud Security Operations</a>.</p></div></td></tr><tr><td><strong>Data Ingestion</strong></td><td><p><strong>Monitor</strong> data ingestion rates, vendor/product breakdowns, and daily quota consumption across your system. For more information, see <a href="system-dashboards/data-ingestion">Data Ingestion</a>.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Data prior to July 2023 is inaccessible on this dashboard due to metric updates, but remains queryable via XQL on the metrics_center dataset.</p></div></td></tr><tr><td><strong>Data Security</strong></td><td><p><strong>Discover</strong> and visualize all your data assets across the different cloud services, which will help you understand where the sensitive data is, how it is used and how it is moving across the organization.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../../data-security/cortex-data-security">Cortex Data Security</a>.</p></div></td></tr><tr><td><strong>Identity Security</strong></td><td><p><strong>Secure</strong> your identity estate by monitoring your identity inventory, detecting critical findings, identifying the top critical issues and findings in your environment, detecting risky identities, discovering admins and admins at risk, and analyzing 3rd-party access.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../../cloud-security/cortex-cloud-identity-security/what-is-cortex-cloud-identity-security">What is Cloud Identity Security?</a>.</p></div></td></tr><tr><td><strong>IT Metrics</strong></td><td><p><strong>Analyze</strong> Cortex XDR agent performance metrics—including CPU/memory utilization, connectivity status, hard reboots, and application crashes.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>The Applications Crashing widget is supported for Windows agents only. Requires Cortex XSIAM Premium, Enterprise, or an Enterprise Runtime add-on.</p></div></td></tr><tr><td><strong>KSPM (Kubernetes Security Posture Management)</strong></td><td><p><strong>Investigate</strong> Kubernetes clusters, assets, and resources to locate unprotected areas, vulnerabilities, malware, and exposed secrets.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Full access requires 'All assets' scoping or Instance Administrator privileges. Restricted access applies under granular SBAC scoping. For details, see <a href="../../../configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kubernetes/onboard-the-kubernetes-connector">Onboard the Kubernetes connector</a> and <a href="../../../onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-user-scope">Manage user scope</a>.</p></div></td></tr><tr><td><strong>MITRE ATT&CK Framework Coverage</strong></td><td><p><strong>Review</strong> Cortex XSIAM's content and detection capabilities against the techniques and tactics of the MITRE ATT&CK framework.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../threat-management/analytics/analytics-overview/review-mitre-att-and-ck-framework-coverage">Review MITRE ATT&CK framework coverage</a>.</p></div></td></tr><tr><td><strong>My Dashboard</strong></td><td><strong>Manage</strong> personal case assignments and monitor individual Mean Time to Respond (MTTR) performance.</td></tr><tr><td><strong>Network Traffic Analysis (NTA)</strong></td><td><strong>Analyze</strong> network traffic patterns and anomalies to highlight potential threats and unusual network behavior.</td></tr><tr><td><strong>NGFW Ingestion</strong></td><td><strong>Track</strong> Next-Generation Firewall (NGFW) log ingestion statuses, daily quota consumption, and individual log type breakdowns.</td></tr><tr><td><strong>Risk Management</strong></td><td><p><strong>Evaluate</strong> risk exposure by investigating compromised accounts and insider threats. The issues displayed in this dashboard are tagged by the research as Identity Threat issues or Identity Analytics issues. A case is displayed if any of its associated issues are tagged as an Identity threat or an Identity Analytics threat.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires the ITDR add-on.</p></div></td></tr><tr><td><strong>Security Manager</strong></td><td><strong>Supervise</strong> operational case management and agent health across your environment. Monitor 30-day open cases by severity, top 10 open cases, and workload distribution by assignee (aged vs. total open cases), alongside top 5 agent version distributions and overall agent status breakdowns.</td></tr><tr><td><strong>Threat Intel Management</strong></td><td><p><strong>Investigate</strong> malicious or suspicious indicators linked to active security cases.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires the Cortex XSIAM Premium license or any other XSIAM license with the Threat Intel Management (TIM) add-on.</p></div></td></tr><tr><td><strong>Troubleshooting Instances</strong></td><td><strong>Diagnose</strong> integration failures by analyzing command and execution errors at the individual instance level.</td></tr><tr><td><strong>Troubleshooting Playbooks</strong></td><td><strong>Debug</strong> playbook and task execution errors using focused runtime metrics and failure analysis.</td></tr></tbody></table> +<table><thead><tr><th width="135">Dashboard</th><th>Improved Description</th></tr></thead><tbody><tr><td><strong>Agent Management</strong></td><td><p><strong>Track</strong> the status, content versions, and OS distribution of all deployed agents across your organization.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires Cortex XSIAM Premium, Enterprise, or any license with the Enterprise Runtime or Cloud Runtime Security add-on.</p></div></td></tr><tr><td><strong>AI Security</strong></td><td><p><strong>Assess</strong> your organization’s AI ecosystem and security posture to guide governance decisions and prioritize risk-mitigation steps.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../../cloud-security/cortex-cloud-ai-security/what-is-cortex-cloud-ai-security">What is Cortex Cloud AI Security?</a>.</p></div></td></tr><tr><td><strong>API Security Management</strong></td><td><strong>Identify</strong> and mitigate threats and vulnerabilities across cloud services by monitoring risky API funnels, regional attack patterns, attack traffic trends, and sensitive data exposure.</td></tr><tr><td><strong>Application Security</strong></td><td><strong>Evaluate</strong> your application security posture through targeted insights into exposed assets, code vulnerabilities, and CI/CD pipeline issues.</td></tr><tr><td><strong>Attack Surface Management</strong></td><td><p><strong>Pinpoint</strong> internet-exposed assets and analyze related exposure cases to reduce your external attack vector.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires Cortex XSIAM Premium or any license with the Attack Surface Management (ASM) add-on.