Documentation — September 03, 2026
22 files changed, 102 insertions, 91 deletions — view the commit on the mirror.
Tenant users now need a CSP role first; connector consolidation covers only Palo Alto Networks integrations
- Manage user access gains a prerequisite: a user must hold the Cortex User role in the Customer Support Portal before they appear in a tenant’s Users list.
- Five data source pages narrow the unified connector story to Palo Alto Networks managed integrations — partner-managed and community-contributed packs stay standalone.
- Retrieve support file password was rewritten around the two ways a Tech Support File is produced.
- Compliance standard cloning changed: copies are suffixed
_copyrather than prefixed “Copy of “, and the flow gains a Select Controls step. - The rest is Cortex Cloud → Cortex XSIAM wording fixes, two retitled pages and whitespace.
Highlights
-
Users must hold the Cortex User role in the CSP before they appear in a tenant
A new prerequisite says an administrator assigns the role on the Edit User screen in the Manage User Console of the Customer Support Portal, and that this controls both the user's visibility and their access.
-
Connector consolidation applies only to Palo Alto Networks managed integrations
Four data source pages now add that partner-managed and community-contributed Marketplace integrations remain outside the unified connector framework and are always managed as standalone packs.
-
Retrieve support file password is rewritten around how the TSF was produced
The procedure now splits by whether the archive came from the Action Center or from cytool log collect on the endpoint, and names the metadata file that carries the encrypted token as _CRYPTO-INFO.
-
Cloned compliance standards are suffixed _copy instead of prefixed "Copy of "
The clone flow also gains a Select Controls step and ends on Create rather than Clone, while the create and edit flows lose the option to save and assign new controls afterwards.
-
The "Data collection may require an add-on" notice was removed
That licensing hint was deleted outright from the Palo Alto Networks integrations page, with nothing put in its place.
-
Two pages were retitled without moving
"Complete data source and connector catalog" became "What is the data source and connector catalog?" and the cloud permissions page now names Cortex XSIAM, but both paths are unchanged so existing links still resolve.
Changes
22 files listed, 15 written up and shaded below.
-
▸ ▾ Navigation manifest (xsiam) modified +2 −2
.meta/xsiamThe book's page tree and ordering — not a documentation page, so no diff is kept. The counts above still say how much moved.
-
▸ ▾ Troubleshooting Resources for Mac modified +1 −1
agent/cortex-xdr-agent-for-macos/troubleshooting-resources-for-macRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,9 +1,9 @@------description: >-description: >-Refer to the following troubleshooting resources for the Cortex XDR agent forRefer to the following troubleshooting resources for the Cortex XDR agent forMac.Mac.------# Troubleshooting Resources for Mac# Troubleshooting Resources for MacResource Description Processes Launch Daemons:
/Applications/Cortex XDR.app/Contents/MacOS/Cortex XDR/Library/Application Support/PaloAltoNetworks/Traps/bin/pmd/Library/Application Support/PaloAltoNetworks/Traps/bin/authorized
Launch Agents:
/Library/Application Support/PaloAltoNetworks/Traps/bin/Cortex XDR Agent.app/Contents/MacOS/Cortex XDR Agent
System Extensions:
com.paloaltonetworks.traps.securityextensioncom.paloaltonetworks.traps.networkextension
Payload:
/Library/Application Support/PaloAltoNetworks/Traps/download/content/cortex-xdr-payload
Cortex XDR agent console log Indicates information, warnings, and errors related to the agent console. The Console log is located in the following folder on the endpoint:
- Mac OS X 10.10 and OSX 10.11—
/var/log/traps/agent/ - macOS 10.12 and later releases—View logs from the Console application in
/Library/Logs/PaloAltoNetworks/Cortex XDR/.
Cortex XDR agent service log Indicates information, warnings, and errors related to Cortex XDR. The Service log is located in the following folder on the endpoint:
- Mac OS X 10.10 and OSX 10.11—
/var/log/traps/ - macOS 10.12 and later releases—View logs from the Console application in
/Library/Logs/PaloAltoNetworks/Cortex XDR/.
Supervisor Command Line Tool (cytool) Allows you to manage agent features and perform advanced troubleshooting on the local endpoint from a command line interface. For more information, see Cytool for Mac. Resource Description Processes Launch Daemons:
/Applications/Cortex XDR.app/Contents/MacOS/Cortex XDR/Library/Application Support/PaloAltoNetworks/Traps/bin/pmd/Library/Application Support/PaloAltoNetworks/Traps/bin/authorized
Launch Agents:
/Library/Application Support/PaloAltoNetworks/Traps/bin/Cortex XDR Agent.app/Contents/MacOS/Cortex XDR Agent
System Extensions:
com.paloaltonetworks.traps.securityextensioncom.paloaltonetworks.traps.networkextension
Payload:
/Library/Application Support/PaloAltoNetworks/Traps/download/content/cortex-xdr-payload
Cortex XDR agent installation log Specifies any errors encountered during the installation of agent components. Use this log file when you need to troubleshoot installation issues. On Mac OS endpoints, the system records installation events in the global install log located at /var/log/install.log.Cortex XDR agent console log Indicates information, warnings, and errors related to the agent console. The Console log is located in the following folder on the endpoint:
- Mac OS X 10.10 and OSX 10.11—
/var/log/traps/agent/ - macOS 10.12 and later releases—View logs from the Console application in
/Library/Logs/PaloAltoNetworks/Cortex XDR/.
Cortex XDR agent service log Indicates information, warnings, and errors related to Cortex XDR. The Service log is located in the following folder on the endpoint:
- Mac OS X 10.10 and OSX 10.11—
/var/log/traps/ - macOS 10.12 and later releases—View logs from the Console application in
/Library/Logs/PaloAltoNetworks/Cortex XDR/.
Supervisor Command Line Tool (cytool) Allows you to manage agent features and perform advanced troubleshooting on the local endpoint from a command line interface. For more information, see Cytool for Mac. Show markdown source
@@ -1,9 +1,9 @@ --- description: >- Refer to the following troubleshooting resources for the Cortex XDR agent for Mac. --- # Troubleshooting Resources for Mac -<table data-header-hidden><thead><tr><th width="160.15020751953125"></th><th width="590.1849365234375"></th></tr></thead><tbody><tr><td>Resource</td><td>Description</td></tr><tr><td>Processes</td><td><p>Launch Daemons:</p><ul><li><code>/Applications/Cortex XDR.app/Contents/MacOS/Cortex XDR</code></li><li><code>/Library/Application Support/PaloAltoNetworks/Traps/bin/pmd</code></li><li><code>/Library/Application Support/PaloAltoNetworks/Traps/bin/authorized</code></li></ul><p>Launch Agents:</p><ul><li><code>/Library/Application Support/PaloAltoNetworks/Traps/bin/Cortex XDR Agent.app/Contents/MacOS/Cortex XDR Agent</code></li></ul><p>System Extensions:</p><ul><li><code>com.paloaltonetworks.traps.securityextension</code></li><li><code>com.paloaltonetworks.traps.networkextension</code></li></ul><p>Payload:</p><ul><li><code>/Library/Application Support/PaloAltoNetworks/Traps/download/content/cortex-xdr-payload</code></li></ul></td></tr><tr><td>Cortex XDR agent console log</td><td><p>Indicates information, warnings, and errors related to the agent console. The Console log is located in the following folder on the endpoint:</p><ul><li>Mac OS X 10.10 and OSX 10.11—<code>/var/log/traps/agent/</code></li><li>macOS 10.12 and later releases—View logs from the Console application in <code>/Library/Logs/PaloAltoNetworks/Cortex XDR/</code>.</li></ul></td></tr><tr><td>Cortex XDR agent service log</td><td><p>Indicates information, warnings, and errors related to Cortex XDR. The Service log is located in the following folder on the endpoint:</p><ul><li>Mac OS X 10.10 and OSX 10.11—<code>/var/log/traps/</code></li><li>macOS 10.12 and later releases—View logs from the Console application in <code>/Library/Logs/PaloAltoNetworks/Cortex XDR/</code>.</li></ul></td></tr><tr><td>Supervisor Command Line Tool (cytool)</td><td>Allows you to manage agent features and perform advanced troubleshooting on the local endpoint from a command line interface. For more information, see <a href="troubleshooting-resources-for-mac/cytool-for-mac">Cytool for Mac</a>.</td></tr></tbody></table> +<table data-header-hidden><thead><tr><th width="160.15020751953125"></th><th width="590.1849365234375"></th></tr></thead><tbody><tr><td>Resource</td><td>Description</td></tr><tr><td>Processes</td><td><p>Launch Daemons:</p><ul><li><code>/Applications/Cortex XDR.app/Contents/MacOS/Cortex XDR</code></li><li><code>/Library/Application Support/PaloAltoNetworks/Traps/bin/pmd</code></li><li><code>/Library/Application Support/PaloAltoNetworks/Traps/bin/authorized</code></li></ul><p>Launch Agents:</p><ul><li><code>/Library/Application Support/PaloAltoNetworks/Traps/bin/Cortex XDR Agent.app/Contents/MacOS/Cortex XDR Agent</code></li></ul><p>System Extensions:</p><ul><li><code>com.paloaltonetworks.traps.securityextension</code></li><li><code>com.paloaltonetworks.traps.networkextension</code></li></ul><p>Payload:</p><ul><li><code>/Library/Application Support/PaloAltoNetworks/Traps/download/content/cortex-xdr-payload</code></li></ul></td></tr><tr><td>Cortex XDR agent installation log</td><td>Specifies any errors encountered during the installation of agent components. Use this log file when you need to troubleshoot installation issues. On Mac OS endpoints, the system records installation events in the global install log located at <code>/var/log/install.log</code>.</td></tr><tr><td>Cortex XDR agent console log</td><td><p>Indicates information, warnings, and errors related to the agent console. The Console log is located in the following folder on the endpoint:</p><ul><li>Mac OS X 10.10 and OSX 10.11—<code>/var/log/traps/agent/</code></li><li>macOS 10.12 and later releases—View logs from the Console application in <code>/Library/Logs/PaloAltoNetworks/Cortex XDR/</code>.</li></ul></td></tr><tr><td>Cortex XDR agent service log</td><td><p>Indicates information, warnings, and errors related to Cortex XDR. The Service log is located in the following folder on the endpoint:</p><ul><li>Mac OS X 10.10 and OSX 10.11—<code>/var/log/traps/</code></li><li>macOS 10.12 and later releases—View logs from the Console application in <code>/Library/Logs/PaloAltoNetworks/Cortex XDR/</code>.</li></ul></td></tr><tr><td>Supervisor Command Line Tool (cytool)</td><td>Allows you to manage agent features and perform advanced troubleshooting on the local endpoint from a command line interface. For more information, see <a href="troubleshooting-resources-for-mac/cytool-for-mac">Cytool for Mac</a>.</td></tr></tbody></table>
-
▸ ▾ Choose compliance standards from the compliance catalog modified +1 −1
xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalogRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -9,11 +9,11 @@ description: >-The compliance catalogs provide a list of available compliance standards and controls.The compliance catalogs provide a list of available compliance standards and controls.Cortex provides lists of available standards and controls in the Standards and Controls catalogs under Posture Management → Compliance → Catalogs.Cortex provides lists of available standards and controls in the Standards and Controls catalogs under Posture Management → Compliance → Catalogs.## What are standards and controls?## What are standards and controls?Standards are guidelines that organizations follow in order to comply with industry best practices and regulations, as well as internal organizational policies and procedures. They improve security and quality in operational practices.Standards are guidelines that organizations follow in order to comply with industry best practices and regulations, as well as internal organizational policies and procedures. They improve security and quality in operational practices.Standards consist of controls, which are measures related to the standard that ensure compliance and mitigate risks. Controls are built from one or more rules, the specific checks that run on an asset. Controls are grouped into categories and sub-categories.Standards consist of controls, which are measures related to the standard that ensure compliance and mitigate risks. Controls are built from one or more rules, the specific checks that run on an asset. Controls are grouped into categories and sub-categories.The Standards and Controls catalogs include built-in industry standards and controls and custom organizational standards and controls.The Standards and Controls catalogs include built-in industry standards and controls and custom organizational standards and controls.Show markdown source
@@ -9,11 +9,11 @@ description: >- The compliance catalogs provide a list of available compliance standards and controls. Cortex provides lists of available standards and controls in the Standards and Controls catalogs under **Posture Management → Compliance → Catalogs**. ## What are standards and controls? Standards are guidelines that organizations follow in order to comply with industry best practices and regulations, as well as internal organizational policies and procedures. They improve security and quality in operational practices. -Standards consist of controls, which are measures related to the standard that ensure compliance and mitigate risks. Controls are built from one or more rules, the specific checks that run on an asset. Controls are grouped into categories and sub-categories. +Standards consist of controls, which are measures related to the standard that ensure compliance and mitigate risks. Controls are built from one or more rules, the specific checks that run on an asset. Controls are grouped into categories and sub-categories.  The **Standards** and **Controls** catalogs include built-in industry standards and controls and custom organizational standards and controls.
-
▸ ▾ Standards catalog modified +1 −15 Swaps the standards list screenshot and drops the enumeration of its columns and the Table to Card View display note.
xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/standards-catalogRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,31 +1,17 @@------description: Browse available compliance standards in Cortex XSIAM.description: Browse available compliance standards in Cortex XSIAM.------# Standards catalog# Standards catalogThe Standards Catalog page displays a list of the available standards:The Standards Catalog page displays a list of the available standards:
This includes information such as:• Name• Version• Description• Created By• Controls• Profiles• Labels• Is Custom• IDYou can click the Display option to switch from Table to Card View.Click on a specific standard to open the standard overview side panel with detailed information about the standard:Click on a specific standard to open the standard overview side panel with detailed information about the standard:
From the side panel, you can view and filter controls associated with the standard, and click on a control to view its details and the rules associated with it.From the side panel, you can view and filter controls associated with the standard, and click on a control to view its details and the rules associated with it.## Built-in compliance standards## Built-in compliance standardsShow markdown source
@@ -1,31 +1,17 @@ --- description: Browse available compliance standards in Cortex XSIAM. --- # Standards catalog The **Standards Catalog** page displays a list of the available standards: -<figure><img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FPwoXrI6LHrIaPift3SN5%2Fcompliance-standards-list.png?alt=media&token=4b053d17-3c28-4076-95de-acb4ea6878eb" alt="This screenshot from Cortex UI shows the list of compliance standards."><figcaption></figcaption></figure> - -This includes information such as: - -* Name -* Version -* Description -* Created By -* Controls -* Profiles -* Labels -* Is Custom -* ID - -You can click the **Display** option to switch from **Table** to **Card View**. +<figure><img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FBE4ZrFLV12XR33QA4cPS%2FScreenshot%202026-09-03%20at%201.26.02%E2%80%AFPM.png?alt=media&token=434f018c-0122-4ca2-b7b6-7295a3b5c596" alt=""><figcaption></figcaption></figure> Click on a specific standard to open the standard overview side panel with detailed information about the standard: <figure><img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FV6CsbFR0dnxRMjxHqPG7%2Fcompliance-standards-sidepane.png?alt=media&token=b0a19d18-2116-434a-8972-949d07619866" alt="This screenshot from Cortex UI shows standard details shown in a side pane."><figcaption></figcaption></figure> From the side panel, you can view and filter controls associated with the standard, and click on a control to view its details and the rules associated with it. ## Built-in compliance standards
-
▸ ▾ Use a built-in or custom control modified +8 −7 Control metadata fields are bolded, and assigning a detection rule moves out of the numbered edit steps into a trailing note.
xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-controlRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -16,17 +16,17 @@ Cortex XSIAM provides built-in controls that cannot be edited or deleted. When yYou can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard.You can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard.1. In the Controls catalog, click + Create Control.1. In the Controls catalog, click + Create Control.2. Define control metadata, including:2. Define control metadata, including:• A single category• A single category• A single sub category (optional)• A single sub category (optional)• Control name• Control name• Description (optional)• Description (optional)• One or more custom standards to associate the control with• One or more custom standards to associate the control with3. Click Create.3. Click Create.4. Assign a custom detection rule to the control as follows.4. Assign a custom detection rule to the control as follows.## Associate a custom control to a detection rule## Associate a custom control to a detection ruleYou can associate custom compliance controls with workload security and cloud security rules. This tailors compliance checks to your organization’s needs. You can associate controls while creating custom rules. You can also associate them when editing custom or built-in rules.You can associate custom compliance controls with workload security and cloud security rules. This tailors compliance checks to your organization’s needs. You can associate controls while creating custom rules. You can also associate them when editing custom or built-in rules.@@ -61,15 +61,16 @@ To associate a custom compliance control:## Edit a custom control## Edit a custom controlYou can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control.You can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control.1. In the Controls catalog, click 🖼 cortex-cloud-compliance-three-dots.png on the built-in control you want to edit and click Save as new.\1. In the Controls catalog, click 🖼 cortex-cloud-compliance-three-dots.png on the built-in control you want to edit and click Save as new.\To edit a custom control, click 🖼 cortex-cloud-compliance-three-dots.png on the custom control and click Edit.To edit a custom control, click 🖼 cortex-cloud-compliance-three-dots.png on the custom control and click Edit.2. Click Next.2. Click Next.3. Edit control metadata, including:3. Edit control metadata, including:• Category: You can reassign the control to a different existing category or create a new category.• Category: You can reassign the control to a different category.• Sub category (optional): You can reassign the control to a different existing sub category or create a new sub category.• Sub category (optional): You can reassign the control to a different sub category.• Control name: You can update the control name.• Control name: You can update the control name.• Description (optional): You can update the control description.• Description (optional): You can update the control description.• Select custom standards: You can modify the list of custom standards with which the control should be associated.• Select custom standards: You can modify the list of custom standards with which the control should be associated.4. Click Save.4. Click Save.5. If the control does not already contain a rule, assign a custom detection rule to the control.If the control does not already contain a rule, assign a custom detection rule to the control.Show markdown source
@@ -16,17 +16,17 @@ Cortex XSIAM provides built-in controls that cannot be edited or deleted. When y You can create a new control that is tailored to your own business needs, standards, and organizational policies to use in a custom standard. 1. In the **Controls** catalog, click **+ Create Control**. 2. Define control metadata, including: * A single category * A single sub category (optional) * Control name - * Description (optional) + * Description (optional) * One or more custom standards to associate the control with 3. Click **Create**. 4. Assign a custom detection rule to the control as follows. ## Associate a custom control to a detection rule You can associate custom compliance controls with workload security and cloud security rules. This tailors compliance checks to your organization’s needs. You can associate controls while creating custom rules. You can also associate them when editing custom or built-in rules. @@ -61,15 +61,16 @@ To associate a custom compliance control: ## Edit a custom control You can edit a copy of a built-in control or edit an existing custom control. You can also delete a custom control. 1. In the **Controls** catalog, click [](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/tDvVprS3kGLl_Hnh6mxouw-5CAbsl8idaK8R43ZLhoTOw) on the built-in control you want to edit and click **Save as new**.\ To edit a custom control, click [](https://docs-cortex.paloaltonetworks.com/viewer/attachment/5CAbsl8idaK8R43ZLhoTOw/tDvVprS3kGLl_Hnh6mxouw-5CAbsl8idaK8R43ZLhoTOw) on the custom control and click **Edit**. 2. Click **Next**. 3. Edit control metadata, including: - * Category: You can reassign the control to a different existing category or create a new category. - * Sub category (optional): You can reassign the control to a different existing sub category or create a new sub category. - * Control name: You can update the control name. - * Description (optional): You can update the control description. - * Select custom standards: You can modify the list of custom standards with which the control should be associated. + * **Category**: You can reassign the control to a different category. + * **Sub category** (optional): You can reassign the control to a different sub category. + * **Control name**: You can update the control name. + * **Description** (optional): You can update the control description. + * **Select custom standards**: You can modify the list of custom standards with which the control should be associated. 4. Click **Save**. -5. If the control does not already contain a rule, assign a custom detection rule to the control. + +If the control does not already contain a rule, assign a custom detection rule to the control. -
▸ ▾ Use a built-in or custom standard modified +10 −11 Clone naming changes to a _copy suffix, a Select Controls step is added, and the "assign new controls" follow-up option is dropped.
xsiam/cloud-security/monitor-and-track-compliance-adherence/choose-compliance-standards-from-the-compliance-catalog/use-a-built-in-or-custom-standardRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -11,50 +11,49 @@ You can use a built-in industry standard or create a custom standard. A custom sCortex provides built-in industry approved regulatory compliance standards, for example GDPR. These standards cannot be edited or deleted, you can duplicate them to create a custom standard.Cortex provides built-in industry approved regulatory compliance standards, for example GDPR. These standards cannot be edited or deleted, you can duplicate them to create a custom standard.## Clone a built-in standard## Clone a built-in standardTo reuse and modify a built-in standard, clone the built-in industry standard:To reuse and modify a built-in standard, clone the built-in industry standard:1. In the Standards catalog, right-click on the custom standard you want to edit (or select
next to it) and then select Save as new.
1. In the Standards catalog, right-click on the custom standard you want to edit (or select
next to it) and then select Save as new.
2. Define compliance standard metadata, including:2. Define compliance standard metadata, including:1. Name: By default, the original built-in standard name is used with “Copy of “ is prepended. You can update it if needed.1. Name: By default, the original built-in standard name is used with “_copy“ is appended. You can update it if needed.2. Description: You can update the description if needed.2. Description: You can update the description if needed.3. Click Clone.3. Select Controls: You can select or deselect controls as needed.3. Click Create.You can edit categories and controls after cloning the standard.## Create a custom standard## Create a custom standardYou can create a custom compliance standard that is tailored to your own business needs and organizational policies.You can create a custom compliance standard that is tailored to your own business needs and organizational policies.To organize controls within a custom compliance standard, you establish categories and optional sub-categories. Every control is defined as part of a specific standard and assigned to a single category within it. Sub-categories offer an additional layer of organizational structure.To organize controls within a custom compliance standard, you establish categories and optional sub-categories. Every control is defined as part of a specific standard and assigned to a single category within it. Sub-categories offer an additional layer of organizational structure.1. In the Standards catalog, click Create Standard.1. In the Standards catalog, click Create Standard.2. Define compliance standard metadata, including:2. Define compliance standard metadata, including:1. Name1. Name2. Description (optional)2. Description (optional)3. Labels (optional)3. Labels (optional)3. Click Next.3. Click Next.4. Under Select Controls, you can do one of the following:4. Under Select Controls, you select the controls that you would like to add to the standard.1. Select the controls that you would like to add to the standard and click Create.5. Click Create.2. You can use the option to Create and Assign New Controls if you would like to save the standard and then create new controls and assign them to the standard.## Edit a custom standard## Edit a custom standardYou can edit an existing custom standard.You can edit an existing custom standard.1. In the Standards catalog, right-click on the custom standard (or select
next to it) and then select Edit.
1. In the Standards catalog, right-click on the custom standard (or select
next to it) and then select Edit.
2. Define compliance standard metadata, including:2. Define compliance standard metadata, including:1. Name1. Name2. Description (optional)2. Description (optional)3. Labels (optional)3. Labels (optional)3. Click Next.3. Click Next.4. Under Select Controls, you can do one of the following:4. Under Select Controls, you can do one of the following, select the controls that you would like to add to the standard.1. Select the controls that you would like to add to the standard and click Save.5. Click Save.2. You can use the option to Save and Assign New Controls if you would like to save the standard and then create new controls and assign them to the standard.## Delete a custom standard## Delete a custom standardTo delete an existing custom standard and all the categories, subcategories, and controls associated with it, perform the following steps.To delete an existing custom standard and all the categories, subcategories, and controls associated with it, perform the following steps.1. In the Standards catalog, right-click on the custom standard (or select
next to it ) and then select Delete.
1. In the Standards catalog, right-click on the custom standard (or select
next to it ) and then select Delete.