</p></div></td></tr><tr><td><strong>Automation Insights</strong></td><td><strong>Review</strong> high-level automation performance, tracking automatically closed issues and execution trends over time.</td></tr><tr><td><strong>Cloud Inventory</strong></td><td><p><strong>Audit</strong> and manage your organization's cloud-based assets across all environments.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires a Cortex XSIAM Enterprise Plus license.</p></div></td></tr><tr><td><strong>Compliance Overview</strong></td><td><p><strong>Review</strong> your organization’s compliance performance against industry standards and internal security frameworks.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../../cloud-security/monitor-and-track-compliance-adherence/compliance-overview-dashboard">Compliance Overview Dashboard</a>.</p></div></td></tr><tr><td><strong>Cortex Cloud Consumption</strong></td><td><p><strong>Track</strong> your cloud consumption with a detailed breakdown by workload type, date range, and other usage details across all your cloud accounts.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="system-dashboards/cortex-cloud-consumption">Cortex Cloud Consumption</a>.</p></div></td></tr><tr><td><strong>Cloud Security Operations</strong></td><td><p><strong>Assess</strong> and resolve high-impact cloud security issues quickly to maintain a strong security operational posture.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="system-dashboards/cloud-security-operations">Cloud Security Operations</a>.</p></div></td></tr><tr><td><strong>Data Ingestion</strong></td><td><p><strong>Monitor</strong> data ingestion rates, vendor/product breakdowns, and daily quota consumption across your system. For more information, see <a href="system-dashboards/data-ingestion">Data Ingestion</a>.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Data prior to July 2023 is inaccessible on this dashboard due to metric updates, but remains queryable via XQL on the metrics_center dataset.</p></div></td></tr><tr><td><strong>Data Security</strong></td><td><p><strong>Discover</strong> and visualize all your data assets across the different cloud services, which will help you understand where the sensitive data is, how it is used and how it is moving across the organization.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../../data-security/cortex-data-security">Cortex Data Security</a>.</p></div></td></tr><tr><td><strong>Identity Security</strong></td><td><p><strong>Secure</strong> your identity estate by monitoring your identity inventory, detecting critical findings, identifying the top critical issues and findings in your environment, detecting risky identities, discovering admins and admins at risk, and analyzing 3rd-party access.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../../cloud-security/cortex-cloud-identity-security/what-is-cortex-cloud-identity-security">What is Cloud Identity Security?</a>.</p></div></td></tr><tr><td><strong>IT Metrics</strong></td><td><p><strong>Analyze</strong> Cortex XDR agent performance metrics—including CPU/memory utilization, connectivity status, hard reboots, and application crashes.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>The Applications Crashing widget is supported for Windows agents only. Requires Cortex XSIAM Premium, Enterprise, or an Enterprise Runtime add-on.</p></div></td></tr><tr><td><strong>KSPM (Kubernetes Security Posture Management)</strong></td><td><p><strong>Investigate</strong> Kubernetes clusters, assets, and resources to locate unprotected areas, vulnerabilities, malware, and exposed secrets.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Full access requires 'All assets' scoping or Instance Administrator privileges. Restricted access applies under granular SBAC scoping. For details, see <a href="../../../configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/kubernetes/onboard-the-kubernetes-connector">Onboard the Kubernetes connector</a> and <a href="../../../onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-user-scope">Manage user scope</a>.</p></div></td></tr><tr><td><strong>MITRE ATT&CK Framework Coverage</strong></td><td><p><strong>Review</strong> Cortex XSIAM's content and detection capabilities against the techniques and tactics of the MITRE ATT&CK framework.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>For more details, see <a href="../../threat-management/analytics/review-mitre-att-and-ck-framework-coverage">Review MITRE ATT&CK framework coverage</a>.</p></div></td></tr><tr><td><strong>My Dashboard</strong></td><td><strong>Manage</strong> personal case assignments and monitor individual Mean Time to Respond (MTTR) performance.</td></tr><tr><td><strong>Network Traffic Analysis (NTA)</strong></td><td><strong>Analyze</strong> network traffic patterns and anomalies to highlight potential threats and unusual network behavior.</td></tr><tr><td><strong>NGFW Ingestion</strong></td><td><strong>Track</strong> Next-Generation Firewall (NGFW) log ingestion statuses, daily quota consumption, and individual log type breakdowns.</td></tr><tr><td><strong>Risk Management</strong></td><td><p><strong>Evaluate</strong> risk exposure by investigating compromised accounts and insider threats. The issues displayed in this dashboard are tagged by the research as Identity Threat issues or Identity Analytics issues. A case is displayed if any of its associated issues are tagged as an Identity threat or an Identity Analytics threat.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires the ITDR add-on.</p></div></td></tr><tr><td><strong>Security Manager</strong></td><td><strong>Supervise</strong> operational case management and agent health across your environment. Monitor 30-day open cases by severity, top 10 open cases, and workload distribution by assignee (aged vs. total open cases), alongside top 5 agent version distributions and overall agent status breakdowns.</td></tr><tr><td><strong>Threat Intel Management</strong></td><td><p><strong>Investigate</strong> malicious or suspicious indicators linked to active security cases.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Requires the Cortex XSIAM Premium license or any other XSIAM license with the Threat Intel Management (TIM) add-on.</p></div></td></tr><tr><td><strong>Troubleshooting Instances</strong></td><td><strong>Diagnose</strong> integration failures by analyzing command and execution errors at the individual instance level.</td></tr><tr><td><strong>Troubleshooting Playbooks</strong></td><td><strong>Debug</strong> playbook and task execution errors using focused runtime metrics and failure analysis.</td></tr></tbody></table>
-
▸ ▾ Analytics modified +9 −9 Every link in the Explore analytics list drops the analytics-overview segment after the twelve child pages moved up a level.
xsiam/detect-investigate-and-respond-to-threats/threat-management/analyticsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -8,19 +8,19 @@ description: >-Cortex XSIAM Analytics analyzes sensor data, establishes behavioral baselines, and creates issues for suspicious activity.Cortex XSIAM Analytics analyzes sensor data, establishes behavioral baselines, and creates issues for suspicious activity.Use Analytics rules and BIOCs to investigate anomalies across endpoints, networks, and identities.Use Analytics rules and BIOCs to investigate anomalies across endpoints, networks, and identities.### Explore analytics### Explore analytics• analytics-overview• analytics-overview• analytics-engine• analytics-engine• analytics-sensors• analytics-sensors• coverage-of-mitre-attack-tactics• coverage-of-mitre-attack-tactics• review-mitre-att-and-ck-framework-coverage• review-mitre-att-and-ck-framework-coverage• analytics-detection-time-intervals• analytics-detection-time-intervals• analytics-issues-and-analytics-biocs• analytics-issues-and-analytics-biocs• view-and-manage-analytics-rules• view-and-manage-analytics-rules• identity-analytics• identity-analytics• ai-detection-and-response-in-cortex-xsiam-beta• ai-detection-and-response-in-cortex-xsiam-beta
Show markdown source
@@ -8,19 +8,19 @@ description: >- Cortex XSIAM Analytics analyzes sensor data, establishes behavioral baselines, and creates issues for suspicious activity. Use Analytics rules and BIOCs to investigate anomalies across endpoints, networks, and identities. ### Explore analytics * [analytics-overview](analytics/analytics-overview "mention") -* [analytics-engine](analytics/analytics-overview/analytics-engine "mention") -* [analytics-sensors](analytics/analytics-overview/analytics-sensors "mention") -* [coverage-of-mitre-attack-tactics](analytics/analytics-overview/coverage-of-mitre-attack-tactics "mention") -* [review-mitre-att-and-ck-framework-coverage](analytics/analytics-overview/review-mitre-att-and-ck-framework-coverage "mention") -* [analytics-detection-time-intervals](analytics/analytics-overview/analytics-detection-time-intervals "mention") -* [analytics-issues-and-analytics-biocs](analytics/analytics-overview/analytics-issues-and-analytics-biocs "mention") -* [view-and-manage-analytics-rules](analytics/analytics-overview/view-and-manage-analytics-rules "mention") -* [identity-analytics](analytics/analytics-overview/identity-analytics "mention") -* [ai-detection-and-response-in-cortex-xsiam-beta](analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta "mention") +* [analytics-engine](analytics/analytics-engine "mention") +* [analytics-sensors](analytics/analytics-sensors "mention") +* [coverage-of-mitre-attack-tactics](analytics/coverage-of-mitre-attack-tactics "mention") +* [review-mitre-att-and-ck-framework-coverage](analytics/review-mitre-att-and-ck-framework-coverage "mention") +* [analytics-detection-time-intervals](analytics/analytics-detection-time-intervals "mention") +* [analytics-issues-and-analytics-biocs](analytics/analytics-issues-and-analytics-biocs "mention") +* [view-and-manage-analytics-rules](analytics/view-and-manage-analytics-rules "mention") +* [identity-analytics](analytics/identity-analytics "mention") +* [ai-detection-and-response-in-cortex-xsiam-beta](analytics/ai-detection-and-response-in-cortex-xsiam-beta "mention") ***
-
▸ ▾ AI Detection & Response in Cortex XSIAM renamed +0 −0 Moved out of Analytics overview along with its prompt-log collection subtree; the relative links inside were repointed one level shallower.
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-betaRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta.md -
▸ ▾ Collect prompt logs renamed +1 −1
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logsRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs.mdBefore After@@ -3,14 +3,14 @@ description: >-Collect prompt logs in Cortex XSIAM to support AI Detection & ResponseCollect prompt logs in Cortex XSIAM to support AI Detection & Responsemonitoring and investigations.monitoring and investigations.------# Collect prompt logs# Collect prompt logsCortex XSIAM collects prompt logs from your cloud accounts using existing data collectors. Currently, AWS and Azure are supported by Cortex XSIAM for prompt log collection. At this time, GCP does not have a storage solution for AI prompts that allows Cortex XSIAM to ingest them.Cortex XSIAM collects prompt logs from your cloud accounts using existing data collectors. Currently, AWS and Azure are supported by Cortex XSIAM for prompt log collection. At this time, GCP does not have a storage solution for AI prompts that allows Cortex XSIAM to ingest them.For details on dataset retention, see Cortex XSIAM product licenses.For details on dataset retention, see Cortex XSIAM product licenses.Follow these procedures to enable prompt log collection in AWS and Azure:Follow these procedures to enable prompt log collection in AWS and Azure:• Prompt log collection in AWS• Prompt log collection in AWS• Enable prompt log collection in Azure• Enable prompt log collection in AzureShow markdown source
@@ -3,14 +3,14 @@ description: >- Collect prompt logs in Cortex XSIAM to support AI Detection & Response monitoring and investigations. --- # Collect prompt logs Cortex XSIAM collects prompt logs from your cloud accounts using existing data collectors. Currently, AWS and Azure are supported by Cortex XSIAM for prompt log collection. At this time, GCP does not have a storage solution for AI prompts that allows Cortex XSIAM to ingest them. -For details on dataset retention, see [Cortex XSIAM product licenses](../../../../../learn-about-cortex-xsiam/cortex-xsiam-product-licenses). +For details on dataset retention, see [Cortex XSIAM product licenses](../../../../learn-about-cortex-xsiam/cortex-xsiam-product-licenses). Follow these procedures to enable prompt log collection in AWS and Azure: * [Prompt log collection in AWS](collect-prompt-logs/prompt-log-collection-in-aws) * [Enable prompt log collection in Azure](collect-prompt-logs/enable-prompt-log-collection-in-azure)
-
▸ ▾ Enable prompt log collection in Azure renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azureRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure.md -
▸ ▾ Configure diagnostic settings renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-diagnostic-settingsRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-diagnostic-settings.md -
▸ ▾ Configure the Azure Event Hub collection in Cortex XSIAM renamed +1 −1
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-the-azure-event-hub-collection-in-cortex-xsiamRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/configure-the-azure-event-hub-collection-in-cortex-xsiam.mdBefore After@@ -1,9 +1,9 @@------description: >-description: >-Configure Azure Event Hub collection in Cortex XSIAM to ingest prompt logs forConfigure Azure Event Hub collection in Cortex XSIAM to ingest prompt logs forAI Detection & Response.AI Detection & Response.------# Configure the Azure Event Hub collection in Cortex XSIAM# Configure the Azure Event Hub collection in Cortex XSIAMFor instructions on ingesting prompt logs from Microsoft Azure Event Hub, see Ingest logs from Microsoft Azure Event Hub.For instructions on ingesting prompt logs from Microsoft Azure Event Hub, see Ingest logs from Microsoft Azure Event Hub.Show markdown source
@@ -1,9 +1,9 @@ --- description: >- Configure Azure Event Hub collection in Cortex XSIAM to ingest prompt logs for AI Detection & Response. --- # Configure the Azure Event Hub collection in Cortex XSIAM -For instructions on ingesting prompt logs from Microsoft Azure Event Hub, see [Ingest logs from Microsoft Azure Event Hub](../../../../../../../configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-event-hub/ingest-logs-from-microsoft-azure-event-hub). +For instructions on ingesting prompt logs from Microsoft Azure Event Hub, see [Ingest logs from Microsoft Azure Event Hub](../../../../../../configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/microsoft/azure-event-hub/ingest-logs-from-microsoft-azure-event-hub).