2. Click Delete.2. Click Delete.Show markdown source
@@ -11,50 +11,49 @@ You can use a built-in industry standard or create a custom standard. A custom s Cortex provides built-in industry approved regulatory compliance standards, for example **GDPR**. These standards cannot be edited or deleted, you can duplicate them to create a custom standard. ## Clone a built-in standard To reuse and modify a built-in standard, clone the built-in industry standard: 1. In the **Standards** catalog, right-click on the custom standard you want to edit (or select <img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FY4XEarbH6eoofHx6zLlS%2Freusable-menu.png?alt=media&token=bae02a0f-56cb-4d38-acb0-9cbc5b21b741" alt="" data-size="line"> next to it) and then select **Save as new**. 2. Define compliance standard metadata, including: - 1. **Name**: By default, the original built-in standard name is used with “Copy of “ is prepended. You can update it if needed. + 1. **Name**: By default, the original built-in standard name is used with “\_copy“ is appended. You can update it if needed. 2. **Description**: You can update the description if needed. -3. Click **Clone**. - -You can edit categories and controls after cloning the standard. + 3. **Select Controls**: You can select or deselect controls as needed.  +3. Click **Create**. ## Create a custom standard You can create a custom compliance standard that is tailored to your own business needs and organizational policies. To organize controls within a custom compliance standard, you establish categories and optional sub-categories. Every control is defined as part of a specific standard and assigned to a single category within it. Sub-categories offer an additional layer of organizational structure. 1. In the **Standards** catalog, click **Create Standard**. 2. Define compliance standard metadata, including: 1. **Name** 2. **Description** (optional) 3. **Labels** (optional) 3. Click **Next.** -4. Under **Select Controls**, you can do one of the following:  - 1. Select the controls that you would like to add to the standard and click **Create**.  - 2. You can use the option to **Create and Assign New Controls** if you would like to save the standard and then create new controls and assign them to the standard.   +4. Under **Select Controls**, you select the controls that you would like to add to the standard. +5. Click **Create**.  ## Edit a custom standard You can edit an existing custom standard. 1. In the **Standards** catalog, right-click on the custom standard (or select <img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FY4XEarbH6eoofHx6zLlS%2Freusable-menu.png?alt=media&token=bae02a0f-56cb-4d38-acb0-9cbc5b21b741" alt="" data-size="line"> next to it) and then select **Edit**. 2. Define compliance standard metadata, including: 1. **Name** 2. **Description** (optional) 3. **Labels** (optional) 3. Click **Next**. -4. Under **Select Controls**, you can do one of the following:  - 1. Select the controls that you would like to add to the standard and click **Save**.  - 2. You can use the option to **Save and Assign New Controls** if you would like to save the standard and then create new controls and assign them to the standard.   +4. Under **Select Controls**, you can do one of the following, select the controls that you would like to add to the standard.  +5. Click **Save**.  ## Delete a custom standard -To delete an existing custom standard and all the categories, subcategories, and controls associated with it, perform the following steps. +To delete an existing custom standard and all the categories, subcategories, and controls associated with it, perform the following steps. + + 1. In the **Standards** catalog, right-click on the custom standard (or select <img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2FY4XEarbH6eoofHx6zLlS%2Freusable-menu.png?alt=media&token=bae02a0f-56cb-4d38-acb0-9cbc5b21b741" alt="" data-size="line"> next to it ) and then select **Delete**. 2. Click **Delete**. -
▸ ▾ Cloud Posture and Runtime Security data sources modified +0 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-posture-and-runtime-security-data-sourcesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -119,9 +119,8 @@ The following Cloud Posture and Runtime Security data sources and connectors are• Terraform• Terraform• VMware• VMware• Workday Automation and Collection• Workday Automation and Collection• Workday• Workday• YouTrack• YouTrack• Zendesk• Zendesk• Zscaler• Zscaler• AppSec Transporter• AppSec TransporterShow markdown source
@@ -119,9 +119,8 @@ The following Cloud Posture and Runtime Security data sources and connectors are * [Terraform](vendor-specific-data-sources-and-connectors/terraform/terraform) * [VMware](vendor-specific-data-sources-and-connectors/vmware/vmware) * [Workday Automation and Collection](vendor-specific-data-sources-and-connectors/workday/workday-automation-and-collection) * [Workday](vendor-specific-data-sources-and-connectors/workday/workday) * [YouTrack](vendor-specific-data-sources-and-connectors/youtrack/youtrack) * [Zendesk](vendor-specific-data-sources-and-connectors/zendesk/zendesk) * [Zscaler](vendor-specific-data-sources-and-connectors/zscaler/zscaler) * [AppSec Transporter](generic-on-premise-data-collectors/broker-vm-data-collector-applets/activate-transporter) -
-
▸ ▾ Edit your onboarded CSP configuration modified +1 −1 Says Cortex XSIAM rather than Cortex Cloud, and corrects "take affect" to "take effect".
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/edit-your-onboarded-csp-configurationRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,15 +1,15 @@------description: Update onboarded cloud configurations in Cortex XSIAM.description: Update onboarded cloud configurations in Cortex XSIAM.------# Edit your onboarded CSP configuration# Edit your onboarded CSP configurationIn order to make changes to your onboarded CSP configuration, you first modify the cloud instance settings in Cortex Cloud and download an updated authentication template. After uploading the updated template to the CSP environment, you execute the template and then the changes take affect.In order to make changes to your onboarded CSP configuration, you first modify the cloud instance settings in Cortex XSIAM and download an updated authentication template. After uploading the updated template to the CSP environment, you execute the template and then the changes take effect.1. Navigate to Settings → Data Sources & Integrations.1. Navigate to Settings → Data Sources & Integrations.2. Identify the Cloud Service Provider you want to update and click View Details.2. Identify the Cloud Service Provider you want to update and click View Details.3. In the Cloud Instances page, identify the cloud instance you want to edit and click the Configuration pencil icon to edit the instance.3. In the Cloud Instances page, identify the cloud instance you want to edit and click the Configuration pencil icon to edit the instance.4. Make changes to the configuration settings. Click Save.4. Make changes to the configuration settings. Click Save.If the changes you made require re-deploying the authentication template, you will be prompted to to download the file. Click **Download CloudFormation** or **Download Terraform** as relevant to your CSP type.If the changes you made require re-deploying the authentication template, you will be prompted to to download the file. Click **Download CloudFormation** or **Download Terraform** as relevant to your CSP type.Show markdown source
@@ -1,15 +1,15 @@ --- description: Update onboarded cloud configurations in Cortex XSIAM. --- # Edit your onboarded CSP configuration -In order to make changes to your onboarded CSP configuration, you first modify the cloud instance settings in Cortex Cloud and download an updated authentication template. After uploading the updated template to the CSP environment, you execute the template and then the changes take affect. +In order to make changes to your onboarded CSP configuration, you first modify the cloud instance settings in Cortex XSIAM and download an updated authentication template. After uploading the updated template to the CSP environment, you execute the template and then the changes take effect. 1. Navigate to **Settings → Data Sources & Integrations**. 2. Identify the Cloud Service Provider you want to update and click **View Details**. 3. In the **Cloud Instances** page, identify the cloud instance you want to edit and click the **Configuration** pencil icon to edit the instance. 4. Make changes to the configuration settings. Click **Save**. If the changes you made require re-deploying the authentication template, you will be prompted to to download the file. Click **Download CloudFormation** or **Download Terraform** as relevant to your CSP type. -
▸ ▾ Pending cloud instances modified +1 −1 Opens with Cortex XSIAM instead of Cortex Cloud.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/pending-cloud-instancesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,15 +1,15 @@------description: Review pending cloud instances in Cortex XSIAM.description: Review pending cloud instances in Cortex XSIAM.------# Pending cloud instances# Pending cloud instancesIn Cortex Cloud, a pending cloud instance refers to a cloud instance created after Cortex Cloud generates an authentication template, but before that template has been fully executed within the Cloud Service Provider (CSP) environment.In Cortex XSIAM, a pending cloud instance refers to a cloud instance created after Cortex Cloud generates an authentication template, but before that template has been fully executed within the Cloud Service Provider (CSP) environment.A pending cloud instance is created each time you complete the onboarding wizard for a new CSP and click Save. You can view all cloud instances, including those in a pending state, by navigating to Cloud Instances. Ensure you remove any default filters that might exclude instances with a "pending" status.A pending cloud instance is created each time you complete the onboarding wizard for a new CSP and click Save. You can view all cloud instances, including those in a pending state, by navigating to Cloud Instances. Ensure you remove any default filters that might exclude instances with a "pending" status.A single pending instance can be leveraged to create multiple cloud instances, all sharing the same configurations defined during the cloud onboarding process. Pending instances are automatically deleted after 30 days.A single pending instance can be leveraged to create multiple cloud instances, all sharing the same configurations defined during the cloud onboarding process. Pending instances are automatically deleted after 30 days.### Manage pending cloud instances### Manage pending cloud instancesThere are some actions that can be performed specifically on cloud instances with a status of "pending".There are some actions that can be performed specifically on cloud instances with a status of "pending".Show markdown source
@@ -1,15 +1,15 @@ --- description: Review pending cloud instances in Cortex XSIAM. --- # Pending cloud instances -In Cortex Cloud, a pending cloud instance refers to a cloud instance created after Cortex Cloud generates an authentication template, but before that template has been fully executed within the Cloud Service Provider (CSP) environment. +In Cortex XSIAM, a pending cloud instance refers to a cloud instance created after Cortex Cloud generates an authentication template, but before that template has been fully executed within the Cloud Service Provider (CSP) environment. A pending cloud instance is created each time you complete the onboarding wizard for a new CSP and click **Save**. You can view all cloud instances, including those in a pending state, by navigating to **Cloud Instances**. Ensure you remove any default filters that might exclude instances with a "pending" status. A single pending instance can be leveraged to create multiple cloud instances, all sharing the same configurations defined during the cloud onboarding process. Pending instances are automatically deleted after 30 days. ### **Manage pending cloud instances** There are some actions that can be performed specifically on cloud instances with a status of "pending".
-
▸ ▾ Troubleshoot errors on cloud instances modified +1 −1
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/troubleshoot-errors-on-cloud-instancesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@------description: >-description: >-You can troubleshoot errors on cloud instances by drilling down on an instanceYou can troubleshoot errors on cloud instances by drilling down on an instancefrom the Data Sources & Integrations page.from the Data Sources & Integrations page in Cortex XSIAM.------# Troubleshoot errors on cloud instances# Troubleshoot errors on cloud instancesTo help you to troubleshoot errors on a cloud instance, Cortex Cloud provides the following visibility and drilldown options:To help you to troubleshoot errors on a cloud instance, Cortex Cloud provides the following visibility and drilldown options:• Overall status of an instance that indicates the health of your instance.• Overall status of an instance that indicates the health of your instance.• A breakdown of the security capabilities enabled on an instance, detailing the status of each capability along with any open errors or issues.• A breakdown of the security capabilities enabled on an instance, detailing the status of each capability along with any open errors or issues.Show markdown source
@@ -1,12 +1,12 @@ --- description: >- You can troubleshoot errors on cloud instances by drilling down on an instance - from the Data Sources & Integrations page. + from the Data Sources & Integrations page in Cortex XSIAM. --- # Troubleshoot errors on cloud instances To help you to troubleshoot errors on a cloud instance, Cortex Cloud provides the following visibility and drilldown options: * Overall status of an instance that indicates the health of your instance. * A breakdown of the security capabilities enabled on an instance, detailing the status of each capability along with any open errors or issues.
-
▸ ▾ Update cloud permissions after Cortex XSIAM release updates modified +2 −2 Title and description now name Cortex XSIAM rather than Cortex generally; the path is unchanged.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding/update-cloud-permissions-after-cortex-release-updatesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,15 +1,15 @@------description: >-description: >-Manage permission updates for your cloud instances following new featureManage permission updates for your cloud instances following new featurereleases or bug fixes.releases or bug fixes in Cortex XSIAM.------# Update cloud permissions after Cortex release updates# Update cloud permissions after Cortex XSIAM release updatesThis topic provides guidance on how to manage permission updates for your cloud instances following new feature releases or bug fixes. It outlines how users are notified of required permission changes and provides step-by-step instructions for granting necessary permissions to ensure continued functionality and security.This topic provides guidance on how to manage permission updates for your cloud instances following new feature releases or bug fixes. It outlines how users are notified of required permission changes and provides step-by-step instructions for granting necessary permissions to ensure continued functionality and security.hint infohint info#### Prerequisites#### Prerequisites• Ensure that the user account used to modify permissions has the necessary privileges within both the Cortex platform and your cloud environment, for example, AWS or Azure.• Ensure that the user account used to modify permissions has the necessary privileges within both the Cortex platform and your cloud environment, for example, AWS or Azure.• You received a notification regarding a new version available that requires permission updates, or viewed a Needs Update status in the Data Sources & Integrations page.• You received a notification regarding a new version available that requires permission updates, or viewed a Needs Update status in the Data Sources & Integrations page.Show markdown source
@@ -1,15 +1,15 @@ --- description: >- Manage permission updates for your cloud instances following new feature - releases or bug fixes. + releases or bug fixes in Cortex XSIAM. --- -# Update cloud permissions after Cortex release updates +# Update cloud permissions after Cortex XSIAM release updates This topic provides guidance on how to manage permission updates for your cloud instances following new feature releases or bug fixes. It outlines how users are notified of required permission changes and provides step-by-step instructions for granting necessary permissions to ensure continued functionality and security. {% hint style="info" %} #### Prerequisites * Ensure that the user account used to modify permissions has the necessary privileges within both the Cortex platform and your cloud environment, for example, AWS or Azure. * You received a notification regarding a new version available that requires permission updates, or viewed a **Needs Update** status in the **Data Sources & Integrations** page. -
▸ ▾ What is the data source and connector catalog? modified +2 −2 Retitled "What is the data source and connector catalog?"; the new-tenant note now scopes hidden integrations to Palo Alto Networks managed ones.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/complete-data-source-catalogRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,15 +1,15 @@------description: >-description: >-Learn more about the complete data source and connector catalog available inLearn more about the complete data source and connector catalog available inCortex XSIAM.Cortex XSIAM.------# Complete data source and connector catalog# What is the data source and connector catalog?The complete data source catalog is a conceptual grouping that is comprised of all configuration points available for data ingestion across Cortex XSIAM. It represents the aggregate of every integration method, from unified vendor connectors and cloud onboarding wizards to generic on-premise collectors and specialized Marketplace integrations.The complete data source catalog is a conceptual grouping that is comprised of all configuration points available for data ingestion across Cortex XSIAM. It represents the aggregate of every integration method, from unified vendor connectors and cloud onboarding wizards to generic on-premise collectors and specialized Marketplace integrations.The catalog is best understood by categorizing ingestion methods into the following core groups. By consulting the specific documentation sections dedicated to each category as detailed below, you gain a complete overview of all available ingestion options that collectively form the data source and connector catalog.The catalog is best understood by categorizing ingestion methods into the following core groups. By consulting the specific documentation sections dedicated to each category as detailed below, you gain a complete overview of all available ingestion options that collectively form the data source and connector catalog.### Vendor-specific data sources and connectors### Vendor-specific data sources and connectorsThis section includes integrations for specific third-party security and IT products, such as Okta, Box, and Salesforce. These include:This section includes integrations for specific third-party security and IT products, such as Okta, Box, and Salesforce. These include:@@ -29,17 +29,17 @@ Flexible collectors for logs and data from local environments not tied to a spec• Broker VM applets, such as Syslog Collector and Database Collector, configured using the Broker VMs page.• Broker VM applets, such as Syslog Collector and Database Collector, configured using the Broker VMs page.• XDR Collectors (XDRC) for on-host log collection, configured on the XDR Collectors page.• XDR Collectors (XDRC) for on-host log collection, configured on the XDR Collectors page.### Marketplace content packs (integrations)### Marketplace content packs (integrations)Packages that offer rich security content, often including a collection integration for data ingestion alongside automation components.Packages that offer rich security content, often including a collection integration for data ingestion alongside automation components.• New Tenants: For tenants onboarded after July 26, 2026, standalone Marketplace integrations that have been consolidated into unified connectors are hidden from the catalog. Instead, these services are managed as sub-capabilities within the relevant vendor connector on the Data Sources & Integrations page to ensure a streamlined experience.• New Tenants: For tenants onboarded after July 26, 2026, standalone Marketplace integrations managed by Palo Alto Networks that have been consolidated into unified connectors are hidden from the catalog. These integrations are managed as sub-capabilities within the relevant vendor connector on the Data Sources & Integrations page. Partner and community-contributed integrations remain visible and available as standalone packs in the Marketplace catalog.• Existing Tenants: Continue to use Marketplace integrations for services not yet migrated to the connector framework for your account. These are installed from Settings → Configurations → Marketplace and configured using the Data Source Onboarder on the Data Sources & Integrations page.• Existing Tenants: Continue to use Marketplace integrations for services not yet migrated to the connector framework for your account. These are installed from Settings → Configurations → Marketplace and configured using the Data Source Onboarder on the Data Sources & Integrations page.### Palo Alto Networks integrations### Palo Alto Networks integrationsThese integrations include both traditional data sources and new unified connectors to ensure deep telemetry ingestion and seamless cross-platform orchestration across the Palo Alto Networks security stack, such as Next-Generation Firewall and Prisma Access, configured on the Data Sources & Integrations page.These integrations include both traditional data sources and new unified connectors to ensure deep telemetry ingestion and seamless cross-platform orchestration across the Palo Alto Networks security stack, such as Next-Generation Firewall and Prisma Access, configured on the Data Sources & Integrations page.### Cloud Posture and Runtime Security data sources### Cloud Posture and Runtime Security data sourcesShow markdown source
@@ -1,15 +1,15 @@ --- description: >- Learn more about the complete data source and connector catalog available in Cortex XSIAM. --- -# Complete data source and connector catalog +# What is the data source and connector catalog? The complete data source catalog is a conceptual grouping that is comprised of all configuration points available for data ingestion across Cortex XSIAM. It represents the aggregate of every integration method, from unified vendor connectors and cloud onboarding wizards to generic on-premise collectors and specialized Marketplace integrations. The catalog is best understood by categorizing ingestion methods into the following core groups. By consulting the specific documentation sections dedicated to each category as detailed below, you gain a complete overview of all available ingestion options that collectively form the data source and connector catalog. ### Vendor-specific data sources and connectors This section includes integrations for specific third-party security and IT products, such as Okta, Box, and Salesforce. These include: @@ -29,17 +29,17 @@ Flexible collectors for logs and data from local environments not tied to a spec * **Broker VM applets**, such as Syslog Collector and Database Collector, configured using the **Broker VMs** page. * **XDR Collectors (XDRC)** for on-host log collection, configured on the **XDR Collectors** page. ### Marketplace content packs (integrations) Packages that offer rich security content, often including a collection integration for data ingestion alongside automation components. -* **New Tenants**: For tenants onboarded after July 26, 2026, standalone Marketplace integrations that have been consolidated into unified connectors are hidden from the catalog. Instead, these services are managed as sub-capabilities within the relevant vendor connector on the **Data Sources & Integrations** page to ensure a streamlined experience. +* **New Tenants**: For tenants onboarded after July 26, 2026, standalone Marketplace integrations managed by Palo Alto Networks that have been consolidated into unified connectors are hidden from the catalog. These integrations are managed as sub-capabilities within the relevant vendor connector on the **Data Sources & Integrations** page. Partner and community-contributed integrations remain visible and available as standalone packs in the [Marketplace](../marketplace) catalog. * **Existing Tenants**: Continue to use Marketplace integrations for services not yet migrated to the connector framework for your account. These are installed from **Settings → Configurations → Marketplace** and configured using the Data Source Onboarder on the **Data Sources & Integrations** page. ### Palo Alto Networks integrations These integrations include both traditional data sources and new unified connectors to ensure deep telemetry ingestion and seamless cross-platform orchestration across the Palo Alto Networks security stack, such as Next-Generation Firewall and Prisma Access, configured on the **Data Sources & Integrations** page. ### Cloud Posture and Runtime Security data sources
-
▸ ▾ Connectors modified +1 −1 Adds that partner-managed and community-contributed integrations stay outside the unified connector framework as standalone integrations.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/connectorsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -33,17 +33,17 @@ When using a unified connector, you follow a guided wizard within Cortex XSIAM.• Security-capability-driven setup: If a connector wizard is available for your tenant, you can disregard the manual configuration steps on the Palo Alto Networks Developer (PAN DEV) site.• Security-capability-driven setup: If a connector wizard is available for your tenant, you can disregard the manual configuration steps on the Palo Alto Networks Developer (PAN DEV) site.• PAN DEV technical reference: While the wizard handles the setup process, you should still refer to the Cortex Developer Docs for Marketplace (PAN DEV) for specific technical information related to the service (sub-capability), such as:• PAN DEV technical reference: While the wizard handles the setup process, you should still refer to the Cortex Developer Docs for Marketplace (PAN DEV) for specific technical information related to the service (sub-capability), such as:• Fetched Incidents Data• Fetched Incidents Data• Available Commands• Available Commands• Other integration-specific data schemas and required fields not provided in the wizard.• Other integration-specific data schemas and required fields not provided in the wizard.#### Legacy Marketplace implementation#### Legacy Marketplace implementationFor integrations not yet available as a unified connector for your tenant, you will continue to use the legacy implementation. These do not feature a configuration wizard and require following the setup instructions on the Cortex Developer Docs for Marketplace (PAN DEV) site for all configuration steps. For more information, see Marketplace.For integrations that are not yet available as a unified connector for your tenant, you will continue to use the legacy implementation. Additionally, partner-managed and community-contributed integrations remain outside the unified connector framework and must be managed as standalone integrations via Marketplace. These do not feature a configuration wizard and require following the setup instructions on the Cortex Developer Docs for Marketplace (PAN DEV) site for all configuration steps. For more information, see Marketplace.### Connectivity and capabilities### Connectivity and capabilitiesUnified connectors group vendor functionality into specific security capabilities. Depending on the connector selected, the wizard will present options based on the following possible capabilities:Unified connectors group vendor functionality into specific security capabilities. Depending on the connector selected, the wizard will present options based on the following possible capabilities:• Automation and Remediation: Run automated actions and remediation commands against the connected service.• Automation and Remediation: Run automated actions and remediation commands against the connected service.• Fetch Issues: Fetch issues and incidents from the connected service for investigation and response.• Fetch Issues: Fetch issues and incidents from the connected service for investigation and response.• Log Collection: Collect and ingest logs and events from the connected service.• Log Collection: Collect and ingest logs and events from the connected service.Show markdown source
@@ -33,17 +33,17 @@ When using a unified connector, you follow a guided wizard within Cortex XSIAM. * **Security-capability-driven setup**: If a connector wizard is available for your tenant, you can disregard the manual configuration steps on the Palo Alto Networks Developer (PAN DEV) site. * **PAN DEV technical reference**: While the wizard handles the setup process, you should still refer to the [Cortex Developer Docs for Marketplace (PAN DEV)](https://cortex.marketplace.pan.dev/marketplace/) for specific technical information related to the service (sub-capability), such as: * Fetched Incidents Data * Available Commands * Other integration-specific data schemas and required fields not provided in the wizard. #### Legacy Marketplace implementation -For integrations not yet available as a unified connector for your tenant, you will continue to use the legacy implementation. These do not feature a configuration wizard and require following the setup instructions on the [Cortex Developer Docs for Marketplace (PAN DEV)](https://cortex.marketplace.pan.dev/marketplace/) site for all configuration steps. For more information, see [Marketplace](../marketplace). +For integrations that are not yet available as a unified connector for your tenant, you will continue to use the legacy implementation. Additionally, partner-managed and community-contributed integrations remain outside the unified connector framework and must be managed as standalone integrations via Marketplace. These do not feature a configuration wizard and require following the setup instructions on the [Cortex Developer Docs for Marketplace (PAN DEV)](https://cortex.marketplace.pan.dev/marketplace/) site for all configuration steps. For more information, see [Marketplace](../marketplace). ### Connectivity and capabilities Unified connectors group vendor functionality into specific security capabilities. Depending on the connector selected, the wizard will present options based on the following possible capabilities: * **Automation and Remediation**: Run automated actions and remediation commands against the connected service. * **Fetch Issues**: Fetch issues and incidents from the connected service for investigation and response. * **Log Collection**: Collect and ingest logs and events from the connected service.
-
▸ ▾ Palo Alto Networks integrations modified +1 −7 Removes the "Data collection may require an add-on" notice from the top of the page.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/palo-alto-networks-integrationsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,29 +1,23 @@------description: Configure Palo Alto Networks integrations for Cortex XSIAM.description: Configure Palo Alto Networks integrations for Cortex XSIAM.------# Palo Alto Networks integrations# Palo Alto Networks integrationsCortex XSIAM supports data ingestion and orchestration from other Palo Alto Networks products. These integrations are provided through a combination of traditional data sources and unified connectors, ensuring comprehensive visibility and seamless cross-platform security operations.Cortex XSIAM supports data ingestion and orchestration from other Palo Alto Networks products. These integrations are provided through a combination of traditional data sources and unified connectors, ensuring comprehensive visibility and seamless cross-platform security operations.hint info### NoticeData collection may require an add-on.endhint### Ingestion methods### Ingestion methodsDepending on the specific product and your tenant onboarding date, integrations are handled via the following methods:Depending on the specific product and your tenant onboarding date, integrations are handled via the following methods:• Connectors: The strategic, unified approach for integrating Palo Alto Networks services. A connector consolidates multiple security capabilities, such as Automation, Data Security, and Identity Posture, into a single, guided configuration flow.• Connectors: The strategic, unified approach for integrating Palo Alto Networks services. A connector consolidates multiple security capabilities, such as Automation, Data Security, and Identity Posture, into a single, guided configuration flow.• Availability: These connectors are available for tenants onboarded after July 26, 2026.• Availability: These connectors are available for tenants onboarded after July 26, 2026.• Legacy support: Existing tenants (onboarded prior to July 26, 2026) can achieve similar functionality by using the standalone Marketplace integrations linked within each product topic. For more information, see Marketplace.• Legacy support: Existing tenants (onboarded before July 26, 2026) can achieve similar functionality by using the standalone Marketplace integrations linked within each product topic. For more information, see Marketplace.• Traditional data sources: Cortex XSIAM supports streaming data directly from Prisma Access accounts, Prisma Access Browser, Cloud Next-Generation Firewalls (CNGFW), and Next-Generation Firewalls (NGFW), including Panorama devices, to your Cortex XSIAM tenants using the Strata Logging Service.• Traditional data sources: Cortex XSIAM supports streaming data directly from Prisma Access accounts, Prisma Access Browser, Cloud Next-Generation Firewalls (CNGFW), and Next-Generation Firewalls (NGFW), including Panorama devices, to your Cortex XSIAM tenants using the Strata Logging Service.• Direct integration: New tenants (and tenants upgraded from Cortex XDR to XSIAM) utilize the direct integration of Next-Generation Firewall, including Panorama devices, into Cortex XSIAM. For these tenants, the option to use the Strata Logging Service integration is not available.• Direct integration: New tenants (and tenants upgraded from Cortex XDR to XSIAM) utilize the direct integration of Next-Generation Firewall, including Panorama devices, into Cortex XSIAM. For these tenants, the option to use the Strata Logging Service integration is not available.• Migration from Strata Logging Service: For tenants with existing direct integrations to the Strata Logging Service, you can migrate your configurations, such as NGFW and Prisma Access, to Cortex XSIAM before your license expires. This can be done manually via the Migrate Devices buttons on the Data Sources & Integrations page (recommended more than two weeks before license expiration) or via automatic migration initiated by Cortex XSIAM two weeks prior to expiration.• Migration from Strata Logging Service: For tenants with existing direct integrations to the Strata Logging Service, you can migrate your configurations, such as NGFW and Prisma Access, to Cortex XSIAM before your license expires. This can be done manually via the Migrate Devices buttons on the Data Sources & Integrations page (recommended more than two weeks before license expiration) or via automatic migration initiated by Cortex XSIAM two weeks prior to expiration.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Roll-back of Strata Logging Service integration migration is not supported.</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Roll-back of Strata Logging Service integration migration is not supported.</p></div>#### Technical reference requirements for connectors#### Technical reference requirements for connectorsShow markdown source
@@ -1,29 +1,23 @@ --- description: Configure Palo Alto Networks integrations for Cortex XSIAM. --- # Palo Alto Networks integrations Cortex XSIAM supports data ingestion and orchestration from other Palo Alto Networks products. These integrations are provided through a combination of traditional data sources and unified connectors, ensuring comprehensive visibility and seamless cross-platform security operations. -{% hint style="info" %} -### Notice - -Data collection may require an add-on. -{% endhint %} - ### Ingestion methods Depending on the specific product and your tenant onboarding date, integrations are handled via the following methods: * **Connectors**: The strategic, unified approach for integrating Palo Alto Networks services. A connector consolidates multiple security capabilities, such as Automation, Data Security, and Identity Posture, into a single, guided configuration flow. * **Availability**: These connectors are available for tenants onboarded after July 26, 2026. - * **Legacy support**: Existing tenants (onboarded prior to July 26, 2026) can achieve similar functionality by using the standalone Marketplace integrations linked within each product topic. For more information, see [Marketplace](../marketplace). + * **Legacy support**: Existing tenants (onboarded before July 26, 2026) can achieve similar functionality by using the standalone Marketplace integrations linked within each product topic. For more information, see [Marketplace](../marketplace). * **Traditional data sources**: Cortex XSIAM supports streaming data directly from Prisma Access accounts, Prisma Access Browser, Cloud Next-Generation Firewalls (CNGFW), and Next-Generation Firewalls (NGFW), including Panorama devices, to your Cortex XSIAM tenants using the Strata Logging Service. * **Direct integration**: New tenants (and tenants upgraded from Cortex XDR to XSIAM) utilize the direct integration of Next-Generation Firewall, including Panorama devices, into Cortex XSIAM. For these tenants, the option to use the Strata Logging Service integration is not available. * **Migration from Strata Logging Service**: For tenants with existing direct integrations to the Strata Logging Service, you can migrate your configurations, such as NGFW and Prisma Access, to Cortex XSIAM before your license expires. This can be done manually via the **Migrate Devices** buttons on the **Data Sources & Integrations** page (recommended more than two weeks before license expiration) or via automatic migration initiated by Cortex XSIAM two weeks prior to expiration. <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Roll-back of Strata Logging Service integration migration is not supported.</p></div> #### Technical reference requirements for connectors -
▸ ▾ Vendor-specific data sources and connectors modified +8 −8 The Marketplace reference note is rewritten: the vendor list covers Palo Alto Networks managed connectors, not every Marketplace content pack.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectorsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -8,32 +8,32 @@ Cortex XSIAM enables you to ingest data from a wide range of third-party vendors• Connectors• Connectors• Standard data sources (also called data collectors)• Standard data sources (also called data collectors)• Cloud Service Provider (CSP) onboarding data sources• Cloud Service Provider (CSP) onboarding data sources• Content pack integrations (Marketplace)• Content pack integrations (Marketplace)In some cases, the same vendor is available through multiple options. Check the available descriptions for each entry in both the user interface and documentation to decide which option is more suitable for your needs.In some cases, the same vendor is available through multiple options. Check the available descriptions for each entry in both the user interface and documentation to decide which option is more suitable for your needs.Data Source Type│Primary Use│Configuration Method│Cortex XSIAM Features│RecommendationData Source Type│Primary Use│Configuration Method│Cortex XSIAM Features│Recommendation| --------------------------------------------------- | -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || --------------------------------------------------- | -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Connector│Unified integration for all vendor capabilities.│Configured on the Data Sources & Integrations page using a unified wizard.│Includes data ingestion, parsing, normalization, plus built-in commands, automations, and posture management.│Recommended approach for all supported vendors. Choose this for a streamlined, multi-capability setup.Connector│Unified integration for all vendor capabilities.│Configured on the Data Sources & Integrations page using a unified wizard.│Includes data ingestion, parsing, normalization, plus built-in commands, automations, and posture management.│Recommended approach for all supported vendors. Choose this for a streamlined, multi-capability setup.Standard data source (also called data collectors)│Ingesting raw logs and events.│Configured in the Data Sources & Integrations page using the Data Source Onboarder.│Limited to data ingestion, parsing, and normalization.│Choose this if you only need raw data ingestion for a service not yet covered by a unified connector.Standard data source (also called data collectors)│Ingesting raw logs and events.│Configured in the Data Sources & Integrations page using the Data Source Onboarder.│Limited to data ingestion, parsing, and normalization.│Choose this if you only need raw data ingestion for a service not yet covered by a unified connector.Cloud Service Provider (CSP) onboarding data source│Ingesting cloud assets and infrastructure logs.│Configured in the Data Sources & Integrations page using the cloud service provider (CSP) onboarding wizard.│Facilitates seamless setup of CSP data, such as AWS, Azure, GCP, and OCI, with minimal user input.│Choose this for streamlined discovery and security posture management of your cloud environments.Cloud Service Provider (CSP) onboarding data source│Ingesting cloud assets and infrastructure logs.│Configured in the Data Sources & Integrations page using the cloud service provider (CSP) onboarding wizard.│Facilitates seamless setup of CSP data, such as AWS, Azure, GCP, and OCI, with minimal user input.│Choose this for streamlined discovery and security posture management of your cloud environments.Content pack integration (Marketplace)│Ingesting data and enabling rich security functionality.│Configured via a content pack downloaded from Marketplace by either:
- Using the Data Source Onboarder on the Data Sources & Integrations page (if available)
- Installing the content pack from Settings → Configurations → Marketplace, and then configuring the integration instance on the Data Sources & Integrations page.
Primarily for existing tenants (onboarded before July 26, 2026) for services not yet migrated to the connector framework.
Choose this option for any of the following reasons:
- You need to define automations.
- You need to collect data that is not covered by a standard collector.
- You need to install rules or automations relevant to integrations or data sources.
Content pack integration (Marketplace)│Ingesting data and enabling rich security functionality.│Configured via a content pack downloaded from Marketplace by either:
- Using the Data Source Onboarder on the Data Sources & Integrations page (if available)
- Installing the content pack from Settings → Configurations → Marketplace, and then configuring the integration instance on the Data Sources & Integrations page.
Primarily used for partner-managed, community-contributed, or Palo Alto Networks managed integrations that have not yet been consolidated into a unified connector.
Choose this option for any of the following reasons:
- You need to define automations.
- You need to collect data that is not covered by a standard collector.
- You need to install rules or automations relevant to integrations or data sources.
### Availability for new tenants### Availability for new tenantsIf your Cortex XSIAM tenant was onboarded after July 26, 2026, a strategic Connector experience across the catalog is available. Standalone Marketplace integrations that have been consolidated into unified connectors are hidden from Marketplace to ensure a simplified configuration flow. For these vendors, always use the uniquely named Connector to manage all supported sub-capabilities.If your Cortex XSIAM tenant was onboarded after July 26, 2026, a strategic Connector experience is available for Palo Alto Networks managed integrations. Standalone Marketplace integrations that have been consolidated into unified connectors are hidden from Marketplace to ensure a simplified configuration flow. For these specific vendors, always use the uniquely named Connector to manage all supported sub-capabilities. Partner and community integrations remain available as standalone entries in Marketplace.### Third-party vendor list### Third-party vendor listCortex XSIAM provides specific documentation for each vendor to help you choose and configure the right connection. To ensure you have a single, unified reference point, the vendors are listed in alphabetical order and includes every supported vendor, regardless of the data source group connector, such as the Broker VM or CSP Onboarding.Cortex XSIAM provides specific documentation for each vendor to help you choose and configure the right connection. To ensure you have a single, unified reference point, the vendors are listed in alphabetical order and includes every supported vendor, regardless of the data source group connector, such as the Broker VM or CSP Onboarding.#### Keep in mind the following:#### Keep in mind the following:• Unique connector names: Each connector has its own unique name. Even if multiple connectors exist for a single vendor, they will be clearly labeled to distinguish their capabilities.• Unique connector names: Each connector has its own unique name. Even if multiple connectors exist for a single vendor, they will be clearly labeled to distinguish their capabilities.• Licensing requirements: Availability of specific connectors, capabilities, and sub-capabilities is determined by your tenant license. You will only see and be able to onboard services supported by your active license.• Licensing requirements: Availability of specific connectors, capabilities, and sub-capabilities is determined by your tenant license. You will only see and be able to onboard services supported by your active license.• Consolidated management: Regardless of whether you are using a traditional data source or a new unified connector, all active instances are managed from the Data Sources & Integrations page.• Consolidated management: Regardless of whether you are using a traditional data source or a new unified connector, all active instances are managed from the Data Sources & Integrations page.• Marketplace reference (existing tenants): For tenants onboarded prior to July 26, 2026, this list doesn't include all content pack integrations, only those shared with a traditional data source. This helps you distinguish between multiple results for the same vendor. For a complete list of all available Marketplace content packs and integrations, see the Cortex Developer Docs for Marketplace. This site provides instructions for these integrations by selecting the <content pack> → Content → Integrations, and, depending on the integration, choosing the relevant integration steps you're looking to implement. You can always install and integrate content pack integrations in Cortex XSIAM from Marketplace or the Data Sources & Integrations page, if the content pack is available from this page.• Marketplace reference: This list identifies vendors that offer Palo Alto Networks managed connectors. It does not include every available Marketplace content pack, particularly partner-managed and community-contributed integrations, which are always managed as standalone packs. To view the complete list of all available integrations, see the Cortex Developer Docs for Marketplace. This site provides instructions for these integrations by selecting the <content pack> → Content → Integrations, and choosing the relevant steps for your implementation. You can always install these standalone integrations directly from Settings → Configurations → Marketplace or the Data Sources & Integrations page (if available).• Requirement hand-off (new tenants): If your tenant was onboarded after July 26, 2026, the unified wizard handles all configuration steps. Yet, you must still refer to the Cortex Developer Docs for Marketplace for critical technical information not provided in the wizard, such as available fetched incidents data, commands, and other specific technical details related to the integration. Note that the Marketplace site may occasionally reference a different Cortex product, but the technical requirements remain applicable.• Requirement hand-off (new tenants): If your tenant was onboarded after July 26, 2026, the unified wizard handles all configuration steps. Yet, you must still refer to the Cortex Developer Docs for Marketplace for critical technical information not provided in the wizard, such as available fetched incidents data, commands, and other specific technical details related to the integration. Note that the Marketplace site may occasionally reference a different Cortex product, but the technical requirements remain applicable.
Show markdown source
@@ -8,32 +8,32 @@ Cortex XSIAM enables you to ingest data from a wide range of third-party vendors * Connectors * Standard data sources (also called data collectors) * Cloud Service Provider (CSP) onboarding data sources * Content pack integrations (Marketplace) In some cases, the same vendor is available through multiple options. Check the available descriptions for each entry in both the user interface and documentation to decide which option is more suitable for your needs. -| Data Source Type | Primary Use | Configuration Method | Cortex XSIAM Features | Recommendation | -| --------------------------------------------------- | -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Connector | Unified integration for all vendor capabilities. | Configured on the **Data Sources & Integrations** page using a unified wizard. | Includes data ingestion, parsing, normalization, plus built-in commands, automations, and posture management. | Recommended approach for all supported vendors. Choose this for a streamlined, multi-capability setup. | -| Standard data source (also called data collectors) | Ingesting raw logs and events. | Configured in the **Data Sources & Integrations** page using the Data Source Onboarder. | Limited to data ingestion, parsing, and normalization. | Choose this if you only need raw data ingestion for a service not yet covered by a unified connector. | -| Cloud Service Provider (CSP) onboarding data source | Ingesting cloud assets and infrastructure logs. | Configured in the **Data Sources & Integrations** page using the cloud service provider (CSP) onboarding wizard. | Facilitates seamless setup of CSP data, such as AWS, Azure, GCP, and OCI, with minimal user input. | Choose this for streamlined discovery and security posture management of your cloud environments. | -| Content pack integration (Marketplace) | Ingesting data and enabling rich security functionality. | <p>Configured via a content pack downloaded from Marketplace by either:</p><ul><li>Using the Data Source Onboarder on the <strong>Data Sources & Integrations</strong> page (if available)</li><li>Installing the content pack from <strong>Settings</strong> → <strong>Configurations</strong> → <strong>Marketplace</strong>, and then configuring the integration instance on the <strong>Data Sources & Integrations</strong> page.</li></ul> | Includes: Data ingestion, parsing, normalization, plus built-in commands and automations, such as playbooks, scripts, correlation rules, and data model rules. | <p>Primarily for existing tenants (onboarded before July 26, 2026) for services not yet migrated to the connector framework.</p><p>Choose this option for any of the following reasons:</p><ul><li>You need to define automations.</li><li>You need to collect data that is not covered by a standard collector.</li><li>You need to install rules or automations relevant to integrations or data sources.</li></ul> | +| Data Source Type | Primary Use | Configuration Method | Cortex XSIAM Features | Recommendation | +| --------------------------------------------------- | -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Connector | Unified integration for all vendor capabilities. | Configured on the **Data Sources & Integrations** page using a unified wizard. | Includes data ingestion, parsing, normalization, plus built-in commands, automations, and posture management. | Recommended approach for all supported vendors. Choose this for a streamlined, multi-capability setup. | +| Standard data source (also called data collectors) | Ingesting raw logs and events. | Configured in the **Data Sources & Integrations** page using the Data Source Onboarder. | Limited to data ingestion, parsing, and normalization. | Choose this if you only need raw data ingestion for a service not yet covered by a unified connector. | +| Cloud Service Provider (CSP) onboarding data source | Ingesting cloud assets and infrastructure logs. | Configured in the **Data Sources & Integrations** page using the cloud service provider (CSP) onboarding wizard. | Facilitates seamless setup of CSP data, such as AWS, Azure, GCP, and OCI, with minimal user input. | Choose this for streamlined discovery and security posture management of your cloud environments. | +| Content pack integration (Marketplace) | Ingesting data and enabling rich security functionality. | <p>Configured via a content pack downloaded from Marketplace by either:</p><ul><li>Using the Data Source Onboarder on the <strong>Data Sources & Integrations</strong> page (if available)</li><li>Installing the content pack from <strong>Settings</strong> → <strong>Configurations</strong> → <strong>Marketplace</strong>, and then configuring the integration instance on the <strong>Data Sources & Integrations</strong> page.</li></ul> | Includes: Data ingestion, parsing, normalization, plus built-in commands and automations, such as playbooks, scripts, correlation rules, and data model rules. | <p>Primarily used for partner-managed, community-contributed, or Palo Alto Networks managed integrations that have not yet been consolidated into a unified connector.</p><p>Choose this option for any of the following reasons:</p><ul><li>You need to define automations.</li><li>You need to collect data that is not covered by a standard collector.</li><li>You need to install rules or automations relevant to integrations or data sources.</li></ul> | ### Availability for new tenants -If your Cortex XSIAM tenant was onboarded after July 26, 2026, a strategic Connector experience across the catalog is available. Standalone Marketplace integrations that have been consolidated into unified connectors are hidden from Marketplace to ensure a simplified configuration flow. For these vendors, always use the uniquely named Connector to manage all supported sub-capabilities. +If your Cortex XSIAM tenant was onboarded after July 26, 2026, a strategic Connector experience is available for Palo Alto Networks managed integrations. Standalone Marketplace integrations that have been consolidated into unified connectors are hidden from Marketplace to ensure a simplified configuration flow. For these specific vendors, always use the uniquely named Connector to manage all supported sub-capabilities. Partner and community integrations remain available as standalone entries in [Marketplace](../marketplace). ### Third-party vendor list Cortex XSIAM provides specific documentation for each vendor to help you choose and configure the right connection. To ensure you have a single, unified reference point, the vendors are listed in alphabetical order and includes every supported vendor, regardless of the data source group connector, such as the Broker VM or CSP Onboarding. #### Keep in mind the following: * **Unique connector names**: Each connector has its own unique name. Even if multiple connectors exist for a single vendor, they will be clearly labeled to distinguish their capabilities. * **Licensing requirements**: Availability of specific connectors, capabilities, and sub-capabilities is determined by your tenant license. You will only see and be able to onboard services supported by your active license. * **Consolidated management**: Regardless of whether you are using a traditional data source or a new unified connector, all active instances are managed from the **Data Sources & Integrations** page. -* **Marketplace reference (existing tenants)**: For tenants onboarded prior to July 26, 2026, this list doesn't include all content pack integrations, only those shared with a traditional data source. This helps you distinguish between multiple results for the same vendor. For a complete list of all available Marketplace content packs and integrations, see the [Cortex Developer Docs for Marketplace](https://cortex.marketplace.pan.dev/marketplace/). This site provides instructions for these integrations by selecting the **\<content pack>** → **Content** → **Integrations**, and, depending on the integration, choosing the relevant integration steps you're looking to implement. You can always install and integrate content pack integrations in Cortex XSIAM from Marketplace or the **Data Sources & Integrations** page, if the content pack is available from this page. +* **Marketplace reference:** This list identifies vendors that offer Palo Alto Networks managed connectors. It does not include every available Marketplace content pack, particularly partner-managed and community-contributed integrations, which are always managed as standalone packs. To view the complete list of all available integrations, see the [Cortex Developer Docs for Marketplace](https://cortex.marketplace.pan.dev/marketplace/). This site provides instructions for these integrations by selecting the <**content pack>** → **Content** → **Integrations**, and choosing the relevant steps for your implementation. You can always install these standalone integrations directly from **Settings → Configurations → Marketplace** or the **Data Sources & Integrations** page (if available). * **Requirement hand-off (new tenants)**: If your tenant was onboarded after July 26, 2026, the unified wizard handles all configuration steps. Yet, you must still refer to the [Cortex Developer Docs for Marketplace](https://cortex.marketplace.pan.dev/marketplace/) for critical technical information not provided in the wizard, such as available fetched incidents data, commands, and other specific technical details related to the integration. Note that the Marketplace site may occasionally reference a different Cortex product, but the technical requirements remain applicable. ***
-