-
▸ ▾ Log HTTP data renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/log-http-dataRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/log-http-data.md -
▸ ▾ Set up prompt logging renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/set-up-prompt-loggingRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/enable-prompt-log-collection-in-azure/set-up-prompt-logging.md -
▸ ▾ Prompt log collection in AWS renamed +2 −2
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-awsRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/collect-prompt-logs/prompt-log-collection-in-aws.mdBefore After@@ -5,13 +5,13 @@ description: >-------# Prompt log collection in AWS# Prompt log collection in AWSAmazon Bedrock allows you to save prompt logs to Amazon S3 or Amazon CloudWatch. For details on how to configure invocation logging using CloudWatch Logs or Amazon S3, see the AWS documentation: Model invocation logging.Amazon Bedrock allows you to save prompt logs to Amazon S3 or Amazon CloudWatch. For details on how to configure invocation logging using CloudWatch Logs or Amazon S3, see the AWS documentation: Model invocation logging.Ingest prompt logs from Amazon S3Ingest prompt logs from Amazon S3For instructions on ingesting prompt logs from Amazon S3, see Ingest generic logs from Amazon S3. In step 7, select Prompt logs as the log type.For instructions on ingesting prompt logs from Amazon S3, see Ingest generic logs from Amazon S3. In step 7, select Prompt logs as the log type.Ingest prompt logs from Amazon CloudWatchIngest prompt logs from Amazon CloudWatchFor instructions on ingesting prompt logs from Amazon CloudWatch, see Ingest logs from Amazon CloudWatch. In step 1.d, select Prompt logs as the log type.For instructions on ingesting prompt logs from Amazon CloudWatch, see Ingest logs from Amazon CloudWatch. In step 1.d, select Prompt logs as the log type.Show markdown source
@@ -5,13 +5,13 @@ description: >- --- # Prompt log collection in AWS Amazon Bedrock allows you to save prompt logs to Amazon S3 or Amazon CloudWatch. For details on how to configure invocation logging using CloudWatch Logs or Amazon S3, see the AWS documentation: [Model invocation logging](https://docs.aws.amazon.com/bedrock/latest/userguide/model-invocation-logging.html). **Ingest prompt logs from Amazon S3** -For instructions on ingesting prompt logs from Amazon S3, see [Ingest generic logs from Amazon S3](../../../../../../configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-generic-logs-from-amazon-s3). In step 7, select **Prompt logs** as the log type. +For instructions on ingesting prompt logs from Amazon S3, see [Ingest generic logs from Amazon S3](../../../../../configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-generic-logs-from-amazon-s3). In step 7, select **Prompt logs** as the log type. **Ingest prompt logs from Amazon CloudWatch** -For instructions on ingesting prompt logs from Amazon CloudWatch, see [Ingest logs from Amazon CloudWatch](../../../../../../configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-cloud-watch/ingest-logs-from-amazon-cloudwatch). In step 1.d, select **Prompt logs** as the log type. +For instructions on ingesting prompt logs from Amazon CloudWatch, see [Ingest logs from Amazon CloudWatch](../../../../../configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-cloud-watch/ingest-logs-from-amazon-cloudwatch). In step 1.d, select **Prompt logs** as the log type.
-
▸ ▾ Data sources and supported services renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/ai-detection-and-response-in-cortex-xsiam-beta/data-sources-and-supported-servicesRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/ai-detection-and-response-in-cortex-xsiam-beta/data-sources-and-supported-services.md -
▸ ▾ Analytics detection time intervals renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-detection-time-intervalsRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-detection-time-intervals.md -
▸ ▾ Analytics engine renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-engineRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-engine.md -
▸ ▾ Analytics issues and Analytics BIOCs renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-issues-and-analytics-biocsRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-issues-and-analytics-biocs.md -
▸ ▾ Analytics sensors renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-sensorsRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/analytics-sensors.md -
▸ ▾ Coverage of MITRE Attack tactics renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/coverage-of-mitre-attack-tacticsRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/coverage-of-mitre-attack-tactics.md -
▸ ▾ Identity Analytics renamed +1 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/identity-analyticsRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/identity-analytics.mdBefore After@@ -11,8 +11,9 @@ Cortex XSIAM enables you to investigate suspicious user activity information usiTo easily track the issues and Analytics BIOC rules, Cortex XSIAM displays an Identity Analytics tag in the Issues table > Issue Name field and Analytics BIOC Rules table > Name field. In the Analytics Issue View, when selecting the User node, Cortex XSIAM details the Active Directory group, organizational unit, role, logins, hosts, alerts, and process executions associated with the user.To easily track the issues and Analytics BIOC rules, Cortex XSIAM displays an Identity Analytics tag in the Issues table > Issue Name field and Analytics BIOC Rules table > Name field. In the Analytics Issue View, when selecting the User node, Cortex XSIAM details the Active Directory group, organizational unit, role, logins, hosts, alerts, and process executions associated with the user.To enable Identity Analytics, you must first:To enable Identity Analytics, you must first:• Set Up Cloud Identity Engine (formerly Directory Sync Services (DSS))• Set Up Cloud Identity Engine (formerly Directory Sync Services (DSS))• Activate Cortex XSIAM Analytics• Activate Cortex XSIAM AnalyticsAfter configuring your Cloud Identity Engine instance and Cortex XSIAM Analytics, select Settings (
) → Configurations → Cortex XSIAM - Analytics, and in the Featured in Analytics section, Enable Identity Analytics.
After configuring your Cloud Identity Engine instance and Cortex XSIAM Analytics, select Settings (
) → Configurations → Cortex XSIAM - Analytics, and in the Featured in Analytics section, Enable Identity Analytics.
Show markdown source
@@ -11,8 +11,9 @@ Cortex XSIAM enables you to investigate suspicious user activity information usi To easily track the issues and Analytics BIOC rules, Cortex XSIAM displays an **Identity Analytics** tag in the **Issues** table > **Issue Name** field and **Analytics BIOC Rules** table > **Name** field. In the **Analytics Issue View**, when selecting the **User** node, Cortex XSIAM details the Active Directory group, organizational unit, role, logins, hosts, alerts, and process executions associated with the user. To enable Identity Analytics, you must first: * Set Up Cloud Identity Engine (formerly Directory Sync Services (DSS)) * Activate Cortex XSIAM Analytics After configuring your Cloud Identity Engine instance and Cortex XSIAM Analytics, select **Settings (**<img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2Fgit-blob-815034b52feae75eb9d9eda9624f792871a6285b%2F0c18f4123ddc2dd785e1bb5b02b1bb604d2bf5730d312da4aa43ee3a67c77aca.png?alt=media" alt="403822_spr.png" data-size="line">**)** → **Configurations** → **Cortex XSIAM - Analytics**, and in the **Featured in Analytics** section, **Enable** Identity Analytics. +
-
▸ ▾ Review MITRE ATT&CK framework coverage renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/review-mitre-att-and-ck-framework-coverageRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/review-mitre-att-and-ck-framework-coverage.md -
▸ ▾ View and manage Analytics rules renamed +0 −0
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/view-and-manage-analytics-rulesRead it on the Cortex docs portal ↗ This file's diff on GitHub ↗ moved from
xsiam/detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/view-and-manage-analytics-rules.md -
▸ ▾ What are detection rules? modified +1 −1
xsiam/detect-investigate-and-respond-to-threats/threat-management/detection-rules/what-are-detection-rulesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -4,10 +4,10 @@ description: >-and generating issues.and generating issues.------# What are detection rules?# What are detection rules?Cortex XSIAM uses rules to detect threats in your network and to generate issues. You can add specific detection rules for which you want Cortex XSIAM to generate issues. The following are the different types of rules available:Cortex XSIAM uses rules to detect threats in your network and to generate issues. You can add specific detection rules for which you want Cortex XSIAM to generate issues. The following are the different types of rules available:• Indicators of compromise (IOCs): IOCs are used to alert for known artifacts that are considered malicious or suspicious. IOCs are static, simple, and based on the detection of criteria such as SHA256 hashes, IP addresses and domains, file names, and paths. You create IOC rules based on information you gather from various threat-intelligence feeds or as a result of an investigation within Cortex XSIAM. For example, if you find out that a certain ransomware uses a certain file hash, you can add the file hash as an IOC and generate an issue if it is detected.• Indicators of compromise (IOCs): IOCs are used to alert for known artifacts that are considered malicious or suspicious. IOCs are static, simple, and based on the detection of criteria such as SHA256 hashes, IP addresses and domains, file names, and paths. You create IOC rules based on information you gather from various threat-intelligence feeds or as a result of an investigation within Cortex XSIAM. For example, if you find out that a certain ransomware uses a certain file hash, you can add the file hash as an IOC and generate an issue if it is detected.• Behavioral indicators of compromise (BIOCs): BIOCs detect suspicious behavior. As you identify specific activities (network, process, file, registry, etc) that indicate a threat, you create BIOCs that can alert you when the behavior is detected. If you enable Cortex XSIAM Analytics, Cortex XSIAM can use Analytics BIOCs (ABIOCs) to establish baseline behavior and detect any deviation from this behavior.• Behavioral indicators of compromise (BIOCs): BIOCs detect suspicious behavior. As you identify specific activities (network, process, file, registry, etc) that indicate a threat, you create BIOCs that can alert you when the behavior is detected. If you enable Cortex XSIAM Analytics, Cortex XSIAM can use Analytics BIOCs (ABIOCs) to establish baseline behavior and detect any deviation from this behavior.• Correlation Rules: Correlation rules help you analyze the relationship between multiple events from multiple sources by using the Cortex Query Language (XQL) based engine.• Correlation Rules: Correlation rules help you analyze the relationship between multiple events from multiple sources by using the Cortex Query Language (XQL) based engine.Show markdown source
@@ -4,10 +4,10 @@ description: >- and generating issues. --- # What are detection rules? Cortex XSIAM uses rules to detect threats in your network and to generate issues. You can add specific detection rules for which you want Cortex XSIAM to generate issues. The following are the different types of rules available: * **Indicators of compromise (IOCs)**: IOCs are used to alert for known artifacts that are considered malicious or suspicious. IOCs are static, simple, and based on the detection of criteria such as SHA256 hashes, IP addresses and domains, file names, and paths. You create IOC rules based on information you gather from various threat-intelligence feeds or as a result of an investigation within Cortex XSIAM. For example, if you find out that a certain ransomware uses a certain file hash, you can add the file hash as an IOC and generate an issue if it is detected. -* **Behavioral indicators of compromise (BIOCs)**: BIOCs detect suspicious behavior. As you identify specific activities (network, process, file, registry, etc) that indicate a threat, you create BIOCs that can alert you when the behavior is detected. If you enable **Cortex XSIAM Analytics**, Cortex XSIAM can use [Analytics BIOCs](../analytics/analytics-overview/analytics-issues-and-analytics-biocs) (ABIOCs) to establish baseline behavior and detect any deviation from this behavior. +* **Behavioral indicators of compromise (BIOCs)**: BIOCs detect suspicious behavior. As you identify specific activities (network, process, file, registry, etc) that indicate a threat, you create BIOCs that can alert you when the behavior is detected. If you enable **Cortex XSIAM Analytics**, Cortex XSIAM can use [Analytics BIOCs](../analytics/analytics-issues-and-analytics-biocs) (ABIOCs) to establish baseline behavior and detect any deviation from this behavior. * **Correlation Rules**: Correlation rules help you analyze the relationship between multiple events from multiple sources by using the Cortex Query Language (XQL) based engine.