▸ ▾ What are Cortex XSIAM data sources and connectors? modified +3 −3 Scopes the hidden-from-catalog integrations to Palo Alto Networks managed ones and drops "legacy" from the standalone implementation note.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/what-are-cortex-xsiam-data-sourcesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -7,47 +7,47 @@ description: >-# What are Cortex XSIAM data sources and connectors?# What are Cortex XSIAM data sources and connectors?Data sources and connectors are the foundational mechanisms used to ingest security and operational data, including logs, events, and asset metadata, into Cortex XSIAM for analysis, correlation, and response. By consolidating data from diverse origins like endpoints, network devices, cloud environments, and third-party security tools, Cortex XSIAM constructs a comprehensive and contextualized security story.Data sources and connectors are the foundational mechanisms used to ingest security and operational data, including logs, events, and asset metadata, into Cortex XSIAM for analysis, correlation, and response. By consolidating data from diverse origins like endpoints, network devices, cloud environments, and third-party security tools, Cortex XSIAM constructs a comprehensive and contextualized security story.### Customer availability by tenant type### Customer availability by tenant typeThe ingestion methods and configuration options available to you in the UI depend on your tenant onboarding date:The ingestion methods and configuration options available to you in the UI depend on your tenant onboarding date:• New tenants (onboarded after July 26, 2026): You will primarily interact with the strategic Connector experience. Standalone Marketplace integrations that have been consolidated into connectors are hidden from the catalog to ensure a unified configuration flow.• New tenants (onboarded after July 26, 2026): You will primarily interact with the strategic Connector experience. Standalone Marketplace integrations managed by Palo Alto Networks that have been consolidated into connectors are hidden from the catalog to ensure a unified configuration flow. Partner and community-contributed integrations remain available as standalone packs.• Existing tenants (onboarded before July 26, 2026): You will continue to see both standalone Marketplace integrations and unified Connectors. Refer to the specific documentation for each vendor to determine the supported configuration method for your account.• Existing tenants (onboarded before July 26, 2026): You will continue to see both standalone Marketplace integrations and unified Connectors. Refer to the specific documentation for each vendor to determine the supported configuration method for your account.### Clarifying terminology: Data sources and connectors### Clarifying terminology: Data sources and connectorsIn the Cortex XSIAM user interface (UI), configuring ingestion involves different areas and terminologies depending on the type of connection and your tenant onboarding date. While Cortex XSIAM is introducing connectors as a new, unified approach to ingestion, traditional data source methods remain supported.In the Cortex XSIAM user interface (UI), configuring ingestion involves different areas and terminologies depending on the type of connection and your tenant onboarding date. While Cortex XSIAM is introducing connectors as a new, unified approach to ingestion, traditional data source methods remain supported.In the current intermediate state, it is important to understand how these terms relate to each other:In the current intermediate state, it is important to understand how these terms relate to each other:• Data sources: Represents the traditional method for any integration that provides data to Cortex XSIAM. In this documentation, Data Source is used as the category for these ingestion methods, which include:• Data sources: Represents the traditional method for any integration that provides data to Cortex XSIAM. In this documentation, Data Source is used as the category for these ingestion methods, which include:• Data collectors: Built-in tools primarily focused on raw log ingestion. This includes generic logs ingested via XDR Collectors and core ingestion functionalities found using the Data Source Onboarder.• Data collectors: Built-in tools primarily focused on raw log ingestion. This includes generic logs ingested via XDR Collectors and core ingestion functionalities found using the Data Source Onboarder.• Broker VM applets: Specialized applications running on the Broker VM that function as collectors, such as the Syslog Collector.• Broker VM applets: Specialized applications running on the Broker VM that function as collectors, such as the Syslog Collector.• Marketplace (integrations): Content packs that include collection integrations. These are often referred to as data sources in the UI, as integrations that fetch data are configured through the Data Source Onboarder on the Data Sources & Integrations page.• Marketplace (integrations): Content packs that include collection integrations. These are often referred to as data sources in the UI, as integrations that fetch data are configured through the Data Source Onboarder on the Data Sources & Integrations page.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This legacy implementation is primarily available to existing customers; new customers (onboarded after July 26, 2026) will use the new Connectors framework for these services (see <a href="#customer-availability-by-tenant-type">Customer availability by tenant type</a> above).</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This implementation is primarily available to existing customers; new customers (onboarded after July 26, 2026) will use the new Connectors framework for Palo Alto Networks managed integrations (see <a href="#customer-availability-by-tenant-type">Customer availability by tenant type</a> above). Partner and community-contributed integrations remain available via the <a href="../marketplace">Marketplace</a>.</p></div>• Connectors: The new, unified mechanism for data ingestion. For supported vendors, a Connector groups multiple security capabilities, such as logs, automation, and posture into a single, uniquely named entry with a guided configuration wizard.• Connectors: The new, unified mechanism for data ingestion. For supported vendors, a Connector groups multiple security capabilities, such as logs, automation, and posture into a single, uniquely named entry with a guided configuration wizard.While specific components like Data Collectors, Broker VM applets, and Connectors are named explicitly when discussing their unique configuration workflows, they all fall under the foundational goal of ingesting data into Cortex XSIAM.While specific components like Data Collectors, Broker VM applets, and Connectors are named explicitly when discussing their unique configuration workflows, they all fall under the foundational goal of ingesting data into Cortex XSIAM.### Why are different data sources and connectors necessary?### Why are different data sources and connectors necessary?Cortex XSIAM enables you to collect data across a vast and varied enterprise landscape. This necessitates distinct data source types and connectors designed for different environments and needs:Cortex XSIAM enables you to collect data across a vast and varied enterprise landscape. This necessitates distinct data source types and connectors designed for different environments and needs:• Connectors: Streamline the onboarding of third-party services by grouping multiple capabilities, such as log collection, automation, posture management, into a single, uniquely named entry with a guided configuration wizard. This unified approach represents the strategic method for all new vendor integrations.• Connectors: Streamline the onboarding of third-party services by grouping multiple capabilities, such as log collection, automation, posture management, into a single, uniquely named entry with a guided configuration wizard. This unified approach represents the strategic method for all new vendor integrations.• Standard data collectors (API/Built-in): These are built-in functionalities primarily focused on ingesting raw logs and security events for core security analysis, parsing, and normalization. They often involve direct API connections, such as Okta and CrowdStrike, or file collection tools, such as Amazon S3.• Standard data collectors (API/Built-in): These are built-in functionalities primarily focused on ingesting raw logs and security events for core security analysis, parsing, and normalization. They often involve direct API connections, such as Okta and CrowdStrike, or file collection tools, such as Amazon S3.• Broker VM data collector applets: These are modular applications installed on a local Broker VM virtual appliance, designed for on-premise data collection needs like the Syslog Collector or Database Collector.• Broker VM data collector applets: These are modular applications installed on a local Broker VM virtual appliance, designed for on-premise data collection needs like the Syslog Collector or Database Collector.• XDR Collectors (XDRC): These are lightweight agents dedicated to on-premise log collection on Windows and Linux host machines, typically gathering logs and events using tools such as Filebeat or Winlogbeat.• XDR Collectors (XDRC): These are lightweight agents dedicated to on-premise log collection on Windows and Linux host machines, typically gathering logs and events using tools such as Filebeat or Winlogbeat.• Cloud Service Provider (CSP) Onboarding: These are specialized wizards for integrating cloud environments, such as AWS, Azure, GCP, and OCI, enabling streamlined setup for asset discovery, posture/runtime security, and log collection.• Cloud Service Provider (CSP) Onboarding: These are specialized wizards for integrating cloud environments, such as AWS, Azure, GCP, and OCI, enabling streamlined setup for asset discovery, posture/runtime security, and log collection.• Marketplace content packs: These packages offer specialized security functionality by bundling both a collection integration (for data ingestion) and automation components, such as playbooks and correlation rules.• Marketplace content packs: These packages offer specialized security functionality by bundling both a collection integration (for data ingestion) and automation components, such as playbooks and correlation rules.<div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Standalone Marketplace integrations are primarily used by existing customers (onboarded before July 26, 2026). New customers will find these services consolidated within the new Connector framework.</p></div><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Standalone Marketplace integrations managed by Palo Alto Networks are primarily used by existing customers (onboarded before July 26, 2026). New customers will find these integrations consolidated within the new Connector framework, while partner and community integrations continue to be available as standalone <a href="../marketplace">Marketplace</a> content packs.</p></div>• Palo Alto Networks Integrations: Cortex XSIAM provides both standard data sources and new unified connectors for Palo Alto Networks products to ensure deep telemetry ingestion and seamless cross-platform orchestration.• Palo Alto Networks Integrations: Cortex XSIAM provides both standard data sources and new unified connectors for Palo Alto Networks products to ensure deep telemetry ingestion and seamless cross-platform orchestration.• Cloud Posture and Runtime Security data sources: These data sources provide agentless visibility and real-time control over cloud risks by using cloud-native APIs to monitor misconfigurations, scan container registries, and secure serverless functions or sensitive data across multi-cloud environments.• Cloud Posture and Runtime Security data sources: These data sources provide agentless visibility and real-time control over cloud risks by using cloud-native APIs to monitor misconfigurations, scan container registries, and secure serverless functions or sensitive data across multi-cloud environments.### Current UI and future direction### Current UI and future directionCortex XSIAM is transitioning toward a unified ingestion experience. While Cortex XSIAM is moving toward a model where all data sources and integrations are unified into the Connector framework, different ingestion methods currently involve distinct configuration workflows and locations in the UI.Cortex XSIAM is transitioning toward a unified ingestion experience. While Cortex XSIAM is moving toward a model where all data sources and integrations are unified into the Connector framework, different ingestion methods currently involve distinct configuration workflows and locations in the UI.The following table summarizes the different ingestion methods and where to manage them:The following table summarizes the different ingestion methods and where to manage them:Show markdown source
@@ -7,47 +7,47 @@ description: >- # What are Cortex XSIAM data sources and connectors? Data sources and connectors are the foundational mechanisms used to ingest security and operational data, including logs, events, and asset metadata, into Cortex XSIAM for analysis, correlation, and response. By consolidating data from diverse origins like endpoints, network devices, cloud environments, and third-party security tools, Cortex XSIAM constructs a comprehensive and contextualized security story. ### **Customer availability by tenant type** The ingestion methods and configuration options available to you in the UI depend on your tenant onboarding date: -* **New tenants (onboarded after July 26, 2026)**: You will primarily interact with the strategic Connector experience. Standalone Marketplace integrations that have been consolidated into connectors are hidden from the catalog to ensure a unified configuration flow. +* **New tenants (onboarded after July 26, 2026)**: You will primarily interact with the strategic Connector experience. Standalone Marketplace integrations managed by Palo Alto Networks that have been consolidated into connectors are hidden from the catalog to ensure a unified configuration flow. Partner and community-contributed integrations remain available as standalone packs. * **Existing tenants (onboarded before July 26, 2026)**: You will continue to see both standalone Marketplace integrations and unified Connectors. Refer to the specific documentation for each vendor to determine the supported configuration method for your account. ### **Clarifying terminology: Data sources and connectors** In the Cortex XSIAM user interface (UI), configuring ingestion involves different areas and terminologies depending on the type of connection and your tenant onboarding date. While Cortex XSIAM is introducing connectors as a new, unified approach to ingestion, traditional data source methods remain supported. In the current intermediate state, it is important to understand how these terms relate to each other: * **Data sources**: Represents the traditional method for any integration that provides data to Cortex XSIAM. In this documentation, Data Source is used as the category for these ingestion methods, which include: * **Data collectors**: Built-in tools primarily focused on raw log ingestion. This includes generic logs ingested via XDR Collectors and core ingestion functionalities found using the Data Source Onboarder. * **Broker VM applets**: Specialized applications running on the Broker VM that function as collectors, such as the Syslog Collector. * **Marketplace (integrations)**: Content packs that include collection integrations. These are often referred to as data sources in the UI, as integrations that fetch data are configured through the Data Source Onboarder on the **Data Sources & Integrations** page. - <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This legacy implementation is primarily available to existing customers; new customers (onboarded after July 26, 2026) will use the new Connectors framework for these services (see <a href="#customer-availability-by-tenant-type">Customer availability by tenant type</a> above).</p></div> + <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>This implementation is primarily available to existing customers; new customers (onboarded after July 26, 2026) will use the new Connectors framework for Palo Alto Networks managed integrations (see <a href="#customer-availability-by-tenant-type">Customer availability by tenant type</a> above). Partner and community-contributed integrations remain available via the <a href="../marketplace">Marketplace</a>.</p></div> * **Connectors**: The new, unified mechanism for data ingestion. For supported vendors, a Connector groups multiple security capabilities, such as logs, automation, and posture into a single, uniquely named entry with a guided configuration wizard. While specific components like Data Collectors, Broker VM applets, and Connectors are named explicitly when discussing their unique configuration workflows, they all fall under the foundational goal of ingesting data into Cortex XSIAM. ### **Why are different data sources and connectors necessary?** Cortex XSIAM enables you to collect data across a vast and varied enterprise landscape. This necessitates distinct data source types and connectors designed for different environments and needs: * **Connectors**: Streamline the onboarding of third-party services by grouping multiple capabilities, such as log collection, automation, posture management, into a single, uniquely named entry with a guided configuration wizard. This unified approach represents the strategic method for all new vendor integrations. * **Standard data collectors (API/Built-in)**: These are built-in functionalities primarily focused on ingesting raw logs and security events for core security analysis, parsing, and normalization. They often involve direct API connections, such as Okta and CrowdStrike, or file collection tools, such as Amazon S3. * **Broker VM data collector applets**: These are modular applications installed on a local Broker VM virtual appliance, designed for on-premise data collection needs like the Syslog Collector or Database Collector. * **XDR Collectors (XDRC)**: These are lightweight agents dedicated to on-premise log collection on Windows and Linux host machines, typically gathering logs and events using tools such as Filebeat or Winlogbeat. * **Cloud Service Provider (CSP) Onboarding**: These are specialized wizards for integrating cloud environments, such as AWS, Azure, GCP, and OCI, enabling streamlined setup for asset discovery, posture/runtime security, and log collection. * **Marketplace content packs**: These packages offer specialized security functionality by bundling both a collection integration (for data ingestion) and automation components, such as playbooks and correlation rules. - <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Standalone Marketplace integrations are primarily used by existing customers (onboarded before July 26, 2026). New customers will find these services consolidated within the new Connector framework.</p></div> + <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>Standalone Marketplace integrations managed by Palo Alto Networks are primarily used by existing customers (onboarded before July 26, 2026). New customers will find these integrations consolidated within the new Connector framework, while partner and community integrations continue to be available as standalone <a href="../marketplace">Marketplace</a> content packs.</p></div> * **Palo Alto Networks Integrations**: Cortex XSIAM provides both standard data sources and new unified connectors for Palo Alto Networks products to ensure deep telemetry ingestion and seamless cross-platform orchestration. * **Cloud Posture and Runtime Security data sources**: These data sources provide agentless visibility and real-time control over cloud risks by using cloud-native APIs to monitor misconfigurations, scan container registries, and secure serverless functions or sensitive data across multi-cloud environments. ### **Current UI and future direction** Cortex XSIAM is transitioning toward a unified ingestion experience. While Cortex XSIAM is moving toward a model where all data sources and integrations are unified into the Connector framework, different ingestion methods currently involve distinct configuration workflows and locations in the UI. The following table summarizes the different ingestion methods and where to manage them:
-
▸ ▾ Choose an Agentic Assistant agent modified +1 −1 Expands the Help Center agent entry to troubleshooting across the Cortex suite, diagnosing tenant security, health and workflows.
xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat/choose-an-agentic-assistant-agentRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -39,17 +39,17 @@ If a system agent is missing from your chat, it may be disabled or not includedExamples of specialized system agents:Examples of specialized system agents:Agent Type│DescriptionAgent Type│Description| ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |IT│Automates identity lifecycle enforcement, real-time containment on endpoints and networks, vulnerability and patch governance, asset intelligence upkeep, and end-to-end incident workflow coordination—delivering policy-driven remediation across the enterprise.IT│Automates identity lifecycle enforcement, real-time containment on endpoints and networks, vulnerability and patch governance, asset intelligence upkeep, and end-to-end incident workflow coordination—delivering policy-driven remediation across the enterprise.Case Investigation│Accelerate and simplify the analyst's workflow by converting complex data points, case context, and event relationships into clear, actionable insights. It understands the whole structure of a case, automatically highlights what matters most, and offers concise summaries that reduce noise and cognitive load. Beyond interpretation, it provides quick-access actions and guided steps that help analysts progress investigations with confidence and consistency. Its strength comes from its ability to reason across diverse evidence, stitch narrative context, and translate technical signals into meaningful next moves - enabling a smoother, more intuitive investigation experience end to end.Case Investigation│Accelerate and simplify the analyst's workflow by converting complex data points, case context, and event relationships into clear, actionable insights. It understands the whole structure of a case, automatically highlights what matters most, and offers concise summaries that reduce noise and cognitive load. Beyond interpretation, it provides quick-access actions and guided steps that help analysts progress investigations with confidence and consistency. Its strength comes from its ability to reason across diverse evidence, stitch narrative context, and translate technical signals into meaningful next moves - enabling a smoother, more intuitive investigation experience end to end.Email Investigation│Automates the full lifecycle of email-borne threat response, spanning mailbox search, forensic collection, analysis, containment, and incident closure across all major mail platforms and security layers.Email Investigation│Automates the full lifecycle of email-borne threat response, spanning mailbox search, forensic collection, analysis, containment, and incident closure across all major mail platforms and security layers.Threat Intel│Gathers fresh threat data, enriches indicators and vulnerabilities, links them to past or current incidents, and publishes clear briefings so the whole SOC acts on the latest attacker tactics.Threat Intel│Gathers fresh threat data, enriches indicators and vulnerabilities, links them to past or current incidents, and publishes clear briefings so the whole SOC acts on the latest attacker tactics.Help Center│Provides answers to questions by referencing product documentation. If further assistance is needed, the agent assists you in opening a support case.Help Center│An AI-powered assistant that helps you troubleshoot issues across the entire Cortex product suite through natural language conversation. Using official documentation, the agent diagnoses your tenant's security, health, and workflows to deliver data-backed guidance and automatically prefill support tickets.
Access the Help Center Agent from Help → Get Support, or by clicking the Agentic Assistant icon in the top-right corner of the tenant and choosing the Help Center agent.Network Security│Audits next-gen firewalls for vulnerabilities, expired certificates, outdated software, risky or unused rules, capacity limits, and other misconfigurations. It searches logs for threats and then automates or guides clean-ups and upgrades to keep the network secure.Network Security│Audits next-gen firewalls for vulnerabilities, expired certificates, outdated software, risky or unused rules, capacity limits, and other misconfigurations. It searches logs for threats and then automates or guides clean-ups and upgrades to keep the network secure.Exposure Management│Helps understand, triage, and remediate vulnerabilities and misconfigurations across enterprise and cloud. Streamlines work for security analysts by helping to proactively prioritize risks, enrich identified exposures with ownership information, and take actions to reduce remediation times.
Note
Requires the Exposure Management add-on.
Exposure Management│Helps understand, triage, and remediate vulnerabilities and misconfigurations across enterprise and cloud. Streamlines work for security analysts by helping to proactively prioritize risks, enrich identified exposures with ownership information, and take actions to reduce remediation times.
Note
Requires the Exposure Management add-on.
Cloud Posture│Helps understand, triage, and remediate misconfigurations, attack paths, and posture issues across cloud environments. Streamlines work for security analysts by proactively prioritizing risks, enriching identified exposures with ownership information, and automatically taking mitigating or remediating actions, such as blocking network access or updating protection policies, to reduce the organization's exposure footprint.Cloud Posture│Helps understand, triage, and remediate misconfigurations, attack paths, and posture issues across cloud environments. Streamlines work for security analysts by proactively prioritizing risks, enriching identified exposures with ownership information, and automatically taking mitigating or remediating actions, such as blocking network access or updating protection policies, to reduce the organization's exposure footprint.Application Security│Operates as an intelligent, autonomous co-pilot within the security program. It provides full-cycle management by continuously monitoring AppSec maturity and driving a prevention-first strategy. The agent performs key actions such as opening pull requests (PRs) to resolve issues, identifying true risks and critical weaknesses in code, and using that context to suggest and apply prevention guardrails that eliminate risky environments. Its core function is to guide the organization’s AppSec journey by proactively improving coverage and measuring maturity, ensuring that security is automated, not merely audited.Application Security│Operates as an intelligent, autonomous co-pilot within the security program. It provides full-cycle management by continuously monitoring AppSec maturity and driving a prevention-first strategy. The agent performs key actions such as opening pull requests (PRs) to resolve issues, identifying true risks and critical weaknesses in code, and using that context to suggest and apply prevention guardrails that eliminate risky environments. Its core function is to guide the organization’s AppSec journey by proactively improving coverage and measuring maturity, ensuring that security is automated, not merely audited.Endpoint Investigation│Unifies host-level containment, forensic collection, and remediation across all major EDR/XDR platforms while feeding evidence and status into the SOC's ticketing and collaboration stack.Endpoint Investigation│Unifies host-level containment, forensic collection, and remediation across all major EDR/XDR platforms while feeding evidence and status into the SOC's ticketing and collaboration stack.Recommended agentsRecommended agentsShow markdown source
@@ -39,17 +39,17 @@ If a system agent is missing from your chat, it may be disabled or not included Examples of specialized system agents: | Agent Type | Description | | ---------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | IT | Automates identity lifecycle enforcement, real-time containment on endpoints and networks, vulnerability and patch governance, asset intelligence upkeep, and end-to-end incident workflow coordination—delivering policy-driven remediation across the enterprise. | | Case Investigation | Accelerate and simplify the analyst's workflow by converting complex data points, case context, and event relationships into clear, actionable insights. It understands the whole structure of a case, automatically highlights what matters most, and offers concise summaries that reduce noise and cognitive load. Beyond interpretation, it provides quick-access actions and guided steps that help analysts progress investigations with confidence and consistency. Its strength comes from its ability to reason across diverse evidence, stitch narrative context, and translate technical signals into meaningful next moves - enabling a smoother, more intuitive investigation experience end to end. | | Email Investigation | Automates the full lifecycle of email-borne threat response, spanning mailbox search, forensic collection, analysis, containment, and incident closure across all major mail platforms and security layers. | | Threat Intel | Gathers fresh threat data, enriches indicators and vulnerabilities, links them to past or current incidents, and publishes clear briefings so the whole SOC acts on the latest attacker tactics. | -| Help Center | Provides answers to questions by referencing product documentation. If further assistance is needed, the agent assists you in opening a support case. | +| Help Center | <p>An AI-powered assistant that helps you troubleshoot issues across the entire Cortex product suite through natural language conversation. Using official documentation, the agent diagnoses your tenant's security, health, and workflows to deliver data-backed guidance and automatically prefill support tickets.<br>Access the Help Center Agent from <strong>Help</strong> → <strong>Get Support</strong>, or by clicking the <strong>Agentic Assistant</strong> icon in the top-right corner of the tenant and choosing the Help Center agent.</p> | | Network Security | Audits next-gen firewalls for vulnerabilities, expired certificates, outdated software, risky or unused rules, capacity limits, and other misconfigurations. It searches logs for threats and then automates or guides clean-ups and upgrades to keep the network secure. | | Exposure Management | <p>Helps understand, triage, and remediate vulnerabilities and misconfigurations across enterprise and cloud. Streamlines work for security analysts by helping to proactively prioritize risks, enrich identified exposures with ownership information, and take actions to reduce remediation times.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>Requires the Exposure Management add-on.</p></div> | | Cloud Posture | Helps understand, triage, and remediate misconfigurations, attack paths, and posture issues across cloud environments. Streamlines work for security analysts by proactively prioritizing risks, enriching identified exposures with ownership information, and automatically taking mitigating or remediating actions, such as blocking network access or updating protection policies, to reduce the organization's exposure footprint. | | Application Security | Operates as an intelligent, autonomous co-pilot within the security program. It provides full-cycle management by continuously monitoring AppSec maturity and driving a prevention-first strategy. The agent performs key actions such as opening pull requests (PRs) to resolve issues, identifying true risks and critical weaknesses in code, and using that context to suggest and apply prevention guardrails that eliminate risky environments. Its core function is to guide the organization’s AppSec journey by proactively improving coverage and measuring maturity, ensuring that security is automated, not merely audited. | | Endpoint Investigation | Unifies host-level containment, forensic collection, and remediation across all major EDR/XDR platforms while feeding evidence and status into the SOC's ticketing and collaboration stack. | **Recommended agents**
-
▸ ▾ Enable access to required PANW resources modified +1 −1 The FQDN, IP address and App-ID table's leading "Egress" label cell is now empty.
xsiam/onboard-cortex-xsiam/deployment-steps/activate-cortex-xsiam/enable-access-to-required-panw-resourcesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -21,9 +21,9 @@ Before configuring your firewall, review these guidelines:• SSL decryption: If you use SSL decryption and experience difficulty connecting the Cortex XDR agent to the server, we recommend that you add the FQDNs required for access to your SSL Decryption Exclusion list in Device → Certificate Management → SSL Decryption Exclusion.• SSL decryption: If you use SSL decryption and experience difficulty connecting the Cortex XDR agent to the server, we recommend that you add the FQDNs required for access to your SSL Decryption Exclusion list in Device → Certificate Management → SSL Decryption Exclusion.hint infohint info<tenant-name>refers to the selected subdomain of your Cortex XSIAM tenant, and<region>is the region in which your tenant is deployed. For more information, see Cortex XSIAM supported regions.<tenant-name>refers to the selected subdomain of your Cortex XSIAM tenant, and<region>is the region in which your tenant is deployed. For more information, see Cortex XSIAM supported regions.endhintendhintThe following tables list required FQDNs, IP addresses, ports, and App-ID coverage for your deployment.The following tables list required FQDNs, IP addresses, ports, and App-ID coverage for your deployment.FQDN IP Addresses and Port App-ID Coverage Egress <tenant-name>.xdr.<region>.paloaltonetworks.comUsed to connect to the Cortex XSIAM tenant.
IP address by region:
- US (United States): 35.244.250.18:443
- EU (Europe): 35.227.237.180:443
- CA (Canada): 34.120.31.199:443
- UK (United Kingdom): 34.120.87.77:443
- JP (Japan): 35.241.28.254:443
- SG (Singapore): 34.117.211.129:443
- AU (Australia): 34.120.229.65:443
- DE (Germany): 34.98.68.183:443
- IN (India): 35.186.207.80:443
- DL (Delhi): 34.8.67.192:443
- CH (Switzerland): 34.111.6.153:443
- PL (Poland): 34.117.240.208:443
- TW (Taiwan): 34.160.28.41:443
- QT (Qatar): 35.190.0.180:443
- FA (France): 34.111.134.57:443
- IL (Israel): 34.111.129.144:443
- SA (Saudi Arabia): 35.244.157.127:443
- ID (Indonesia): 34.111.58.152:443
- ES (Spain): 34.111.188.248:443
- IT (Italy): 34.8.224.70:443
- KR (South Korea): 34.54.5.247:443
- ZA (South Africa): 34.149.165.12:443
- BR (Brazil): 34.96.83.202:443
- FI (Finland):
34.160.63.63:443
cortex-xdrdistributions.traps.paloaltonetworks.comUsed for the first request in registration flow where the agent passes the distribution id and obtains the
ch-<tenant-name>.traps.paloaltonetworks.comof its tenant.- IP address: 35.223.6.69
- Port: 443
traps-management-servicehttps://lrc-<region>.paloaltonetworks.comwss://lrc-<region>.paloaltonetworks.comUsed in live terminal flow.
IP address by region:
- US (United States): 35.190.88.43:443
- EU (Europe): 35.244.251.25:443
- CA (Canada): 35.203.99.74:443
- UK (United Kingdom): 35.242.159.176:443
- JP (Japan): 34.84.201.32:443
- SG (Singapore): 34.87.61.186:443
- AU (Australia): 35.244.66.177:443
- DE (Germany): 34.107.61.141:443
- IN (India): 35.200.146.253:443
- DL (Delhi): 34.131.116.135:443
- CH (Switzerland): 34.65.213.226:443
- PL (Poland): 34.118.62.80:443
- TW (Taiwan): 34.80.34.30:443
- QT (Qatar): 34.18.34.73:443
- FA (France): 34.163.57.57:443
- IL (Israel): 34.165.43.106:443
- SA (Saudi Arabia): 34.166.54.6:443
- ID (Indonesia): 34.101.214.157:443
- ES (Spain): 34.175.18.78:443
- IT (Italy): 34.154.154.5:443
- KR (South Korea): 34.22.66.91:443
- ZA (South Africa): 34.35.56.170:443
- BR (Brazil): 34.151.236.197:443
- FI (Finland):
34.88.31.230:443
cortex-xdrpanw-xdr-installers-prod-us.storage.googleapis.comUsed to download installers for upgrade actions from the server.
This storage bucket is used for all regions.
- IP ranges in GCP
- Port: 443
cortex-xdrpanw-xdr-payloads-prod-us.storage.googleapis.comUsed to download the executable for the live terminal for XDR agents earlier than version 7.1.0.
This storage bucket is used for all regions.
- IP ranges in GCP
- Port: 443
cortex-xdrglobal-content-profiles-policy.storage.googleapis.comUsed to download content updates.
- IP ranges in GCP
- Port: 443
cortex-xdrpanw-xdr-evr-prod-<region>.storage.googleapis.comUsed to download extended verdict request results in scanning.
- IP ranges in GCP
- Port: 443
cortex-xdrhttps://<region>-docker.pkg.devUsed to download the Kubernetes image from the registry for Kubernetes agents installation.
Refer to Regional Docker registry mapping for your specific tenant location and corresponding Docker registry URL.
- IP ranges in GCP
- Port: 443
Regional Docker registry mapping Tenant location GCP region Registry URL UK
Netherlands (EU)
United States (US)
Canada (CA)
South Korea (KR)
Singapore (SG)
Australia (AU)
Japan (JP)
India (IN)
Germany (DE)
France (FR)
Finland (FI)europe-west2
europe-west4
us-central1
northamerica-northeast1
asia-northeast3
asia-southeast1
australia-southeast1
asia-northeast1
asia-south1
europe-west3
europe-west9
europe-north1europe-west2-docker.pkg.dev
europe-west4-docker.pkg.dev
us-central1-docker.pkg.dev
northamerica-northeast1-docker.pkg.dev
asia-northeast3-docker.pkg.dev
asia-southeast1-docker.pkg.dev
australia-southeast1-docker.pkg.dev
asia-northeast1-docker.pkg.dev
asia-south1-docker.pkg.dev
europe-west3-docker.pkg.dev
europe-west9-docker.pkg.dev
dc-<tenant-name>.traps.paloaltonetworks.comUsed for EDR data upload.
IP address by region:
- US (United States): 34.98.77.231:443
- EU (Europe): 34.102.140.103:443
- CA (Canada): 34.96.120.25:443
- UK (United Kingdom): 35.244.133.254:443
- JP (Japan): 34.95.66.187:443
- SG (Singapore): 34.120.142.18:443
- AU (Australia): 34.102.237.151:443
- DE (Germany): 34.107.161.143:443
- IN (India): 34.120.213.187:443
- DL (Delhi): 136.110.132.208:443
- CH (Switzerland): 34.149.180.250:443
- PL (Poland): 35.190.13.237:443
- TW (Taiwan): 34.149.248.76:443
- QT (Qatar): 34.107.129.254:443
- FA (France): 34.36.155.211:443
- IL (Israel): 34.128.157.130:443
- SA (Saudi Arabia): 34.107.213.85:443
- ID (Indonesia): 34.128.156.84:443
- ES (Spain): 34.120.102.147:443
- IT (Italy): 34.8.234.58:443
- KR (South Korea): 34.54.155.245:443
- ZA (South Africa): 35.190.79.68:443
- BR (Brazil): 136.110.146.246:443
- FI (Finland):
136.110.165.34:443
traps-management-servicech-<tenant-name>.traps.paloaltonetworks.comUsed for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports.
IP address by region:
- US (United States): 34.98.77.231:443
- EU (Europe): 34.102.140.103:443
- CA (Canada): 34.96.120.25:443
- UK (United Kingdom): 35.244.133.254:443
- JP (Japan): 34.95.66.187:443
- SG (Singapore): 34.120.142.18:443
- AU (Australia): 34.102.237.151:443
- DE (Germany): 34.107.161.143:443
- IN (India): 34.120.213.188:443
- DL (Delhi): 136.110.132.208:443
- CH (Switzerland): 34.149.180.250:443
- PL (Poland): 35.190.13.237:443
- TW (Taiwan): 34.149.248.76:443
- QT (Qatar): 34.107.129.254:443
- FA (France): 34.36.155.211:443
- IL (Israel): 34.128.157.130:443
- SA (Saudi Arabia): 34.107.213.85:443
- ID (Indonesia): 34.128.156.84:443
- ES (Spain): 34.120.102.147:443
- IT (Italy): 34.8.234.58:443
- KR (South Korea): 34.54.155.245:443
- ZA (South Africa): 35.190.79.68:443
- BR (Brazil): 136.110.146.246:443
- FI (Finland):
136.110.165.34:443
traps-management-serviceapi-<tenant-name>.xdr.<region>.paloaltonetworks.comUsed for API requests and responses and to connect to an engine.
IP address by region:
- US (United States): 35.222.81.194:443
- EU (Europe): 34.90.67.58:443
- CA (Canada): 35.203.82.121:443
- UK (United Kingdom): 34.89.56.78:443
- JP (Japan): 34.84.125.129:443
- SG (Singapore): 34.87.83.144:443
- AU (Australia): 35.189.18.208:443
- DE (Germany): 34.107.57.23:443
- IN (India): 35.200.158.164:443
- DL (Delhi): 34.131.165.103:443
- CH (Switzerland): 34.65.248.119:443
- PL (Poland): 34.116.216.55:443
- TW (Taiwan): 35.234.8.249:443
- QT (Qatar): 34.18.46.240:443
- FA (France): 34.155.222.152:443
- IL (Israel): 34.165.156.139:443
- SA (Saudi Arabia): 34.166.58.79:443
- ID (Indonesia): 34.128.115.238:443
- ES (Spain): 34.175.30.176:443
- IT (Italy): 34.154.195.120:443
- KR (South Korea): 34.64.54.175:443
- ZA (South Africa): 34.35.64.191:443
- BR (Brazil): 34.39.136.78:443
- FI (Finland):
35.228.73.215:443
— cc-<tenant-name>.traps.paloaltonetworks.comUsed for get-verdict requests.
For agents on endpoints, you must allow the IP address for the closest region to ensure connectivity. Endpoints use latency-based routing. An agent that belongs to a US tenant, for example, but that is physically located in Singapore, routes to Singapore to get the verdict.
IP address by region:
- US (United States): 35.224.140.142:443
- EU (Europe): 34.90.71.103:443
- CA (Canada): 35.203.35.23:443
- UK (United Kingdom): 34.89.42.214:443
- JP (Japan): 34.84.225.105:443
- SG (Singapore): 35.247.161.94:443
- AU (Australia): 35.201.23.188:443
- DE (Germany): 35.242.201.199:443
- IN (India): 35.244.57.196:443
- DL (Delhi): 34.131.47.126:443
- CH (Switzerland): 34.65.137.215:443
- PL (Poland): 34.116.213.71:443
- TW (Taiwan): 35.229.186.216:443
- QT (Qatar): 34.18.53.229:443
- FA (France): 34.155.110.169:443
- IL (Israel): 34.165.2.110:443
- SA (Saudi Arabia): 34.166.53.160:443
- ID (Indonesia): 34.101.155.198:443
- ES (Spain): 34.175.205.166:443
- IT (Italy): 34.154.230.76:443
- KR (South Korea): 34.64.228.117:443
- ZA (South Africa): 34.35.13.198:443
- BR (Brazil): 34.39.195.104:443
- FI (Finland):
35.228.118.177:443
traps-management-servicexdr-<region>-<project ID>-tim-indicators.storage.googleapis.comUsed to download the IOC indicators from the tenant.
IP address by region:
- US (United States): 35.224.140.142:443
- EU (Europe): 34.90.71.103:443
- CA (Canada): 35.203.35.23:443
- UK (United Kingdom): 34.89.42.214:443
- JP (Japan): 34.84.225.105:443
- SG (Singapore): 35.247.161.94:443
- AU (Australia): 35.201.23.188:443
- DE (Germany): 35.242.201.199:443
- IN (India): 35.244.57.196:443
- DL (Delhi): 34.131.47.126:443
- CH (Switzerland): 34.65.137.215:443
- PL (Poland): 34.116.213.71:443
- TW (Taiwan): 35.229.186.216:443
- QT (Qatar): 34.18.53.229:443
- FA (France): 34.155.110.169:443
- IL (Israel): 34.165.2.110:443
- SA (Saudi Arabia): 34.166.53.160:443
- ID (Indonesia): 34.101.155.198:443
- ES (Spain): 34.175.205.166:443
- IT (Italy): 34.154.230.76:443
- KR (South Korea): 34.64.228.117:443
- ZA (South Africa): 34.35.13.198:443
- BR (Brazil): 34.39.195.104:443
- FI (Finland):
35.228.118.177:443
cortex-xdrBroker VM Resources
Required for deployments that use Broker VM features
xdr-ova-installers-prod-us.storage.googleapis.com
Used to download Broker VM images from the server.
This storage bucket is used for all regions.
- IP ranges in GCP
- Port: 443
cortex-xdrbr-<tenant-name>.xdr.<region>.paloaltonetworks.comIP address by region:
- US (United States): 104.155.131.72:443
- EU (Europe): 34.91.128.226:443
- CA (Canada): 34.95.8.232:443
- UK (United Kingdom): 35.197.219.110:443
- JP (Japan):34.85.74.43:443
- SG (Singapore): 34.87.167.125:443
- AU (Australia): 35.244.93.0:443
- DE (Germany): 35.198.112.13:443
- IN (India): 35.200.234.99:443
- DL (Delhi): 34.131.131.141:443
- CH (Switzerland): 34.65.51.103:443
- PL (Poland): 34.116.176.97:443
- TW (Taiwan): 34.80.230.166:443
- QT (Qatar): 34.18.37.73:443
- FA (France): 34.155.90.61:443
- IL (Israel): 34.165.24.222:443
- SA (Saudi Arabia): 34.166.55.153:443
- ID (Indonesia): 34.101.101.170:443
- ES (Spain): 34.175.182.55:443
- IT (Italy): 34.154.168.139:443
- KR (South Korea): 34.64.46.249:443
- ZA (South Africa): 34.35.45.251:443
- BR (Brazil): 35.198.38.182:443
- FI (Finland):
34.88.26.246:443
— distributions.traps.paloaltonetworks.com- IP address: 35.223.6.69
- Port: 443
traps-management-servicetime.google.compool.ntp.org
UDP port: 123 — App Login and Authentication identity.paloaltonetworks.com
(SSO)
- IP address: 34.120.119.85
- Port: 443
— login.paloaltonetworks.com
(SSO)
- IP address: 34.102.139.110
- Port: 443
— In-App Help Center and Notifications data.pendo.io Port: 443 — pendo-static-5664029141630976.storage.googleapis.com Port: 443 — Email Notifications — IP address for all regions: 159.183.150.248 — Ingress
These IPs are used for communication between Cortex XSIAM and your resources. Use them when sending data out from your tenant.
FI (Finland):
- 34.88.97.182
- 34.88.189.1
US (United States)
- 34.132.108.184
- 34.69.63.16
EU (Europe)
- 34.147.107.51
- 34.91.26.125
CA (Canada)
- 35.203.108.13
- 35.203.101.162
UK (United Kingdom)
- 35.242.180.163
- 34.105.173.229
JP (Japan)
- 35.200.3.131
- 34.146.181.233
SG (Singapore)
- 35.240.243.57
- 34.126.183.208
AU (Australia)
- 34.151.83.236
- 34.116.67.90
DE (Germany)
- 35.234.118.195
- 34.89.183.45
IN (India)
- 35.200.175.78
- 34.93.9.198
CH (Switzerland)
- 34.65.108.153
- 34.65.155.169
PL (Poland)
- 34.118.48.171
- 34.116.202.235
TW (Taiwan)
- 34.80.133.68
- 35.234.18.10
QT (Qatar)
- 34.18.34.118
- 34.18.39.155
FA (France)
- 34.155.5.117
- 34.155.41.247
IL (Israel)
- 34.165.33.165
- 34.165.27.131
SA (Saudi Arabia)
- 34.166.61.81
- 34.166.58.213
ID (Indonesia)
- 34.128.126.138
- 34.128.82.158
ES (Spain)
- 34.175.46.46
- 34.175.80.182
IT (Italy)
- 34.154.23.156
- 34.154.186.12
KR (South Korea)
- 34.64.93.168
- 34.64.237.45
ZA (South Africa):
- 34.35.42.196
- 34.35.79.219
cortex-xdrOutbound IPs for engines IP addresses by region
FI (Finland)
- 35.228.175.228
- 35.228.44.44
US (United States)
- 35.225.156.101
- 34.69.88.119
EU (Europe)
- 34.147.67.188
- 34.90.16.31
CA (Canada)
- 35.203.57.162
- 35.203.90.79
UK (United Kingdom)
- 34.142.3.42
- 34.142.44.136
JP (Japan)
- 34.146.60.215
- 34.84.93.160
SG (Singapore)
- 35.240.144.192
- 35.240.255.15
AU (Australia)
- 35.244.73.76
- 35.201.22.63
DE (Germany)
- 34.107.83.197
- 34.159.53.97
IN (India)
- 35.244.5.205
- 34.93.118.113
DL (Delhi)
- 34.131.207.151
- 34.126.212.40
CH (Switzerland)
- 34.65.222.25
- 34.65.233.60
PL (Poland)
- 34.118.92.214
- 34.116.223.119
TW (Taiwan)
- 104.199.223.229
- 34.81.38.132
QT (Qatar)
- 34.18.39.0
- 34.18.32.96
FA (France)
- 34.155.197.131
- 34.155.5.100
IL (Israel)
- 34.165.46.47
- 34.165.17.246
SA (Saudi Arabia)
- 34.166.58.243
- 34.166.54.238
ID (Indonesia)
- 34.101.125.66
- 34.101.218.184
ES (Spain)
- 34.175.255.99
- 34.175.230.35
IT (Italy)
- 34.154.173.134
- 34.154.229.60
KR (South Korea)
- 34.64.189.205
- 34.64.45.118
ZA (South Africa)
- 34.35.70.193
- 34.35.80.189
BR (Brazil)
- 35.199.96.109
- 34.39.161.254
— Collect third-party data from your SaaS and Cloud resources — IP address by region.
FI (Finland)
- 35.228.192.167
- 34.88.193.126
US (United States)
- 34.66.69.154
- 35.202.21.123
AU (Australia)
- 35.197.181.108
- 35.197.175.44
CA (Canada)
- 34.95.33.72
- 34.95.62.136
SG (Singapore)
- 35.247.148.38
- 35.247.173.40
JP (Japan)
- 34.85.68.167
- 34.84.99.239
IN (India)
- 34.93.3.196
- 34.93.175.218
DL (Delhi)
- 34.131.111.87
- 34.131.101.138
DE (Germany)
- 34.89.197.46
- 34.107.3.224
UK (United Kingdom)
- 34.105.227.146
- 34.105.137.22
EU (Europe)
- 34.90.70.107
- 35.204.129.196
CH (Switzerland)
- 34.65.225.124
- 34.65.89.6
PL (Poland)
- 34.118.71.237
- 34.118.124.130
TW (Taiwan)
- 35.201.142.86
- 35.189.176.163
QT (Qatar)
- 34.18.44.71
- 34.18.30.132
FA (France)
- 34.163.125.167
- 34.163.155.105
IL (Israel)
- 34.165.131.171
- 34.165.120.206
SA (Saudi Arabia)
- 34.166.59.20
- 34.166.53.242
ID (Indonesia)
- 34.101.158.32
- 34.101.79.159
ES (Spain)
- 34.175.27.251
- 34.175.198.50
IT (Italy)
- 34.154.208.247
- 34.154.243.11
KR (South Korea)
- 34.64.107.163
- 34.64.84.25
ZA (South Africa):
- 34.35.69.156
- 34.35.60.86
BR (Brazil)
- 34.39.177.125
- 34.39.140.36
cortex-xdrLog Forwarding to a Syslog Receiver See Integrate a syslog receiver. FQDN IP Addresses and Port App-ID Coverage <tenant-name>.xdr.<region>.paloaltonetworks.comUsed to send data from external services and systems to the Cortex tenant.
IP address by region:
- US (United States): 35.244.250.18:443
- EU (Europe): 35.227.237.180:443
- CA (Canada): 34.120.31.199:443
- UK (United Kingdom): 34.120.87.77:443
- JP (Japan): 35.241.28.254:443
- SG (Singapore): 34.117.211.129:443
- AU (Australia): 34.120.229.65:443
- DE (Germany): 34.98.68.183:443
- IN (India): 35.186.207.80:443
- DL (Delhi): 34.8.67.192:443
- CH (Switzerland): 34.111.6.153:443
- PL (Poland): 34.117.240.208:443
- TW (Taiwan): 34.160.28.41:443
- QT (Qatar): 35.190.0.180:443
- FA (France): 34.111.134.57:443
- IL (Israel): 34.111.129.144:443
- SA (Saudi Arabia): 35.244.157.127:443
- ID (Indonesia): 34.111.58.152:443
- ES (Spain): 34.111.188.248:443
- IT (Italy): 34.8.224.70:443
- KR (South Korea): 34.54.5.247:443
- ZA (South Africa): 34.149.165.12:443
- BR (Brazil): 34.96.83.202:443
- FI (Finland):
34.160.63.63:443
cortex-xdrdistributions.traps.paloaltonetworks.comUsed for the first request in registration flow where the agent passes the distribution id and obtains the
ch-<tenant-name>.traps.paloaltonetworks.comof its tenant.- IP address: 35.223.6.69
- Port: 443
traps-management-servicehttps://lrc-<region>.paloaltonetworks.comwss://lrc-<region>.paloaltonetworks.comUsed in live terminal flow.
IP address by region:
- US (United States): 35.190.88.43:443
- EU (Europe): 35.244.251.25:443
- CA (Canada): 35.203.99.74:443
- UK (United Kingdom): 35.242.159.176:443
- JP (Japan): 34.84.201.32:443
- SG (Singapore): 34.87.61.186:443
- AU (Australia): 35.244.66.177:443
- DE (Germany): 34.107.61.141:443
- IN (India): 35.200.146.253:443
- DL (Delhi): 34.131.116.135:443
- CH (Switzerland): 34.65.213.226:443
- PL (Poland): 34.118.62.80:443
- TW (Taiwan): 34.80.34.30:443
- QT (Qatar): 34.18.34.73:443
- FA (France): 34.163.57.57:443
- IL (Israel): 34.165.43.106:443
- SA (Saudi Arabia): 34.166.54.6:443
- ID (Indonesia): 34.101.214.157:443
- ES (Spain): 34.175.18.78:443
- IT (Italy): 34.154.154.5:443
- KR (South Korea): 34.22.66.91:443
- ZA (South Africa): 34.35.56.170:443
- BR (Brazil): 34.151.236.197:443
- FI (Finland):
34.88.31.230:443
cortex-xdrpanw-xdr-installers-prod-us.storage.googleapis.comUsed to download installers for upgrade actions from the server.
This storage bucket is used for all regions.
- IP ranges in GCP
- Port: 443
cortex-xdrpanw-xdr-payloads-prod-us.storage.googleapis.comUsed to download the executable for the live terminal for XDR agents earlier than version 7.1.0.
This storage bucket is used for all regions.
- IP ranges in GCP
- Port: 443
cortex-xdrglobal-content-profiles-policy.storage.googleapis.comUsed to download content updates.
- IP ranges in GCP
- Port: 443
cortex-xdrpanw-xdr-evr-prod-<region>.storage.googleapis.comUsed to download extended verdict request results in scanning.
- IP ranges in GCP
- Port: 443
cortex-xdrhttps://<region>-docker.pkg.devUsed to download the Kubernetes image from the registry for Kubernetes agents installation.
Refer to Regional Docker registry mapping for your specific tenant location and corresponding Docker registry URL.
- IP ranges in GCP
- Port: 443
Regional Docker registry mapping Tenant location GCP region Registry URL UK
Netherlands (EU)
United States (US)
Canada (CA)
South Korea (KR)
Singapore (SG)
Australia (AU)
Japan (JP)
India (IN)
Germany (DE)
France (FR)
Finland (FI)europe-west2
europe-west4
us-central1
northamerica-northeast1
asia-northeast3
asia-southeast1
australia-southeast1
asia-northeast1
asia-south1
europe-west3
europe-west9
europe-north1europe-west2-docker.pkg.dev
europe-west4-docker.pkg.dev
us-central1-docker.pkg.dev
northamerica-northeast1-docker.pkg.dev
asia-northeast3-docker.pkg.dev
asia-southeast1-docker.pkg.dev
australia-southeast1-docker.pkg.dev
asia-northeast1-docker.pkg.dev
asia-south1-docker.pkg.dev
europe-west3-docker.pkg.dev
europe-west9-docker.pkg.dev
dc-<tenant-name>.traps.paloaltonetworks.comUsed for EDR data upload.
IP address by region:
- US (United States): 34.98.77.231:443
- EU (Europe): 34.102.140.103:443
- CA (Canada): 34.96.120.25:443
- UK (United Kingdom): 35.244.133.254:443
- JP (Japan): 34.95.66.187:443
- SG (Singapore): 34.120.142.18:443
- AU (Australia): 34.102.237.151:443
- DE (Germany): 34.107.161.143:443
- IN (India): 34.120.213.187:443
- DL (Delhi): 136.110.132.208:443
- CH (Switzerland): 34.149.180.250:443
- PL (Poland): 35.190.13.237:443
- TW (Taiwan): 34.149.248.76:443
- QT (Qatar): 34.107.129.254:443
- FA (France): 34.36.155.211:443
- IL (Israel): 34.128.157.130:443
- SA (Saudi Arabia): 34.107.213.85:443
- ID (Indonesia): 34.128.156.84:443
- ES (Spain): 34.120.102.147:443
- IT (Italy): 34.8.234.58:443
- KR (South Korea): 34.54.155.245:443
- ZA (South Africa): 35.190.79.68:443
- BR (Brazil): 136.110.146.246:443
- FI (Finland):
136.110.165.34:443
traps-management-servicech-<tenant-name>.traps.paloaltonetworks.comUsed for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports.
IP address by region:
- US (United States): 34.98.77.231:443
- EU (Europe): 34.102.140.103:443
- CA (Canada): 34.96.120.25:443
- UK (United Kingdom): 35.244.133.254:443
- JP (Japan): 34.95.66.187:443
- SG (Singapore): 34.120.142.18:443
- AU (Australia): 34.102.237.151:443
- DE (Germany): 34.107.161.143:443
- IN (India): 34.120.213.188:443
- DL (Delhi): 136.110.132.208:443
- CH (Switzerland): 34.149.180.250:443
- PL (Poland): 35.190.13.237:443
- TW (Taiwan): 34.149.248.76:443
- QT (Qatar): 34.107.129.254:443
- FA (France): 34.36.155.211:443
- IL (Israel): 34.128.157.130:443
- SA (Saudi Arabia): 34.107.213.85:443
- ID (Indonesia): 34.128.156.84:443
- ES (Spain): 34.120.102.147:443
- IT (Italy): 34.8.234.58:443
- KR (South Korea): 34.54.155.245:443
- ZA (South Africa): 35.190.79.68:443
- BR (Brazil): 136.110.146.246:443
- FI (Finland):
136.110.165.34:443
traps-management-serviceapi-<tenant-name>.xdr.<region>.paloaltonetworks.comUsed for API requests and responses and to connect to an engine.
IP address by region:
- US (United States): 35.222.81.194:443
- EU (Europe): 34.90.67.58:443
- CA (Canada): 35.203.82.121:443
- UK (United Kingdom): 34.89.56.78:443
- JP (Japan): 34.84.125.129:443
- SG (Singapore): 34.87.83.144:443
- AU (Australia): 35.189.18.208:443
- DE (Germany): 34.107.57.23:443
- IN (India): 35.200.158.164:443
- DL (Delhi): 34.131.165.103:443
- CH (Switzerland): 34.65.248.119:443
- PL (Poland): 34.116.216.55:443
- TW (Taiwan): 35.234.8.249:443
- QT (Qatar): 34.18.46.240:443
- FA (France): 34.155.222.152:443
- IL (Israel): 34.165.156.139:443
- SA (Saudi Arabia): 34.166.58.79:443
- ID (Indonesia): 34.128.115.238:443
- ES (Spain): 34.175.30.176:443
- IT (Italy): 34.154.195.120:443
- KR (South Korea): 34.64.54.175:443
- ZA (South Africa): 34.35.64.191:443
- BR (Brazil): 34.39.136.78:443
- FI (Finland):
35.228.73.215:443
— cc-<tenant-name>.traps.paloaltonetworks.comUsed for get-verdict requests.