-
▸ ▾ Cortex XSIAM onboarding checklist modified +1 −1
xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-onboarding-checklistRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -18,11 +18,11 @@ This checklist does not include any specific Cloud Security requirements. If youThis deployment phase sets up Cortex XSIAM infrastructure, data pipelines, endpoint protection, and security analytics.This deployment phase sets up Cortex XSIAM infrastructure, data pipelines, endpoint protection, and security analytics.Step│Details│See MoreStep│Details│See More| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ || ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |- Activation and initial setup
✅ Enable access to required PANW resources and set up encryption keys (BYOK), if required.
✅ Assign initial administrator and analyst-type user roles (Responder/Investigator), create user groups, and assign roles to those groups (recommended) to a limited number of users initially. You can update this later.
✅ Set up access through the Customer Support Portal or SAML single sign-on.
│Activate Cortex XSIAM
Enable access to required PANW resources
Set up users and roles
Set up authentication- Activation and initial setup
✅ Enable access to required PANW resources and set up encryption keys (BYOK), if required.
✅ Assign initial administrator and analyst-type user roles (Responder/Investigator), create user groups, and assign roles to those groups (recommended) to a limited number of users initially. You can update this later.
✅ Set up access through the Customer Support Portal or SAML single sign-on.
│Activate Cortex XSIAM
Enable access to required PANW resources
Set up users and roles
Set up authentication- Configure content
Use the Data Sources Onboarding wizard to configure the following:
✅ Priority content:
- Configure network security data, such as Palo Alto Networks Next-Generation Firewalls, and network devices.
- Configure identity and user data. Install the Cloud Identity Engine (optional and highly recommended), which provides the necessary Active Directory or Microsoft Entra ID/Okta context (user names, group membership, computer names) to map a raw event (for example, an IP address) to a user or asset.
✅ Highly recommended content:
- Connect cloud audit logs for the most critical providers, such as AWS CloudTrail, Azure Activity Logs, and Google Cloud Audit Logs, directly to Cortex XSIAM.
- Configure/enable a key Threat Intelligence feed, such as the Unit 42 Intelligence feed, to enrich incoming issues. This ensures that as soon as a log/alert hits the Data Lake, it has the latest malicious context.
- Configure content
Use the Data Sources Onboarding wizard to configure the following:
✅ Priority content:
- Configure network security data, such as Palo Alto Networks Next-Generation Firewalls, and network devices.
- Configure identity and user data. Install the Cloud Identity Engine (optional and highly recommended), which provides the necessary Active Directory or Microsoft Entra ID/Okta context (user names, group membership, computer names) to map a raw event (for example, an IP address) to a user or asset.
✅ Highly recommended content:
- Connect cloud audit logs for the most critical providers, such as AWS CloudTrail, Azure Activity Logs, and Google Cloud Audit Logs, directly to Cortex XSIAM.
- Configure/enable a key Threat Intelligence feed, such as the Unit 42 Intelligence feed, to enrich incoming issues. This ensures that as soon as a log/alert hits the Data Lake, it has the latest malicious context.
- Deploy the XDR agent
✅ After testing expected agent behavior and performance, review and select default endpoint security profiles (Exploit, Malware, Restrictions, Agent Settings, Exceptions) to begin protecting your endpoints from threats immediately. Once endpoints are deployed and start collecting data, you can make any necessary adjustments to these rules and policies.
✅ Verify endpoint data collection (logs, alerts, events) is flowing from deployed agents to the XSIAM Data Lake. After deploying the agents to the pilot group, set up data collection to analyze the data.
This provides granular event data (process execution, file activity, registry changes, network connections) necessary for EDR/XDR detection and Behavioral Indicators of Compromise (BIOCs).
│- Deploy the XDR agent
✅ After testing expected agent behavior and performance, review and select default endpoint security profiles (Exploit, Malware, Restrictions, Agent Settings, Exceptions) to begin protecting your endpoints from threats immediately. Once endpoints are deployed and start collecting data, you can make any necessary adjustments to these rules and policies.
✅ Verify endpoint data collection (logs, alerts, events) is flowing from deployed agents to the XSIAM Data Lake. After deploying the agents to the pilot group, set up data collection to analyze the data.
This provides granular event data (process execution, file activity, registry changes, network connections) necessary for EDR/XDR detection and Behavioral Indicators of Compromise (BIOCs).
│- Enable Analytics and Identity Analytics
The analytics engine accesses your logs as they are streamed to Cortex XSIAM, including firewall data, and analyzes them as soon as they arrive.
You need EDR or network logs from at least 30 endpoints over a minimum of 2 weeks, or Cloud audit logs over a minimum of 2 weeks.
✅ Enable Identity Analytics, which focuses on user behavior that is critical since attackers primarily target credentials. It has two main functions:
- User/Entity Behavior Analytics (UEBA): Profiles users, hosts, and groups based on identity data and flags anomalies like a user logging in from a new country (Impossible Traveler), accessing an unusual database, or transferring a massive file volume outside of their norm.