For agents on endpoints, you must allow the IP address for the closest region to ensure connectivity. Endpoints use latency-based routing. An agent that belongs to a US tenant, for example, but that is physically located in Singapore, routes to Singapore to get the verdict.
IP address by region:
- US (United States): 35.224.140.142:443
- EU (Europe): 34.90.71.103:443
- CA (Canada): 35.203.35.23:443
- UK (United Kingdom): 34.89.42.214:443
- JP (Japan): 34.84.225.105:443
- SG (Singapore): 35.247.161.94:443
- AU (Australia): 35.201.23.188:443
- DE (Germany): 35.242.201.199:443
- IN (India): 35.244.57.196:443
- DL (Delhi): 34.131.47.126:443
- CH (Switzerland): 34.65.137.215:443
- PL (Poland): 34.116.213.71:443
- TW (Taiwan): 35.229.186.216:443
- QT (Qatar): 34.18.53.229:443
- FA (France): 34.155.110.169:443
- IL (Israel): 34.165.2.110:443
- SA (Saudi Arabia): 34.166.53.160:443
- ID (Indonesia): 34.101.155.198:443
- ES (Spain): 34.175.205.166:443
- IT (Italy): 34.154.230.76:443
- KR (South Korea): 34.64.228.117:443
- ZA (South Africa): 34.35.13.198:443
- BR (Brazil): 34.39.195.104:443
- FI (Finland):
35.228.118.177:443
traps-management-servicexdr-<region>-<project ID>-tim-indicators.storage.googleapis.comUsed to download the IOC indicators from the tenant.
IP address by region:
- US (United States): 35.224.140.142:443
- EU (Europe): 34.90.71.103:443
- CA (Canada): 35.203.35.23:443
- UK (United Kingdom): 34.89.42.214:443
- JP (Japan): 34.84.225.105:443
- SG (Singapore): 35.247.161.94:443
- AU (Australia): 35.201.23.188:443
- DE (Germany): 35.242.201.199:443
- IN (India): 35.244.57.196:443
- DL (Delhi): 34.131.47.126:443
- CH (Switzerland): 34.65.137.215:443
- PL (Poland): 34.116.213.71:443
- TW (Taiwan): 35.229.186.216:443
- QT (Qatar): 34.18.53.229:443
- FA (France): 34.155.110.169:443
- IL (Israel): 34.165.2.110:443
- SA (Saudi Arabia): 34.166.53.160:443
- ID (Indonesia): 34.101.155.198:443
- ES (Spain): 34.175.205.166:443
- IT (Italy): 34.154.230.76:443
- KR (South Korea): 34.64.228.117:443
- ZA (South Africa): 34.35.13.198:443
- BR (Brazil): 34.39.195.104:443
- FI (Finland):
35.228.118.177:443
cortex-xdrBroker VM Resources
Required for deployments that use Broker VM features
xdr-ova-installers-prod-us.storage.googleapis.com
Used to download Broker VM images from the server.
This storage bucket is used for all regions.
- IP ranges in GCP
- Port: 443
cortex-xdrbr-<tenant-name>.xdr.<region>.paloaltonetworks.comIP address by region:
- US (United States): 104.155.131.72:443
- EU (Europe): 34.91.128.226:443
- CA (Canada): 34.95.8.232:443
- UK (United Kingdom): 35.197.219.110:443
- JP (Japan):34.85.74.43:443
- SG (Singapore): 34.87.167.125:443
- AU (Australia): 35.244.93.0:443
- DE (Germany): 35.198.112.13:443
- IN (India): 35.200.234.99:443
- DL (Delhi): 34.131.131.141:443
- CH (Switzerland): 34.65.51.103:443
- PL (Poland): 34.116.176.97:443
- TW (Taiwan): 34.80.230.166:443
- QT (Qatar): 34.18.37.73:443
- FA (France): 34.155.90.61:443
- IL (Israel): 34.165.24.222:443
- SA (Saudi Arabia): 34.166.55.153:443
- ID (Indonesia): 34.101.101.170:443
- ES (Spain): 34.175.182.55:443
- IT (Italy): 34.154.168.139:443
- KR (South Korea): 34.64.46.249:443
- ZA (South Africa): 34.35.45.251:443
- BR (Brazil): 35.198.38.182:443
- FI (Finland):
34.88.26.246:443
— distributions.traps.paloaltonetworks.com- IP address: 35.223.6.69
- Port: 443
traps-management-servicetime.google.compool.ntp.org
UDP port: 123 — App Login and Authentication identity.paloaltonetworks.com
(SSO)
- IP address: 34.120.119.85
- Port: 443
— login.paloaltonetworks.com
(SSO)
- IP address: 34.102.139.110
- Port: 443
— In-App Help Center and Notifications data.pendo.io Port: 443 — pendo-static-5664029141630976.storage.googleapis.com Port: 443 — Email Notifications — IP address for all regions: 159.183.150.248 — Ingress
These IPs are used for communication between Cortex XSIAM and your resources. Use them when sending data out from your tenant.
FI (Finland):
- 34.88.97.182
- 34.88.189.1
US (United States)
- 34.132.108.184
- 34.69.63.16
EU (Europe)
- 34.147.107.51
- 34.91.26.125
CA (Canada)
- 35.203.108.13
- 35.203.101.162
UK (United Kingdom)
- 35.242.180.163
- 34.105.173.229
JP (Japan)
- 35.200.3.131
- 34.146.181.233
SG (Singapore)
- 35.240.243.57
- 34.126.183.208
AU (Australia)
- 34.151.83.236
- 34.116.67.90
DE (Germany)
- 35.234.118.195
- 34.89.183.45
IN (India)
- 35.200.175.78
- 34.93.9.198
CH (Switzerland)
- 34.65.108.153
- 34.65.155.169
PL (Poland)
- 34.118.48.171
- 34.116.202.235
TW (Taiwan)
- 34.80.133.68
- 35.234.18.10
QT (Qatar)
- 34.18.34.118
- 34.18.39.155
FA (France)
- 34.155.5.117
- 34.155.41.247
IL (Israel)
- 34.165.33.165
- 34.165.27.131
SA (Saudi Arabia)
- 34.166.61.81
- 34.166.58.213
ID (Indonesia)
- 34.128.126.138
- 34.128.82.158
ES (Spain)
- 34.175.46.46
- 34.175.80.182
IT (Italy)
- 34.154.23.156
- 34.154.186.12
KR (South Korea)
- 34.64.93.168
- 34.64.237.45
ZA (South Africa):
- 34.35.42.196
- 34.35.79.219
cortex-xdrEgress IP addresses
Used for traffic from the Cortex tenant to external services and systems. Add the relevant IP addresses from this list to your allow lists for your external services and systems.IP addresses by region
FI (Finland)
- 35.228.175.228
- 35.228.44.44
US (United States)
- 35.225.156.101
- 34.69.88.119
EU (Europe)
- 34.147.67.188
- 34.90.16.31
CA (Canada)
- 35.203.57.162
- 35.203.90.79
UK (United Kingdom)
- 34.142.3.42
- 34.142.44.136
JP (Japan)
- 34.146.60.215
- 34.84.93.160
SG (Singapore)
- 35.240.144.192
- 35.240.255.15
AU (Australia)
- 35.244.73.76
- 35.201.22.63
DE (Germany)
- 34.107.83.197
- 34.159.53.97
IN (India)
- 35.244.5.205
- 34.93.118.113
DL (Delhi)
- 34.131.207.151
- 34.126.212.40
CH (Switzerland)
- 34.65.222.25
- 34.65.233.60
PL (Poland)
- 34.118.92.214
- 34.116.223.119
TW (Taiwan)
- 104.199.223.229
- 34.81.38.132
QT (Qatar)
- 34.18.39.0
- 34.18.32.96
FA (France)
- 34.155.197.131
- 34.155.5.100
IL (Israel)
- 34.165.46.47
- 34.165.17.246
SA (Saudi Arabia)
- 34.166.58.243
- 34.166.54.238
ID (Indonesia)
- 34.101.125.66
- 34.101.218.184
ES (Spain)
- 34.175.255.99
- 34.175.230.35
IT (Italy)
- 34.154.173.134
- 34.154.229.60
KR (South Korea)
- 34.64.189.205
- 34.64.45.118
ZA (South Africa)
- 34.35.70.193
- 34.35.80.189
BR (Brazil)
- 35.199.96.109
- 34.39.161.254
— Collect third-party data from your SaaS and Cloud resources — IP address by region.
FI (Finland)
- 35.228.192.167
- 34.88.193.126
US (United States)
- 34.66.69.154
- 35.202.21.123
AU (Australia)
- 35.197.181.108
- 35.197.175.44
CA (Canada)
- 34.95.33.72
- 34.95.62.136
SG (Singapore)
- 35.247.148.38
- 35.247.173.40
JP (Japan)
- 34.85.68.167
- 34.84.99.239
IN (India)
- 34.93.3.196
- 34.93.175.218
DL (Delhi)
- 34.131.111.87
- 34.131.101.138
DE (Germany)
- 34.89.197.46
- 34.107.3.224
UK (United Kingdom)
- 34.105.227.146
- 34.105.137.22
EU (Europe)
- 34.90.70.107
- 35.204.129.196
CH (Switzerland)
- 34.65.225.124
- 34.65.89.6
PL (Poland)
- 34.118.71.237
- 34.118.124.130
TW (Taiwan)
- 35.201.142.86
- 35.189.176.163
QT (Qatar)
- 34.18.44.71
- 34.18.30.132
FA (France)
- 34.163.125.167
- 34.163.155.105
IL (Israel)
- 34.165.131.171
- 34.165.120.206
SA (Saudi Arabia)
- 34.166.59.20
- 34.166.53.242
ID (Indonesia)
- 34.101.158.32
- 34.101.79.159
ES (Spain)
- 34.175.27.251
- 34.175.198.50
IT (Italy)
- 34.154.208.247
- 34.154.243.11
KR (South Korea)
- 34.64.107.163
- 34.64.84.25
ZA (South Africa):
- 34.35.69.156
- 34.35.60.86
BR (Brazil)
- 34.39.177.125
- 34.39.140.36
cortex-xdrLog Forwarding to a Syslog Receiver See Integrate a syslog receiver. Show markdown source
@@ -21,9 +21,9 @@ Before configuring your firewall, review these guidelines: * SSL decryption: If you use SSL decryption and experience difficulty connecting the Cortex XDR agent to the server, we recommend that you add the FQDNs required for access to your SSL Decryption Exclusion list in Device → Certificate Management → **SSL Decryption Exclusion**. {% hint style="info" %} _**`<tenant-name>`**_ refers to the selected subdomain of your Cortex XSIAM tenant, and _**`<region>`**_ is the region in which your tenant is deployed. For more information, see [Cortex XSIAM supported regions](cortex-xsiam-supported-regions). {% endhint %} The following tables list required FQDNs, IP addresses, ports, and App-ID coverage for your deployment. -<table><thead><tr><th>FQDN</th><th width="265">IP Addresses and Port</th><th>App-ID Coverage</th></tr></thead><tbody><tr><td><strong>Egress</strong></td><td></td><td></td></tr><tr><td><p><em><strong><code><tenant-name></code></strong></em><strong><code>.xdr.</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used to connect to the Cortex XSIAM tenant.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.244.250.18:443</li><li>EU (Europe): 35.227.237.180:443</li><li>CA (Canada): 34.120.31.199:443</li><li>UK (United Kingdom): 34.120.87.77:443</li><li>JP (Japan): 35.241.28.254:443</li><li>SG (Singapore): 34.117.211.129:443</li><li>AU (Australia): 34.120.229.65:443</li><li>DE (Germany): 34.98.68.183:443</li><li>IN (India): 35.186.207.80:443</li><li>DL (Delhi): 34.8.67.192:443</li><li>CH (Switzerland): 34.111.6.153:443</li><li>PL (Poland): 34.117.240.208:443</li><li>TW (Taiwan): 34.160.28.41:443</li><li>QT (Qatar): 35.190.0.180:443</li><li>FA (France): 34.111.134.57:443</li><li>IL (Israel): 34.111.129.144:443</li><li>SA (Saudi Arabia): 35.244.157.127:443</li><li>ID (Indonesia): 34.111.58.152:443</li><li>ES (Spain): 34.111.188.248:443</li><li>IT (Italy): 34.8.224.70:443</li><li>KR (South Korea): 34.54.5.247:443</li><li>ZA (South Africa): 34.149.165.12:443</li><li>BR (Brazil): 34.96.83.202:443</li><li>FI (Finland):<br>34.160.63.63:443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>distributions.traps.paloaltonetworks.com</code></strong></p><p>Used for the first request in registration flow where the agent passes the distribution id and obtains the <strong><code>ch-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong> of its tenant.</p></td><td><ul><li>IP address: 35.223.6.69</li><li>Port: 443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><p><strong><code>https://lrc-</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p><strong><code>wss://lrc-</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used in live terminal flow.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.190.88.43:443</li><li>EU (Europe): 35.244.251.25:443</li><li>CA (Canada): 35.203.99.74:443</li><li>UK (United Kingdom): 35.242.159.176:443</li><li>JP (Japan): 34.84.201.32:443</li><li>SG (Singapore): 34.87.61.186:443</li><li>AU (Australia): 35.244.66.177:443</li><li>DE (Germany): 34.107.61.141:443</li><li>IN (India): 35.200.146.253:443</li><li>DL (Delhi): 34.131.116.135:443</li><li>CH (Switzerland): 34.65.213.226:443</li><li>PL (Poland): 34.118.62.80:443</li><li>TW (Taiwan): 34.80.34.30:443</li><li>QT (Qatar): 34.18.34.73:443</li><li>FA (France): 34.163.57.57:443</li><li>IL (Israel): 34.165.43.106:443</li><li>SA (Saudi Arabia): 34.166.54.6:443</li><li>ID (Indonesia): 34.101.214.157:443</li><li>ES (Spain): 34.175.18.78:443</li><li>IT (Italy): 34.154.154.5:443</li><li>KR (South Korea): 34.22.66.91:443</li><li>ZA (South Africa): 34.35.56.170:443</li><li>BR (Brazil): 34.151.236.197:443</li><li>FI (Finland):<br>34.88.31.230:443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>panw-xdr-installers-prod-us.storage.googleapis.com</code></strong></p><p>Used to download installers for upgrade actions from the server.</p><p>This storage bucket is used for all regions.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>panw-xdr-payloads-prod-us.storage.googleapis.com</code></strong></p><p>Used to download the executable for the live terminal for XDR agents earlier than version 7.1.0.</p><p>This storage bucket is used for all regions.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>global-content-profiles-policy.storage.googleapis.com</code></strong></p><p>Used to download content updates.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>panw-xdr-evr-prod-</code></strong><em><strong><code><region></code></strong></em><strong><code>.storage.googleapis.com</code></strong></p><p>Used to download extended verdict request results in scanning.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>https://</code></strong><em><strong><code><region></code></strong></em><strong><code>-docker.pkg.dev</code></strong></p><p>Used to download the Kubernetes image from the registry for Kubernetes agents installation.</p><p>Refer to <strong>Regional Docker registry mapping</strong> for your specific tenant location and corresponding Docker registry URL.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td></td></tr><tr><td><strong>Regional Docker registry mapping</strong></td><td></td><td></td></tr><tr><td><strong>Tenant location</strong></td><td><strong>GCP region</strong></td><td><strong>Registry URL</strong></td></tr><tr><td><p>UK</p><p>Netherlands (EU)</p><p>United States (US)</p><p>Canada (CA)</p><p>South Korea (KR)</p><p>Singapore (SG)</p><p>Australia (AU)</p><p>Japan (JP)</p><p>India (IN)</p><p>Germany (DE)</p><p>France (FR)<br>Finland (FI)</p></td><td><p>europe-west2</p><p>europe-west4</p><p>us-central1</p><p>northamerica-northeast1</p><p>asia-northeast3</p><p>asia-southeast1</p><p>australia-southeast1</p><p>asia-northeast1</p><p>asia-south1</p><p>europe-west3</p><p>europe-west9<br>europe-north1</p></td><td><p>europe-west2-docker.pkg.dev</p><p>europe-west4-docker.pkg.dev</p><p>us-central1-docker.pkg.dev</p><p>northamerica-northeast1-docker.pkg.dev</p><p>asia-northeast3-docker.pkg.dev</p><p>asia-southeast1-docker.pkg.dev</p><p>australia-southeast1-docker.pkg.dev</p><p>asia-northeast1-docker.pkg.dev</p><p>asia-south1-docker.pkg.dev</p><p>europe-west3-docker.pkg.dev</p><p>europe-west9-docker.pkg.dev</p></td></tr><tr><td><p><strong><code>dc-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for EDR data upload.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 34.98.77.231:443</li><li>EU (Europe): 34.102.140.103:443</li><li>CA (Canada): 34.96.120.25:443</li><li>UK (United Kingdom): 35.244.133.254:443</li><li>JP (Japan): 34.95.66.187:443</li><li>SG (Singapore): 34.120.142.18:443</li><li>AU (Australia): 34.102.237.151:443</li><li>DE (Germany): 34.107.161.143:443</li><li>IN (India): 34.120.213.187:443</li><li>DL (Delhi): 136.110.132.208:443</li><li>CH (Switzerland): 34.149.180.250:443</li><li>PL (Poland): 35.190.13.237:443</li><li>TW (Taiwan): 34.149.248.76:443</li><li>QT (Qatar): 34.107.129.254:443</li><li>FA (France): 34.36.155.211:443</li><li>IL (Israel): 34.128.157.130:443</li><li>SA (Saudi Arabia): 34.107.213.85:443</li><li>ID (Indonesia): 34.128.156.84:443</li><li>ES (Spain): 34.120.102.147:443</li><li>IT (Italy): 34.8.234.58:443</li><li>KR (South Korea): 34.54.155.245:443</li><li>ZA (South Africa): 35.190.79.68:443</li><li>BR (Brazil): 136.110.146.246:443</li><li>FI (Finland):<br>136.110.165.34:443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><p><strong><code>ch-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 34.98.77.231:443</li><li>EU (Europe): 34.102.140.103:443</li><li>CA (Canada): 34.96.120.25:443</li><li>UK (United Kingdom): 35.244.133.254:443</li><li>JP (Japan): 34.95.66.187:443</li><li>SG (Singapore): 34.120.142.18:443</li><li>AU (Australia): 34.102.237.151:443</li><li>DE (Germany): 34.107.161.143:443</li><li>IN (India): 34.120.213.188:443</li><li>DL (Delhi): 136.110.132.208:443</li><li>CH (Switzerland): 34.149.180.250:443</li><li>PL (Poland): 35.190.13.237:443</li><li>TW (Taiwan): 34.149.248.76:443</li><li>QT (Qatar): 34.107.129.254:443</li><li>FA (France): 34.36.155.211:443</li><li>IL (Israel): 34.128.157.130:443</li><li>SA (Saudi Arabia): 34.107.213.85:443</li><li>ID (Indonesia): 34.128.156.84:443</li><li>ES (Spain): 34.120.102.147:443</li><li>IT (Italy): 34.8.234.58:443</li><li>KR (South Korea): 34.54.155.245:443</li><li>ZA (South Africa): 35.190.79.68:443</li><li>BR (Brazil): 136.110.146.246:443</li><li>FI (Finland):<br>136.110.165.34:443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><p><strong><code>api-</code></strong><em><strong><code><tenant-name>.xdr.<region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used for API requests and responses and to connect to an engine.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.222.81.194:443</li><li>EU (Europe): 34.90.67.58:443</li><li>CA (Canada): 35.203.82.121:443</li><li>UK (United Kingdom): 34.89.56.78:443</li><li>JP (Japan): 34.84.125.129:443</li><li>SG (Singapore): 34.87.83.144:443</li><li>AU (Australia): 35.189.18.208:443</li><li>DE (Germany): 34.107.57.23:443</li><li>IN (India): 35.200.158.164:443</li><li>DL (Delhi): 34.131.165.103:443</li><li>CH (Switzerland): 34.65.248.119:443</li><li>PL (Poland): 34.116.216.55:443</li><li>TW (Taiwan): 35.234.8.249:443</li><li>QT (Qatar): 34.18.46.240:443</li><li>FA (France): 34.155.222.152:443</li><li>IL (Israel): 34.165.156.139:443</li><li>SA (Saudi Arabia): 34.166.58.79:443</li><li>ID (Indonesia): 34.128.115.238:443</li><li>ES (Spain): 34.175.30.176:443</li><li>IT (Italy): 34.154.195.120:443</li><li>KR (South Korea): 34.64.54.175:443</li><li>ZA (South Africa): 34.35.64.191:443</li><li>BR (Brazil): 34.39.136.78:443</li><li>FI (Finland):<br>35.228.73.215:443</li></ul></td><td>—</td></tr><tr><td><p><strong><code>cc-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for get-verdict requests.</p><p>For agents on endpoints, you must allow the IP address for the closest region to ensure connectivity. Endpoints use latency-based routing. An agent that belongs to a US tenant, for example, but that is physically located in Singapore, routes to Singapore to get the verdict.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.224.140.142:443</li><li>EU (Europe): 34.90.71.103:443</li><li>CA (Canada): 35.203.35.23:443</li><li>UK (United Kingdom): 34.89.42.214:443</li><li>JP (Japan): 34.84.225.105:443</li><li>SG (Singapore): 35.247.161.94:443</li><li>AU (Australia): 35.201.23.188:443</li><li>DE (Germany): 35.242.201.199:443</li><li>IN (India): 35.244.57.196:443</li><li>DL (Delhi): 34.131.47.126:443</li><li>CH (Switzerland): 34.65.137.215:443</li><li>PL (Poland): 34.116.213.71:443</li><li>TW (Taiwan): 35.229.186.216:443</li><li>QT (Qatar): 34.18.53.229:443</li><li>FA (France): 34.155.110.169:443</li><li>IL (Israel): 34.165.2.110:443</li><li>SA (Saudi Arabia): 34.166.53.160:443</li><li>ID (Indonesia): 34.101.155.198:443</li><li>ES (Spain): 34.175.205.166:443</li><li>IT (Italy): 34.154.230.76:443</li><li>KR (South Korea): 34.64.228.117:443</li><li>ZA (South Africa): 34.35.13.198:443</li><li>BR (Brazil): 34.39.195.104:443</li><li>FI (Finland):<br>35.228.118.177:443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><p><code>xdr-<region>-<project ID>-tim-indicators.storage.googleapis.com</code></p><p>Used to download the IOC indicators from the tenant.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.224.140.142:443</li><li>EU (Europe): 34.90.71.103:443</li><li>CA (Canada): 35.203.35.23:443</li><li>UK (United Kingdom): 34.89.42.214:443</li><li>JP (Japan): 34.84.225.105:443</li><li>SG (Singapore): 35.247.161.94:443</li><li>AU (Australia): 35.201.23.188:443</li><li>DE (Germany): 35.242.201.199:443</li><li>IN (India): 35.244.57.196:443</li><li>DL (Delhi): 34.131.47.126:443</li><li>CH (Switzerland): 34.65.137.215:443</li><li>PL (Poland): 34.116.213.71:443</li><li>TW (Taiwan): 35.229.186.216:443</li><li>QT (Qatar): 34.18.53.229:443</li><li>FA (France): 34.155.110.169:443</li><li>IL (Israel): 34.165.2.110:443</li><li>SA (Saudi Arabia): 34.166.53.160:443</li><li>ID (Indonesia): 34.101.155.198:443</li><li>ES (Spain): 34.175.205.166:443</li><li>IT (Italy): 34.154.230.76:443</li><li>KR (South Korea): 34.64.228.117:443</li><li>ZA (South Africa): 34.35.13.198:443</li><li>BR (Brazil): 34.39.195.104:443</li><li>FI (Finland):<br>35.228.118.177:443</li></ul></td><td><code>cortex-xdr</code></td></tr><tr><td><p><strong>Broker VM Resources</strong></p><p>Required for deployments that use Broker VM features</p></td><td></td><td></td></tr><tr><td><p><a href="http://xdr-ova-installers-prod-us.storage.googleapis.com/">xdr-ova-installers-prod-us.storage.googleapis.com</a></p><p>Used to download Broker VM images from the server.</p><p>This storage bucket is used for all regions.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><strong><code>br-</code></strong><em><strong><code><tenant-name>.xdr.<region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></td><td><p>IP address by region:</p><ul><li>US (United States): 104.155.131.72:443</li><li>EU (Europe): 34.91.128.226:443</li><li>CA (Canada): 34.95.8.232:443</li><li>UK (United Kingdom): 35.197.219.110:443</li><li>JP (Japan):34.85.74.43:443</li><li>SG (Singapore): 34.87.167.125:443</li><li>AU (Australia): 35.244.93.0:443</li><li>DE (Germany): 35.198.112.13:443</li><li>IN (India): 35.200.234.99:443</li><li>DL (Delhi): 34.131.131.141:443</li><li>CH (Switzerland): 34.65.51.103:443</li><li>PL (Poland): 34.116.176.97:443</li><li>TW (Taiwan): 34.80.230.166:443</li><li>QT (Qatar): 34.18.37.73:443</li><li>FA (France): 34.155.90.61:443</li><li>IL (Israel): 34.165.24.222:443</li><li>SA (Saudi Arabia): 34.166.55.153:443</li><li>ID (Indonesia): 34.101.101.170:443</li><li>ES (Spain): 34.175.182.55:443</li><li>IT (Italy): 34.154.168.139:443</li><li>KR (South Korea): 34.64.46.249:443</li><li>ZA (South Africa): 34.35.45.251:443</li><li>BR (Brazil): 35.198.38.182:443</li><li>FI (Finland):<br>34.88.26.246:443</li></ul></td><td>—</td></tr><tr><td><strong><code>distributions.traps.paloaltonetworks.com</code></strong></td><td><ul><li>IP address: 35.223.6.69</li><li>Port: 443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><ul><li><strong><code>time.google.com</code></strong></li><li><strong><code>pool.ntp.org</code></strong></li></ul></td><td>UDP port: 123</td><td>—</td></tr><tr><td><strong>App Login and Authentication</strong></td><td></td><td></td></tr><tr><td><p>identity.paloaltonetworks.com</p><p>(SSO)</p></td><td><ul><li>IP address: 34.120.119.85</li><li>Port: 443</li></ul></td><td>—</td></tr><tr><td><p>login.paloaltonetworks.com</p><p>(SSO)</p></td><td><ul><li>IP address: 34.102.139.110</li><li>Port: 443</li></ul></td><td>—</td></tr><tr><td><strong>In-App Help Center and Notifications</strong></td><td></td><td></td></tr><tr><td>data.pendo.io</td><td>Port: 443</td><td>—</td></tr><tr><td>pendo-static-5664029141630976.storage.googleapis.com</td><td>Port: 443</td><td>—</td></tr><tr><td><strong>Email Notifications</strong></td><td></td><td></td></tr><tr><td>—</td><td>IP address for all regions: 159.183.150.248</td><td>—</td></tr><tr><td><p><strong>Ingress</strong></p><p>These IPs are used for communication between Cortex XSIAM and your resources. Use them when sending data out from your tenant.