Investigation context: When an issue fires, Identity Analytics ensures that the relevant user profile details, recent activities, and group membership are automatically aggregated and displayed with a user-based Analytics type issue and Analytics BIOC rule
The Cloud Identity Engine must be set up.
✅ Enable the Identity Threat Detection and Response (ITDR) add-on (optional), which enhances the analytics baseline capabilities to include the Directory Infrastructure. This enables the detection of advanced attacks targeting Domain Controllers and other identity components.
In addition, the ITDR module integrates proactive capabilities by using attack surface management to identify and expose identity-related security flaws and vulnerabilities before they can be exploited.
│- Enable Analytics and Identity Analytics
The analytics engine accesses your logs as they are streamed to Cortex XSIAM, including firewall data, and analyzes them as soon as they arrive.
You need EDR or network logs from at least 30 endpoints over a minimum of 2 weeks, or Cloud audit logs over a minimum of 2 weeks.
✅ Enable Identity Analytics, which focuses on user behavior that is critical since attackers primarily target credentials. It has two main functions:
- User/Entity Behavior Analytics (UEBA): Profiles users, hosts, and groups based on identity data and flags anomalies like a user logging in from a new country (Impossible Traveler), accessing an unusual database, or transferring a massive file volume outside of their norm.
Investigation context: When an issue fires, Identity Analytics ensures that the relevant user profile details, recent activities, and group membership are automatically aggregated and displayed with a user-based Analytics type issue and Analytics BIOC rule
The Cloud Identity Engine must be set up.
✅ Enable the Identity Threat Detection and Response (ITDR) add-on (optional), which enhances the analytics baseline capabilities to include the Directory Infrastructure. This enables the detection of advanced attacks targeting Domain Controllers and other identity components.
In addition, the ITDR module integrates proactive capabilities by using attack surface management to identify and expose identity-related security flaws and vulnerabilities before they can be exploited.
│Your Cortex XSIAM is now operational and is collecting data.Your Cortex XSIAM is now operational and is collecting data.Show markdown source
@@ -18,11 +18,11 @@ This checklist does not include any specific Cloud Security requirements. If you This deployment phase sets up Cortex XSIAM infrastructure, data pipelines, endpoint protection, and security analytics. | Step | Details | See More | | ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | 1. Activation and initial setup | <p>✅ In the Cortex Gateway, activate Cortex XSIAM and confirm license status.</p><p>✅ Enable access to required PANW resources and set up encryption keys (BYOK), if required.</p><p>✅ Assign initial administrator and analyst-type user roles (Responder/Investigator), create user groups, and assign roles to those groups (recommended) to a limited number of users initially. You can update this later.</p><p>✅ Set up access through the Customer Support Portal or SAML single sign-on.</p> | <p><a href="activate-cortex-xsiam">Activate Cortex XSIAM</a><br><br><a href="activate-cortex-xsiam/enable-access-to-required-panw-resources">Enable access to required PANW resources</a><br><br><a href="set-up-users-and-roles">Set up users and roles</a><br><a href="set-up-authentication">Set up authentication</a></p> | | 2. Configure content | <p>Use the Data Sources Onboarding wizard to configure the following:</p><p>✅ Priority content:</p><ul><li>Configure network security data, such as Palo Alto Networks Next-Generation Firewalls, and network devices.</li><li>Configure identity and user data. Install the Cloud Identity Engine (optional and highly recommended), which provides the necessary Active Directory or Microsoft Entra ID/Okta context (user names, group membership, computer names) to map a raw event (for example, an IP address) to a user or asset.</li></ul><p>✅ Highly recommended content:</p><ul><li>Connect cloud audit logs for the most critical providers, such as AWS CloudTrail, Azure Activity Logs, and Google Cloud Audit Logs, directly to Cortex XSIAM.</li><li>Configure/enable a key Threat Intelligence feed, such as the Unit 42 Intelligence feed, to enrich incoming issues. This ensures that as soon as a log/alert hits the Data Lake, it has the latest malicious context.</li></ul> | <ul><li><a href="../../configure-cortex-xsiam/cortex-xsiam-data-sources/what-are-cortex-xsiam-data-sources">What are Cortex XSIAM data sources?</a></li><li><a href="set-up-cloud-identity-engine">Set up Cloud Identity Engine</a></li></ul> | | 3. Deploy the XDR agent | <p>✅ Install the XDR agent by creating XDR Agent installation packages for a small, diverse pilot group of endpoints and deploy the agent to a pilot group (phased rollout). Start with small, low-risk endpoints and extend, as required. Gradually expand agent distribution to larger groups that have similar attributes (hardware, software, and users). At the end of two weeks, you can have Cortex XSIAM deployed on up to 100 endpoints.</p><p>✅ After testing expected agent behavior and performance, review and select default endpoint security profiles (Exploit, Malware, Restrictions, Agent Settings, Exceptions) to begin protecting your endpoints from threats immediately. Once endpoints are deployed and start collecting data, you can make any necessary adjustments to these rules and policies.</p><p>✅ Verify endpoint data collection (logs, alerts, events) is flowing from deployed agents to the XSIAM Data Lake. After deploying the agents to the pilot group, set up data collection to analyze the data.</p><p>This provides granular event data (process execution, file activity, registry changes, network connections) necessary for EDR/XDR detection and Behavioral Indicators of Compromise (BIOCs).</p> | <ul><li><a href="install-cortex-xdr-agents/create-an-agent-installation-package">Create an agent installation package</a></li><li><a href="../../protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules">Set up endpoint profiles and exception rules</a></li><li><a href="../../protect-your-endpoints/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles">Set up agent settings profiles</a></li><li><a href="install-cortex-xdr-agents/configure-global-agent-settings">Configure global agent settings</a></li></ul> | -| 4. Enable Analytics and Identity Analytics | <p>✅ Enable Cortex XSIAM Analytics engine (if not already enabled).</p><p>The analytics engine accesses your logs as they are streamed to Cortex XSIAM, including firewall data, and analyzes them as soon as they arrive.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>You need EDR or network logs from at least 30 endpoints over a minimum of 2 weeks, or Cloud audit logs over a minimum of 2 weeks.</p></div><p>✅ Enable Identity Analytics, which focuses on user behavior that is critical since attackers primarily target credentials. It has two main functions:</p><ul><li>User/Entity Behavior Analytics (UEBA): Profiles users, hosts, and groups based on identity data and flags anomalies like a user logging in from a new country (Impossible Traveler), accessing an unusual database, or transferring a massive file volume outside of their norm.</li><li><p>Investigation context: When an issue fires, Identity Analytics ensures that the relevant user profile details, recent activities, and group membership are automatically aggregated and displayed with a user-based Analytics type issue and Analytics BIOC rule</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The Cloud Identity Engine must be set up.</p></div></li></ul><p>✅ Enable the Identity Threat Detection and Response (ITDR) add-on (optional), which enhances the analytics baseline capabilities to include the Directory Infrastructure. This enables the detection of advanced attacks targeting Domain Controllers and other identity components.</p><p>In addition, the ITDR module integrates proactive capabilities by using attack surface management to identify and expose identity-related security flaws and vulnerabilities before they can be exploited.</p> | <ul><li><a href="cortex-xsiam-analytics/enable-the-analytics-engine-and-identity-analytics">Enable the Analytics Engine and Identity Analytics</a></li><li><a href="../../detect-investigate-and-respond-to-threats/threat-management/analytics/analytics-overview/identity-analytics">Identity Analytics</a></li><li><a href="../../detect-investigate-and-respond-to-threats/identity-threat-module-itdr">Identity Threat Detection and Response (ITDR)</a></li></ul> | +| 4. Enable Analytics and Identity Analytics | <p>✅ Enable Cortex XSIAM Analytics engine (if not already enabled).</p><p>The analytics engine accesses your logs as they are streamed to Cortex XSIAM, including firewall data, and analyzes them as soon as they arrive.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>You need EDR or network logs from at least 30 endpoints over a minimum of 2 weeks, or Cloud audit logs over a minimum of 2 weeks.</p></div><p>✅ Enable Identity Analytics, which focuses on user behavior that is critical since attackers primarily target credentials. It has two main functions:</p><ul><li>User/Entity Behavior Analytics (UEBA): Profiles users, hosts, and groups based on identity data and flags anomalies like a user logging in from a new country (Impossible Traveler), accessing an unusual database, or transferring a massive file volume outside of their norm.</li><li><p>Investigation context: When an issue fires, Identity Analytics ensures that the relevant user profile details, recent activities, and group membership are automatically aggregated and displayed with a user-based Analytics type issue and Analytics BIOC rule</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The Cloud Identity Engine must be set up.</p></div></li></ul><p>✅ Enable the Identity Threat Detection and Response (ITDR) add-on (optional), which enhances the analytics baseline capabilities to include the Directory Infrastructure. This enables the detection of advanced attacks targeting Domain Controllers and other identity components.</p><p>In addition, the ITDR module integrates proactive capabilities by using attack surface management to identify and expose identity-related security flaws and vulnerabilities before they can be exploited.</p> | <ul><li><a href="cortex-xsiam-analytics/enable-the-analytics-engine-and-identity-analytics">Enable the Analytics Engine and Identity Analytics</a></li><li><a href="../../detect-investigate-and-respond-to-threats/threat-management/analytics/identity-analytics">Identity Analytics</a></li><li><a href="../../detect-investigate-and-respond-to-threats/identity-threat-module-itdr">Identity Threat Detection and Response (ITDR)</a></li></ul> | Your Cortex XSIAM is now operational and is collecting data.
-
▸ ▾ Forward notifications to Amazon SQS modified +4 −0 Adds a note to use the default AWS SQS message queue depth of 256 KB or higher.
xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-sqsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -6,16 +6,20 @@ description: >-------# Forward notifications to Amazon SQS# Forward notifications to Amazon SQS### Create the SQS queue### Create the SQS queueLog in to your AWS Management Console and create a new Standard SQS queue.Log in to your AWS Management Console and create a new Standard SQS queue.hint infoNOTE: Use the default AWS SQS message queue depth (256KB) or higher when creating or editing a standard SQS queue.endhint### Configure egress in Cortex Gateway### Configure egress in Cortex GatewayBefore forwarding cases or issues to Amazon SQS, you need to configure egress. Only a user with Account Admin or Instance Admin permissions can configure egress.Before forwarding cases or issues to Amazon SQS, you need to configure egress. Only a user with Account Admin or Instance Admin permissions can configure egress.To configure egress, to enter the queue name. For example, if the full URL is https://sqs.region.amazonaws.com/account-id/queue-name, enter onlyqueue-name.To configure egress, to enter the queue name. For example, if the full URL is https://sqs.region.amazonaws.com/account-id/queue-name, enter onlyqueue-name.1. In the Cortex Gateway, go to Permission Management → Egress Configurations → Path.1. In the Cortex Gateway, go to Permission Management → Egress Configurations → Path.2. Select the account name and tenant.2. Select the account name and tenant.Show markdown source
@@ -6,16 +6,20 @@ description: >- --- # Forward notifications to Amazon SQS ### Create the SQS queue Log in to your AWS Management Console and create a new **Standard SQS queue**. +{% hint style="info" %} +NOTE: Use the default AWS SQS message queue depth (256KB) or higher when creating or editing a standard SQS queue.  +{% endhint %} + ### Configure egress in Cortex Gateway Before forwarding cases or issues to Amazon SQS, you need to configure egress. Only a user with Account Admin or Instance Admin permissions can configure egress. To configure egress, to enter the queue name. For example, if the full URL is https://sqs.region.amazonaws.com/account-id/queue-name, enter only `queue-name`. 1. In the Cortex Gateway, go to **Permission Management** → **Egress Configurations** → **Path**. 2. Select the account name and tenant.