</p></td><td></td><td></td></tr><tr><td></td><td><ul><li><p>FI (Finland):</p><ul><li>34.88.97.182</li><li>34.88.189.1</li></ul></li><li><p>US (United States)</p><ul><li>34.132.108.184</li><li>34.69.63.16</li></ul></li><li><p>EU (Europe)</p><ul><li>34.147.107.51</li><li>34.91.26.125</li></ul></li><li><p>CA (Canada)</p><ul><li>35.203.108.13</li><li>35.203.101.162</li></ul></li><li><p>UK (United Kingdom)</p><ul><li>35.242.180.163</li><li>34.105.173.229</li></ul></li><li><p>JP (Japan)</p><ul><li>35.200.3.131</li><li>34.146.181.233</li></ul></li><li><p>SG (Singapore)</p><ul><li>35.240.243.57</li><li>34.126.183.208</li></ul></li><li><p>AU (Australia)</p><ul><li>34.151.83.236</li><li>34.116.67.90</li></ul></li><li><p>DE (Germany)</p><ul><li>35.234.118.195</li><li>34.89.183.45</li></ul></li><li><p>IN (India)</p><ul><li>35.200.175.78</li><li>34.93.9.198</li></ul></li><li><p>CH (Switzerland)</p><ul><li>34.65.108.153</li><li>34.65.155.169</li></ul></li><li><p>PL (Poland)</p><ul><li>34.118.48.171</li><li>34.116.202.235</li></ul></li><li><p>TW (Taiwan)</p><ul><li>34.80.133.68</li><li>35.234.18.10</li></ul></li><li><p>QT (Qatar)</p><ul><li>34.18.34.118</li><li>34.18.39.155</li></ul></li><li><p>FA (France)</p><ul><li>34.155.5.117</li><li>34.155.41.247</li></ul></li><li><p>IL (Israel)</p><ul><li>34.165.33.165</li><li>34.165.27.131</li></ul></li><li><p>SA (Saudi Arabia)</p><ul><li>34.166.61.81</li><li>34.166.58.213</li></ul></li><li><p>ID (Indonesia)</p><ul><li>34.128.126.138</li><li>34.128.82.158</li></ul></li><li><p>ES (Spain)</p><ul><li>34.175.46.46</li><li>34.175.80.182</li></ul></li><li><p>IT (Italy)</p><ul><li>34.154.23.156</li><li>34.154.186.12</li></ul></li><li><p>KR (South Korea)</p><ul><li>34.64.93.168</li><li>34.64.237.45</li></ul></li><li><p>ZA (South Africa):</p><ul><li>34.35.42.196</li><li>34.35.79.219</li></ul></li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><strong>Outbound IPs for engines</strong></td><td></td><td></td></tr><tr><td></td><td><p>IP addresses by region</p><ul><li><p>FI (Finland)</p><ul><li>35.228.175.228</li><li>35.228.44.44</li></ul></li><li><p>US (United States)</p><ul><li>35.225.156.101</li><li>34.69.88.119</li></ul></li><li><p>EU (Europe)</p><ul><li>34.147.67.188</li><li>34.90.16.31</li></ul></li><li><p>CA (Canada)</p><ul><li>35.203.57.162</li><li>35.203.90.79</li></ul></li><li><p>UK (United Kingdom)</p><ul><li>34.142.3.42</li><li>34.142.44.136</li></ul></li><li><p>JP (Japan)</p><ul><li>34.146.60.215</li><li>34.84.93.160</li></ul></li><li><p>SG (Singapore)</p><ul><li>35.240.144.192</li><li>35.240.255.15</li></ul></li><li><p>AU (Australia)</p><ul><li>35.244.73.76</li><li>35.201.22.63</li></ul></li><li><p>DE (Germany)</p><ul><li>34.107.83.197</li><li>34.159.53.97</li></ul></li><li><p>IN (India)</p><ul><li>35.244.5.205</li><li>34.93.118.113</li></ul></li><li><p>DL (Delhi)</p><ul><li>34.131.207.151</li><li>34.126.212.40</li></ul></li><li><p>CH (Switzerland)</p><ul><li>34.65.222.25</li><li>34.65.233.60</li></ul></li><li><p>PL (Poland)</p><ul><li>34.118.92.214</li><li>34.116.223.119</li></ul></li><li><p>TW (Taiwan)</p><ul><li>104.199.223.229</li><li>34.81.38.132</li></ul></li><li><p>QT (Qatar)</p><ul><li>34.18.39.0</li><li>34.18.32.96</li></ul></li><li><p>FA (France)</p><ul><li>34.155.197.131</li><li>34.155.5.100</li></ul></li><li><p>IL (Israel)</p><ul><li>34.165.46.47</li><li>34.165.17.246</li></ul></li><li><p>SA (Saudi Arabia)</p><ul><li>34.166.58.243</li><li>34.166.54.238</li></ul></li><li><p>ID (Indonesia)</p><ul><li>34.101.125.66</li><li>34.101.218.184</li></ul></li><li><p>ES (Spain)</p><ul><li>34.175.255.99</li><li>34.175.230.35</li></ul></li><li><p>IT (Italy)</p><ul><li>34.154.173.134</li><li>34.154.229.60</li></ul></li><li><p>KR (South Korea)</p><ul><li>34.64.189.205</li><li>34.64.45.118</li></ul></li><li><p>ZA (South Africa)</p><ul><li>34.35.70.193</li><li>34.35.80.189</li></ul></li><li><p>BR (Brazil)</p><ul><li>35.199.96.109</li><li>34.39.161.254</li></ul></li></ul></td><td>—</td></tr><tr><td><strong>Collect third-party data from your SaaS and Cloud resources</strong></td><td></td><td></td></tr><tr><td>—</td><td><p>IP address by region.</p><ul><li><p>FI (Finland)</p><ul><li>35.228.192.167</li><li>34.88.193.126</li></ul></li><li><p>US (United States)</p><ul><li>34.66.69.154</li><li>35.202.21.123</li></ul></li><li><p>AU (Australia)</p><ul><li>35.197.181.108</li><li>35.197.175.44</li></ul></li><li><p>CA (Canada)</p><ul><li>34.95.33.72</li><li>34.95.62.136</li></ul></li><li><p>SG (Singapore)</p><ul><li>35.247.148.38</li><li>35.247.173.40</li></ul></li><li><p>JP (Japan)</p><ul><li>34.85.68.167</li><li>34.84.99.239</li></ul></li><li><p>IN (India)</p><ul><li>34.93.3.196</li><li>34.93.175.218</li></ul></li><li><p>DL (Delhi)</p><ul><li>34.131.111.87</li><li>34.131.101.138</li></ul></li><li><p>DE (Germany)</p><ul><li>34.89.197.46</li><li>34.107.3.224</li></ul></li><li><p>UK (United Kingdom)</p><ul><li>34.105.227.146</li><li>34.105.137.22</li></ul></li><li><p>EU (Europe)</p><ul><li>34.90.70.107</li><li>35.204.129.196</li></ul></li><li><p>CH (Switzerland)</p><ul><li>34.65.225.124</li><li>34.65.89.6</li></ul></li><li><p>PL (Poland)</p><ul><li>34.118.71.237</li><li>34.118.124.130</li></ul></li><li><p>TW (Taiwan)</p><ul><li>35.201.142.86</li><li>35.189.176.163</li></ul></li><li><p>QT (Qatar)</p><ul><li>34.18.44.71</li><li>34.18.30.132</li></ul></li><li><p>FA (France)</p><ul><li>34.163.125.167</li><li>34.163.155.105</li></ul></li><li><p>IL (Israel)</p><ul><li>34.165.131.171</li><li>34.165.120.206</li></ul></li><li><p>SA (Saudi Arabia)</p><ul><li>34.166.59.20</li><li>34.166.53.242</li></ul></li><li><p>ID (Indonesia)</p><ul><li>34.101.158.32</li><li>34.101.79.159</li></ul></li><li><p>ES (Spain)</p><ul><li>34.175.27.251</li><li>34.175.198.50</li></ul></li><li><p>IT (Italy)</p><ul><li>34.154.208.247</li><li>34.154.243.11</li></ul></li><li><p>KR (South Korea)</p><ul><li>34.64.107.163</li><li>34.64.84.25</li></ul></li><li><p>ZA (South Africa):</p><ul><li>34.35.69.156</li><li>34.35.60.86</li></ul></li><li><p>BR (Brazil)</p><ul><li>34.39.177.125</li><li>34.39.140.36</li></ul></li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><strong>Log Forwarding to a Syslog Receiver</strong></td><td></td><td></td></tr><tr><td>See <a href="../../post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver">Integrate a syslog receiver</a>.</td><td></td><td></td></tr></tbody></table> +<table><thead><tr><th>FQDN</th><th width="265">IP Addresses and Port</th><th>App-ID Coverage</th></tr></thead><tbody><tr><td></td><td></td><td></td></tr><tr><td><p><em><strong><code><tenant-name></code></strong></em><strong><code>.xdr.</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used to send data from external services and systems to the Cortex tenant.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.244.250.18:443</li><li>EU (Europe): 35.227.237.180:443</li><li>CA (Canada): 34.120.31.199:443</li><li>UK (United Kingdom): 34.120.87.77:443</li><li>JP (Japan): 35.241.28.254:443</li><li>SG (Singapore): 34.117.211.129:443</li><li>AU (Australia): 34.120.229.65:443</li><li>DE (Germany): 34.98.68.183:443</li><li>IN (India): 35.186.207.80:443</li><li>DL (Delhi): 34.8.67.192:443</li><li>CH (Switzerland): 34.111.6.153:443</li><li>PL (Poland): 34.117.240.208:443</li><li>TW (Taiwan): 34.160.28.41:443</li><li>QT (Qatar): 35.190.0.180:443</li><li>FA (France): 34.111.134.57:443</li><li>IL (Israel): 34.111.129.144:443</li><li>SA (Saudi Arabia): 35.244.157.127:443</li><li>ID (Indonesia): 34.111.58.152:443</li><li>ES (Spain): 34.111.188.248:443</li><li>IT (Italy): 34.8.224.70:443</li><li>KR (South Korea): 34.54.5.247:443</li><li>ZA (South Africa): 34.149.165.12:443</li><li>BR (Brazil): 34.96.83.202:443</li><li>FI (Finland):<br>34.160.63.63:443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>distributions.traps.paloaltonetworks.com</code></strong></p><p>Used for the first request in registration flow where the agent passes the distribution id and obtains the <strong><code>ch-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong> of its tenant.</p></td><td><ul><li>IP address: 35.223.6.69</li><li>Port: 443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><p><strong><code>https://lrc-</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p><strong><code>wss://lrc-</code></strong><em><strong><code><region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used in live terminal flow.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.190.88.43:443</li><li>EU (Europe): 35.244.251.25:443</li><li>CA (Canada): 35.203.99.74:443</li><li>UK (United Kingdom): 35.242.159.176:443</li><li>JP (Japan): 34.84.201.32:443</li><li>SG (Singapore): 34.87.61.186:443</li><li>AU (Australia): 35.244.66.177:443</li><li>DE (Germany): 34.107.61.141:443</li><li>IN (India): 35.200.146.253:443</li><li>DL (Delhi): 34.131.116.135:443</li><li>CH (Switzerland): 34.65.213.226:443</li><li>PL (Poland): 34.118.62.80:443</li><li>TW (Taiwan): 34.80.34.30:443</li><li>QT (Qatar): 34.18.34.73:443</li><li>FA (France): 34.163.57.57:443</li><li>IL (Israel): 34.165.43.106:443</li><li>SA (Saudi Arabia): 34.166.54.6:443</li><li>ID (Indonesia): 34.101.214.157:443</li><li>ES (Spain): 34.175.18.78:443</li><li>IT (Italy): 34.154.154.5:443</li><li>KR (South Korea): 34.22.66.91:443</li><li>ZA (South Africa): 34.35.56.170:443</li><li>BR (Brazil): 34.151.236.197:443</li><li>FI (Finland):<br>34.88.31.230:443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>panw-xdr-installers-prod-us.storage.googleapis.com</code></strong></p><p>Used to download installers for upgrade actions from the server.</p><p>This storage bucket is used for all regions.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>panw-xdr-payloads-prod-us.storage.googleapis.com</code></strong></p><p>Used to download the executable for the live terminal for XDR agents earlier than version 7.1.0.</p><p>This storage bucket is used for all regions.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>global-content-profiles-policy.storage.googleapis.com</code></strong></p><p>Used to download content updates.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>panw-xdr-evr-prod-</code></strong><em><strong><code><region></code></strong></em><strong><code>.storage.googleapis.com</code></strong></p><p>Used to download extended verdict request results in scanning.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><p><strong><code>https://</code></strong><em><strong><code><region></code></strong></em><strong><code>-docker.pkg.dev</code></strong></p><p>Used to download the Kubernetes image from the registry for Kubernetes agents installation.</p><p>Refer to <strong>Regional Docker registry mapping</strong> for your specific tenant location and corresponding Docker registry URL.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td></td></tr><tr><td><strong>Regional Docker registry mapping</strong></td><td></td><td></td></tr><tr><td><strong>Tenant location</strong></td><td><strong>GCP region</strong></td><td><strong>Registry URL</strong></td></tr><tr><td><p>UK</p><p>Netherlands (EU)</p><p>United States (US)</p><p>Canada (CA)</p><p>South Korea (KR)</p><p>Singapore (SG)</p><p>Australia (AU)</p><p>Japan (JP)</p><p>India (IN)</p><p>Germany (DE)</p><p>France (FR)<br>Finland (FI)</p></td><td><p>europe-west2</p><p>europe-west4</p><p>us-central1</p><p>northamerica-northeast1</p><p>asia-northeast3</p><p>asia-southeast1</p><p>australia-southeast1</p><p>asia-northeast1</p><p>asia-south1</p><p>europe-west3</p><p>europe-west9<br>europe-north1</p></td><td><p>europe-west2-docker.pkg.dev</p><p>europe-west4-docker.pkg.dev</p><p>us-central1-docker.pkg.dev</p><p>northamerica-northeast1-docker.pkg.dev</p><p>asia-northeast3-docker.pkg.dev</p><p>asia-southeast1-docker.pkg.dev</p><p>australia-southeast1-docker.pkg.dev</p><p>asia-northeast1-docker.pkg.dev</p><p>asia-south1-docker.pkg.dev</p><p>europe-west3-docker.pkg.dev</p><p>europe-west9-docker.pkg.dev</p></td></tr><tr><td><p><strong><code>dc-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for EDR data upload.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 34.98.77.231:443</li><li>EU (Europe): 34.102.140.103:443</li><li>CA (Canada): 34.96.120.25:443</li><li>UK (United Kingdom): 35.244.133.254:443</li><li>JP (Japan): 34.95.66.187:443</li><li>SG (Singapore): 34.120.142.18:443</li><li>AU (Australia): 34.102.237.151:443</li><li>DE (Germany): 34.107.161.143:443</li><li>IN (India): 34.120.213.187:443</li><li>DL (Delhi): 136.110.132.208:443</li><li>CH (Switzerland): 34.149.180.250:443</li><li>PL (Poland): 35.190.13.237:443</li><li>TW (Taiwan): 34.149.248.76:443</li><li>QT (Qatar): 34.107.129.254:443</li><li>FA (France): 34.36.155.211:443</li><li>IL (Israel): 34.128.157.130:443</li><li>SA (Saudi Arabia): 34.107.213.85:443</li><li>ID (Indonesia): 34.128.156.84:443</li><li>ES (Spain): 34.120.102.147:443</li><li>IT (Italy): 34.8.234.58:443</li><li>KR (South Korea): 34.54.155.245:443</li><li>ZA (South Africa): 35.190.79.68:443</li><li>BR (Brazil): 136.110.146.246:443</li><li>FI (Finland):<br>136.110.165.34:443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><p><strong><code>ch-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for all other requests between the agent and its tenant server, including heartbeat, uploads, action results, and scan reports.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 34.98.77.231:443</li><li>EU (Europe): 34.102.140.103:443</li><li>CA (Canada): 34.96.120.25:443</li><li>UK (United Kingdom): 35.244.133.254:443</li><li>JP (Japan): 34.95.66.187:443</li><li>SG (Singapore): 34.120.142.18:443</li><li>AU (Australia): 34.102.237.151:443</li><li>DE (Germany): 34.107.161.143:443</li><li>IN (India): 34.120.213.188:443</li><li>DL (Delhi): 136.110.132.208:443</li><li>CH (Switzerland): 34.149.180.250:443</li><li>PL (Poland): 35.190.13.237:443</li><li>TW (Taiwan): 34.149.248.76:443</li><li>QT (Qatar): 34.107.129.254:443</li><li>FA (France): 34.36.155.211:443</li><li>IL (Israel): 34.128.157.130:443</li><li>SA (Saudi Arabia): 34.107.213.85:443</li><li>ID (Indonesia): 34.128.156.84:443</li><li>ES (Spain): 34.120.102.147:443</li><li>IT (Italy): 34.8.234.58:443</li><li>KR (South Korea): 34.54.155.245:443</li><li>ZA (South Africa): 35.190.79.68:443</li><li>BR (Brazil): 136.110.146.246:443</li><li>FI (Finland):<br>136.110.165.34:443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><p><strong><code>api-</code></strong><em><strong><code><tenant-name>.xdr.<region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></p><p>Used for API requests and responses and to connect to an engine.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.222.81.194:443</li><li>EU (Europe): 34.90.67.58:443</li><li>CA (Canada): 35.203.82.121:443</li><li>UK (United Kingdom): 34.89.56.78:443</li><li>JP (Japan): 34.84.125.129:443</li><li>SG (Singapore): 34.87.83.144:443</li><li>AU (Australia): 35.189.18.208:443</li><li>DE (Germany): 34.107.57.23:443</li><li>IN (India): 35.200.158.164:443</li><li>DL (Delhi): 34.131.165.103:443</li><li>CH (Switzerland): 34.65.248.119:443</li><li>PL (Poland): 34.116.216.55:443</li><li>TW (Taiwan): 35.234.8.249:443</li><li>QT (Qatar): 34.18.46.240:443</li><li>FA (France): 34.155.222.152:443</li><li>IL (Israel): 34.165.156.139:443</li><li>SA (Saudi Arabia): 34.166.58.79:443</li><li>ID (Indonesia): 34.128.115.238:443</li><li>ES (Spain): 34.175.30.176:443</li><li>IT (Italy): 34.154.195.120:443</li><li>KR (South Korea): 34.64.54.175:443</li><li>ZA (South Africa): 34.35.64.191:443</li><li>BR (Brazil): 34.39.136.78:443</li><li>FI (Finland):<br>35.228.73.215:443</li></ul></td><td>—</td></tr><tr><td><p><strong><code>cc-</code></strong><em><strong><code><tenant-name></code></strong></em><strong><code>.traps.paloaltonetworks.com</code></strong></p><p>Used for get-verdict requests.</p><p>For agents on endpoints, you must allow the IP address for the closest region to ensure connectivity. Endpoints use latency-based routing. An agent that belongs to a US tenant, for example, but that is physically located in Singapore, routes to Singapore to get the verdict.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.224.140.142:443</li><li>EU (Europe): 34.90.71.103:443</li><li>CA (Canada): 35.203.35.23:443</li><li>UK (United Kingdom): 34.89.42.214:443</li><li>JP (Japan): 34.84.225.105:443</li><li>SG (Singapore): 35.247.161.94:443</li><li>AU (Australia): 35.201.23.188:443</li><li>DE (Germany): 35.242.201.199:443</li><li>IN (India): 35.244.57.196:443</li><li>DL (Delhi): 34.131.47.126:443</li><li>CH (Switzerland): 34.65.137.215:443</li><li>PL (Poland): 34.116.213.71:443</li><li>TW (Taiwan): 35.229.186.216:443</li><li>QT (Qatar): 34.18.53.229:443</li><li>FA (France): 34.155.110.169:443</li><li>IL (Israel): 34.165.2.110:443</li><li>SA (Saudi Arabia): 34.166.53.160:443</li><li>ID (Indonesia): 34.101.155.198:443</li><li>ES (Spain): 34.175.205.166:443</li><li>IT (Italy): 34.154.230.76:443</li><li>KR (South Korea): 34.64.228.117:443</li><li>ZA (South Africa): 34.35.13.198:443</li><li>BR (Brazil): 34.39.195.104:443</li><li>FI (Finland):<br>35.228.118.177:443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><p><code>xdr-<region>-<project ID>-tim-indicators.storage.googleapis.com</code></p><p>Used to download the IOC indicators from the tenant.</p></td><td><p>IP address by region:</p><ul><li>US (United States): 35.224.140.142:443</li><li>EU (Europe): 34.90.71.103:443</li><li>CA (Canada): 35.203.35.23:443</li><li>UK (United Kingdom): 34.89.42.214:443</li><li>JP (Japan): 34.84.225.105:443</li><li>SG (Singapore): 35.247.161.94:443</li><li>AU (Australia): 35.201.23.188:443</li><li>DE (Germany): 35.242.201.199:443</li><li>IN (India): 35.244.57.196:443</li><li>DL (Delhi): 34.131.47.126:443</li><li>CH (Switzerland): 34.65.137.215:443</li><li>PL (Poland): 34.116.213.71:443</li><li>TW (Taiwan): 35.229.186.216:443</li><li>QT (Qatar): 34.18.53.229:443</li><li>FA (France): 34.155.110.169:443</li><li>IL (Israel): 34.165.2.110:443</li><li>SA (Saudi Arabia): 34.166.53.160:443</li><li>ID (Indonesia): 34.101.155.198:443</li><li>ES (Spain): 34.175.205.166:443</li><li>IT (Italy): 34.154.230.76:443</li><li>KR (South Korea): 34.64.228.117:443</li><li>ZA (South Africa): 34.35.13.198:443</li><li>BR (Brazil): 34.39.195.104:443</li><li>FI (Finland):<br>35.228.118.177:443</li></ul></td><td><code>cortex-xdr</code></td></tr><tr><td><p><strong>Broker VM Resources</strong></p><p>Required for deployments that use Broker VM features</p></td><td></td><td></td></tr><tr><td><p><a href="http://xdr-ova-installers-prod-us.storage.googleapis.com/">xdr-ova-installers-prod-us.storage.googleapis.com</a></p><p>Used to download Broker VM images from the server.</p><p>This storage bucket is used for all regions.</p></td><td><ul><li>IP ranges in GCP</li><li>Port: 443</li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><strong><code>br-</code></strong><em><strong><code><tenant-name>.xdr.<region></code></strong></em><strong><code>.paloaltonetworks.com</code></strong></td><td><p>IP address by region:</p><ul><li>US (United States): 104.155.131.72:443</li><li>EU (Europe): 34.91.128.226:443</li><li>CA (Canada): 34.95.8.232:443</li><li>UK (United Kingdom): 35.197.219.110:443</li><li>JP (Japan):34.85.74.43:443</li><li>SG (Singapore): 34.87.167.125:443</li><li>AU (Australia): 35.244.93.0:443</li><li>DE (Germany): 35.198.112.13:443</li><li>IN (India): 35.200.234.99:443</li><li>DL (Delhi): 34.131.131.141:443</li><li>CH (Switzerland): 34.65.51.103:443</li><li>PL (Poland): 34.116.176.97:443</li><li>TW (Taiwan): 34.80.230.166:443</li><li>QT (Qatar): 34.18.37.73:443</li><li>FA (France): 34.155.90.61:443</li><li>IL (Israel): 34.165.24.222:443</li><li>SA (Saudi Arabia): 34.166.55.153:443</li><li>ID (Indonesia): 34.101.101.170:443</li><li>ES (Spain): 34.175.182.55:443</li><li>IT (Italy): 34.154.168.139:443</li><li>KR (South Korea): 34.64.46.249:443</li><li>ZA (South Africa): 34.35.45.251:443</li><li>BR (Brazil): 35.198.38.182:443</li><li>FI (Finland):<br>34.88.26.246:443</li></ul></td><td>—</td></tr><tr><td><strong><code>distributions.traps.paloaltonetworks.com</code></strong></td><td><ul><li>IP address: 35.223.6.69</li><li>Port: 443</li></ul></td><td><strong><code>traps-management-service</code></strong></td></tr><tr><td><ul><li><strong><code>time.google.com</code></strong></li><li><strong><code>pool.ntp.org</code></strong></li></ul></td><td>UDP port: 123</td><td>—</td></tr><tr><td><strong>App Login and Authentication</strong></td><td></td><td></td></tr><tr><td><p>identity.paloaltonetworks.com</p><p>(SSO)</p></td><td><ul><li>IP address: 34.120.119.85</li><li>Port: 443</li></ul></td><td>—</td></tr><tr><td><p>login.paloaltonetworks.com</p><p>(SSO)</p></td><td><ul><li>IP address: 34.102.139.110</li><li>Port: 443</li></ul></td><td>—</td></tr><tr><td><strong>In-App Help Center and Notifications</strong></td><td></td><td></td></tr><tr><td>data.pendo.io</td><td>Port: 443</td><td>—</td></tr><tr><td>pendo-static-5664029141630976.storage.googleapis.com</td><td>Port: 443</td><td>—</td></tr><tr><td><strong>Email Notifications</strong></td><td></td><td></td></tr><tr><td>—</td><td>IP address for all regions: 159.183.150.248</td><td>—</td></tr><tr><td><p><strong>Ingress</strong></p><p>These IPs are used for communication between Cortex XSIAM and your resources. Use them when sending data out from your tenant.</p></td><td></td><td></td></tr><tr><td></td><td><ul><li><p>FI (Finland):</p><ul><li>34.88.97.182</li><li>34.88.189.1</li></ul></li><li><p>US (United States)</p><ul><li>34.132.108.184</li><li>34.69.63.16</li></ul></li><li><p>EU (Europe)</p><ul><li>34.147.107.51</li><li>34.91.26.125</li></ul></li><li><p>CA (Canada)</p><ul><li>35.203.108.13</li><li>35.203.101.162</li></ul></li><li><p>UK (United Kingdom)</p><ul><li>35.242.180.163</li><li>34.105.173.229</li></ul></li><li><p>JP (Japan)</p><ul><li>35.200.3.131</li><li>34.146.181.233</li></ul></li><li><p>SG (Singapore)</p><ul><li>35.240.243.57</li><li>34.126.183.208</li></ul></li><li><p>AU (Australia)</p><ul><li>34.151.83.236</li><li>34.116.67.90</li></ul></li><li><p>DE (Germany)</p><ul><li>35.234.118.195</li><li>34.89.183.45</li></ul></li><li><p>IN (India)</p><ul><li>35.200.175.78</li><li>34.93.9.198</li></ul></li><li><p>CH (Switzerland)</p><ul><li>34.65.108.153</li><li>34.65.155.169</li></ul></li><li><p>PL (Poland)</p><ul><li>34.118.48.171</li><li>34.116.202.235</li></ul></li><li><p>TW (Taiwan)</p><ul><li>34.80.133.68</li><li>35.234.18.10</li></ul></li><li><p>QT (Qatar)</p><ul><li>34.18.34.118</li><li>34.18.39.155</li></ul></li><li><p>FA (France)</p><ul><li>34.155.5.117</li><li>34.155.41.247</li></ul></li><li><p>IL (Israel)</p><ul><li>34.165.33.165</li><li>34.165.27.131</li></ul></li><li><p>SA (Saudi Arabia)</p><ul><li>34.166.61.81</li><li>34.166.58.213</li></ul></li><li><p>ID (Indonesia)</p><ul><li>34.128.126.138</li><li>34.128.82.158</li></ul></li><li><p>ES (Spain)</p><ul><li>34.175.46.46</li><li>34.175.80.182</li></ul></li><li><p>IT (Italy)</p><ul><li>34.154.23.156</li><li>34.154.186.12</li></ul></li><li><p>KR (South Korea)</p><ul><li>34.64.93.168</li><li>34.64.237.45</li></ul></li><li><p>ZA (South Africa):</p><ul><li>34.35.42.196</li><li>34.35.79.219</li></ul></li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><strong>Egress IP addresses</strong><br>Used for traffic from the Cortex tenant to external services and systems. Add the relevant IP addresses from this list to your allow lists for your external services and systems.</td><td></td><td></td></tr><tr><td></td><td><p>IP addresses by region</p><ul><li><p>FI (Finland)</p><ul><li>35.228.175.228</li><li>35.228.44.44</li></ul></li><li><p>US (United States)</p><ul><li>35.225.156.101</li><li>34.69.88.119</li></ul></li><li><p>EU (Europe)</p><ul><li>34.147.67.188</li><li>34.90.16.31</li></ul></li><li><p>CA (Canada)</p><ul><li>35.203.57.162</li><li>35.203.90.79</li></ul></li><li><p>UK (United Kingdom)</p><ul><li>34.142.3.42</li><li>34.142.44.136</li></ul></li><li><p>JP (Japan)</p><ul><li>34.146.60.215</li><li>34.84.93.160</li></ul></li><li><p>SG (Singapore)</p><ul><li>35.240.144.192</li><li>35.240.255.15</li></ul></li><li><p>AU (Australia)</p><ul><li>35.244.73.76</li><li>35.201.22.63</li></ul></li><li><p>DE (Germany)</p><ul><li>34.107.83.197</li><li>34.159.53.97</li></ul></li><li><p>IN (India)</p><ul><li>35.244.5.205</li><li>34.93.118.113</li></ul></li><li><p>DL (Delhi)</p><ul><li>34.131.207.151</li><li>34.126.212.40</li></ul></li><li><p>CH (Switzerland)</p><ul><li>34.65.222.25</li><li>34.65.233.60</li></ul></li><li><p>PL (Poland)</p><ul><li>34.118.92.214</li><li>34.116.223.119</li></ul></li><li><p>TW (Taiwan)</p><ul><li>104.199.223.229</li><li>34.81.38.132</li></ul></li><li><p>QT (Qatar)</p><ul><li>34.18.39.0</li><li>34.18.32.96</li></ul></li><li><p>FA (France)</p><ul><li>34.155.197.131</li><li>34.155.5.100</li></ul></li><li><p>IL (Israel)</p><ul><li>34.165.46.47</li><li>34.165.17.246</li></ul></li><li><p>SA (Saudi Arabia)</p><ul><li>34.166.58.243</li><li>34.166.54.238</li></ul></li><li><p>ID (Indonesia)</p><ul><li>34.101.125.66</li><li>34.101.218.184</li></ul></li><li><p>ES (Spain)</p><ul><li>34.175.255.99</li><li>34.175.230.35</li></ul></li><li><p>IT (Italy)</p><ul><li>34.154.173.134</li><li>34.154.229.60</li></ul></li><li><p>KR (South Korea)</p><ul><li>34.64.189.205</li><li>34.64.45.118</li></ul></li><li><p>ZA (South Africa)</p><ul><li>34.35.70.193</li><li>34.35.80.189</li></ul></li><li><p>BR (Brazil)</p><ul><li>35.199.96.109</li><li>34.39.161.254</li></ul></li></ul></td><td>—</td></tr><tr><td><strong>Collect third-party data from your SaaS and Cloud resources</strong></td><td></td><td></td></tr><tr><td>—</td><td><p>IP address by region.</p><ul><li><p>FI (Finland)</p><ul><li>35.228.192.167</li><li>34.88.193.126</li></ul></li><li><p>US (United States)</p><ul><li>34.66.69.154</li><li>35.202.21.123</li></ul></li><li><p>AU (Australia)</p><ul><li>35.197.181.108</li><li>35.197.175.44</li></ul></li><li><p>CA (Canada)</p><ul><li>34.95.33.72</li><li>34.95.62.136</li></ul></li><li><p>SG (Singapore)</p><ul><li>35.247.148.38</li><li>35.247.173.40</li></ul></li><li><p>JP (Japan)</p><ul><li>34.85.68.167</li><li>34.84.99.239</li></ul></li><li><p>IN (India)</p><ul><li>34.93.3.196</li><li>34.93.175.218</li></ul></li><li><p>DL (Delhi)</p><ul><li>34.131.111.87</li><li>34.131.101.138</li></ul></li><li><p>DE (Germany)</p><ul><li>34.89.197.46</li><li>34.107.3.224</li></ul></li><li><p>UK (United Kingdom)</p><ul><li>34.105.227.146</li><li>34.105.137.22</li></ul></li><li><p>EU (Europe)</p><ul><li>34.90.70.107</li><li>35.204.129.196</li></ul></li><li><p>CH (Switzerland)</p><ul><li>34.65.225.124</li><li>34.65.89.6</li></ul></li><li><p>PL (Poland)</p><ul><li>34.118.71.237</li><li>34.118.124.130</li></ul></li><li><p>TW (Taiwan)</p><ul><li>35.201.142.86</li><li>35.189.176.163</li></ul></li><li><p>QT (Qatar)</p><ul><li>34.18.44.71</li><li>34.18.30.132</li></ul></li><li><p>FA (France)</p><ul><li>34.163.125.167</li><li>34.163.155.105</li></ul></li><li><p>IL (Israel)</p><ul><li>34.165.131.171</li><li>34.165.120.206</li></ul></li><li><p>SA (Saudi Arabia)</p><ul><li>34.166.59.20</li><li>34.166.53.242</li></ul></li><li><p>ID (Indonesia)</p><ul><li>34.101.158.32</li><li>34.101.79.159</li></ul></li><li><p>ES (Spain)</p><ul><li>34.175.27.251</li><li>34.175.198.50</li></ul></li><li><p>IT (Italy)</p><ul><li>34.154.208.247</li><li>34.154.243.11</li></ul></li><li><p>KR (South Korea)</p><ul><li>34.64.107.163</li><li>34.64.84.25</li></ul></li><li><p>ZA (South Africa):</p><ul><li>34.35.69.156</li><li>34.35.60.86</li></ul></li><li><p>BR (Brazil)</p><ul><li>34.39.177.125</li><li>34.39.140.36</li></ul></li></ul></td><td><strong><code>cortex-xdr</code></strong></td></tr><tr><td><strong>Log Forwarding to a Syslog Receiver</strong></td><td></td><td></td></tr><tr><td>See <a href="../../post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver">Integrate a syslog receiver</a>.</td><td></td><td></td></tr></tbody></table> -
▸ ▾ Set up users, groups, and roles modified +4 −4
xsiam/onboard-cortex-xsiam/deployment-steps/set-up-users-and-rolesRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -7,20 +7,20 @@ description: Learn how to set up users and roles in Cortex XSIAM.Cortex XSIAM uses both Role-Based Access Control (RBAC) and Scope-Based Access Control (SBAC) to manage roles with specific permissions for controlling user access.Cortex XSIAM uses both Role-Based Access Control (RBAC) and Scope-Based Access Control (SBAC) to manage roles with specific permissions for controlling user access.RBAC helps manage access to Cortex XSIAM components and Cortex Query Language (XQL) datasets, so that users, based on their roles, are granted minimal access required to accomplish their tasks.RBAC helps manage access to Cortex XSIAM components and Cortex Query Language (XQL) datasets, so that users, based on their roles, are granted minimal access required to accomplish their tasks.SBAC refines the RBAC permissions by granting access only to the relevant data that the user requires for their designated role. Users with Access Management permission can apply scopes to limit the data and content that users can be granted access to in Cortex XSIAM, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows, which can be applied as relevant to the enforcement area, entity, or dataset. For more information on user scopes, see Manage user scope.SBAC refines the RBAC permissions by granting access only to the relevant data that the user requires for their designated role. Users with Access Management permission can apply scopes to limit the data and content that users can be granted access to in Cortex XSIAM, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows, which can be applied as relevant to the enforcement area, entity, or dataset. For more information on user scopes, see Manage user scope.Cortex Gateway and the tenant have different options and requirements.Cortex Gateway and the tenant have different options and requirements.Location│DetailsLocation│Details| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- || ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |Cortex Gateway│A centralized portal for managing roles, user groups, and users for all tenants. Any roles and user groups created in Cortex Gateway are available for all tenants.In Cortex Gateway, on the Permissions page, you can manage users that have been added to your Customer Support Portal account or view users that have been created in the tenant using SSO (you cannot edit SSO users in Cortex Gateway). All users must have at least one role or belong to at least one user group to be saved in the Cortex Gateway. You can exclude different tenants or different Cortex products. For more information, see Cortex Gateway Administrator Guide.
Only users with the Account Admin role can manage roles, tenants, and user groups in Cortex Gateway.
Cortex Gateway│A centralized portal for managing roles, user groups, and users for all tenants. Any roles and user groups created in Cortex Gateway are available for all tenants.In Cortex Gateway, on the Permissions page, you can manage users that have been added to your Customer Support Portal account or view users that have been created in the tenant using SSO (you cannot edit SSO users in Cortex Gateway). All users must have at least one role or belong to at least one user group to be saved in the Cortex Gateway. You can exclude different tenants or different Cortex products. For more information, see Cortex Gateway Administrator Guide.
Note
To make users visible in the Users list within the Cortex tenant, an administrator must first assign them the Cortex User role in the Customer Support Portal (CSP). For more information, see Manage user roles.
Only users with the Account Admin role can manage roles, tenants, and user groups in Cortex Gateway.
Cortex XSIAM tenant│(Recommended) All permissions and roles are specific to the tenant and exist only at the tenant level. Advanced settings, such as SBAC and Dataset access management, can be defined at the tenant level.Managing users, roles, scopes, user groups, and authentication settings in Cortex XSIAM requires View/Edit RBAC permissions for Access Management (under Configurations). Account Admin and Instance Administrator roles are granted this permission by default.
For more information, see Manage user roles.
Cortex XSIAM tenant│(Recommended) All permissions and roles are specific to the tenant and exist only at the tenant level. Advanced settings, such as SBAC and Dataset access management, can be defined at the tenant level.Managing users, roles, scopes, user groups, and authentication settings in Cortex XSIAM requires View/Edit RBAC permissions for Access Management (under Configurations). Account Admin and Instance Administrator roles are granted this permission by default.
For more information, see Manage user roles.
### Predefined user roles### Predefined user rolesCortex XSIAM utilizes Role-Based Access Control (RBAC) to manage user permissions across all tenants and services. This framework ensures a secure separation of duties by granting users only the specific access required for their functional or regional responsibilities. Key features include:Cortex XSIAM utilizes Role-Based Access Control (RBAC) to manage user permissions across all tenants and services. This framework ensures a secure separation of duties by granting users only the specific access required for their functional or regional responsibilities. Key features include:• Predefined Roles: Cortex XSIAM provides default roles with set permissions. While these cannot be edited directly, they can be copied and customized to meet your organization's specific security requirements. To view the predefined permissions for each default role, go to Settings → Configurations → Access Management → Roles.• Predefined Roles: Cortex XSIAM provides default roles with set permissions. While these cannot be edited directly, they can be copied and customized to meet your organization's specific security requirements. To view the predefined permissions for each default role, go to Settings → Configurations → Access Management → Roles.For more information about user role-based access permissions, see [Role permissions by component](../../reference-and-developer-docs/role-based-access-control/role-permissions-by-component)For more information about user role-based access permissions, see [Role permissions by component](../../reference-and-developer-docs/role-based-access-control/role-permissions-by-component)Show markdown source
@@ -7,20 +7,20 @@ description: Learn how to set up users and roles in Cortex XSIAM. Cortex XSIAM uses both Role-Based Access Control (RBAC) and Scope-Based Access Control (SBAC) to manage roles with specific permissions for controlling user access. RBAC helps manage access to Cortex XSIAM components and Cortex Query Language (XQL) datasets, so that users, based on their roles, are granted minimal access required to accomplish their tasks. SBAC refines the RBAC permissions by granting access only to the relevant data that the user requires for their designated role. Users with **Access Management** permission can apply scopes to limit the data and content that users can be granted access to in Cortex XSIAM, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows, which can be applied as relevant to the enforcement area, entity, or dataset. For more information on user scopes, see [Manage user scope](../../post-deployment/manage-user-roles-and-access-management#UUID-071cdbb6-6c6a-6afe-3a67-1fa79991a0a8). Cortex Gateway and the tenant have different options and requirements. -| Location | Details | -| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Cortex Gateway | <p>A centralized portal for managing roles, user groups, and users for all tenants. Any roles and user groups created in Cortex Gateway are available for all tenants.</p><p>In <strong>Cortex Gateway</strong>, on the <strong>Permissions</strong> page, you can manage users that have been added to your Customer Support Portal account or view users that have been created in the tenant using SSO (you cannot edit SSO users in Cortex Gateway). All users must have at least one role or belong to at least one user group to be saved in the Cortex Gateway. You can exclude different tenants or different Cortex products. For more information, see <a href="https://app.gitbook.com/s/nG6FTSH3MviWTK9yhAIg/cortex-gateway-admin-guide">Cortex Gateway Administrator Guide</a>.</p><p>Only users with the Account Admin role can manage roles, tenants, and user groups in Cortex Gateway.</p> | -| Cortex XSIAM tenant | <p>(Recommended) All permissions and roles are specific to the tenant and exist only at the tenant level. Advanced settings, such as SBAC and Dataset access management, can be defined at the tenant level.</p><p>Managing users, roles, scopes, user groups, and authentication settings in Cortex XSIAM requires <strong>View/Edit</strong> RBAC permissions for <strong>Access Management</strong> (under <strong>Configurations</strong>). Account Admin and Instance Administrator roles are granted this permission by default.</p><p>For more information, see <a href="../../post-deployment/manage-user-roles-and-access-management#UUID-751d26ed-9390-dddd-d4f6-bb1f20db3a1d">Manage user roles</a>.</p> | +| Location | Details | +| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Cortex Gateway | <p>A centralized portal for managing roles, user groups, and users for all tenants. Any roles and user groups created in Cortex Gateway are available for all tenants.</p><p>In <strong>Cortex Gateway</strong>, on the <strong>Permissions</strong> page, you can manage users that have been added to your Customer Support Portal account or view users that have been created in the tenant using SSO (you cannot edit SSO users in Cortex Gateway). All users must have at least one role or belong to at least one user group to be saved in the Cortex Gateway. You can exclude different tenants or different Cortex products. For more information, see <a href="https://app.gitbook.com/s/nG6FTSH3MviWTK9yhAIg/cortex-gateway-admin-guide">Cortex Gateway Administrator Guide</a>.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>To make users visible in the <strong>Users</strong> list within the Cortex tenant, an administrator must first assign them the <strong>Cortex User</strong> role in the Customer Support Portal (CSP). For more information, see <a href="../../post-deployment/manage-user-roles-and-access-management#UUID-751d26ed-9390-dddd-d4f6-bb1f20db3a1d">Manage user roles</a>.</p></div><p>Only users with the Account Admin role can manage roles, tenants, and user groups in Cortex Gateway.<br></p> | +| Cortex XSIAM tenant | <p>(Recommended) All permissions and roles are specific to the tenant and exist only at the tenant level. Advanced settings, such as SBAC and Dataset access management, can be defined at the tenant level.</p><p>Managing users, roles, scopes, user groups, and authentication settings in Cortex XSIAM requires <strong>View/Edit</strong> RBAC permissions for <strong>Access Management</strong> (under <strong>Configurations</strong>). Account Admin and Instance Administrator roles are granted this permission by default.</p><p>For more information, see <a href="../../post-deployment/manage-user-roles-and-access-management#UUID-751d26ed-9390-dddd-d4f6-bb1f20db3a1d">Manage user roles</a>.</p> | ### **Predefined user roles** Cortex XSIAM utilizes Role-Based Access Control (RBAC) to manage user permissions across all tenants and services. This framework ensures a secure separation of duties by granting users only the specific access required for their functional or regional responsibilities. Key features include: * Predefined Roles: Cortex XSIAM provides default roles with set permissions. While these cannot be edited directly, they can be copied and customized to meet your organization's specific security requirements. To view the predefined permissions for each default role, go to **Settings** → **Configurations** → **Access Management** → **Roles**. For more information about user role-based access permissions, see [Role permissions by component](../../reference-and-developer-docs/role-based-access-control/role-permissions-by-component) -
▸ ▾ Forward notifications to Amazon SQS modified +1 −1
xsiam/onboard-cortex-xsiam/post-deployment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xsiam-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-sqsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -7,17 +7,17 @@ description: >-# Forward notifications to Amazon SQS# Forward notifications to Amazon SQS### Create the SQS queue### Create the SQS queueLog in to your AWS Management Console and create a new Standard SQS queue.Log in to your AWS Management Console and create a new Standard SQS queue.hint infohint infoNOTE: Use the default AWS SQS message queue depth (256KB) or higher when creating or editing a standard SQS queue.NOTE: Use the default AWS SQS message queue depth (256KB) or higher when creating or editing a standard SQS queue.endhintendhint### Configure egress in Cortex Gateway### Configure egress in Cortex GatewayBefore forwarding cases or issues to Amazon SQS, you need to configure egress. Only a user with Account Admin or Instance Admin permissions can configure egress.Before forwarding cases or issues to Amazon SQS, you need to configure egress. Only a user with Account Admin or Instance Admin permissions can configure egress.To configure egress, to enter the queue name. For example, if the full URL is https://sqs.region.amazonaws.com/account-id/queue-name, enter onlyqueue-name.To configure egress, to enter the queue name. For example, if the full URL is https://sqs.region.amazonaws.com/account-id/queue-name, enter onlyqueue-name.Show markdown source
@@ -7,17 +7,17 @@ description: >- # Forward notifications to Amazon SQS ### Create the SQS queue Log in to your AWS Management Console and create a new **Standard SQS queue**. {% hint style="info" %} -NOTE: Use the default AWS SQS message queue depth (256KB) or higher when creating or editing a standard SQS queue.  +NOTE: Use the default AWS SQS message queue depth (256KB) or higher when creating or editing a standard SQS queue. {% endhint %} ### Configure egress in Cortex Gateway Before forwarding cases or issues to Amazon SQS, you need to configure egress. Only a user with Account Admin or Instance Admin permissions can configure egress. To configure egress, to enter the queue name. For example, if the full URL is https://sqs.region.amazonaws.com/account-id/queue-name, enter only `queue-name`. -
▸ ▾ Manage user access modified +12 −8 Replaces a bare topic list with the Cortex User role prerequisite in the CSP, plus new SSO-only access and access-revocation rules.
xsiam/onboard-cortex-xsiam/post-deployment/manage-user-roles-and-access-management/manage-user-accessRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -4,28 +4,32 @@ description: >-SBAC scopes, and XQL dataset row controls.SBAC scopes, and XQL dataset row controls.------# Manage user access# Manage user accesshint warninghint warning### Prerequisite### PrerequisiteManaging users, roles, scopes, user groups, authentication settings in Cortex XSIAM Access Management requires View/Edit RBAC permissions for Access Management (under Configurations). Account Admin and Instance Administrator roles are granted this permission by default. For more information, see Predefined user roles in Set up users and roles.• Managing users, roles, scopes, user groups, authentication settings in Cortex XSIAM Access Management requires View/Edit RBAC permissions for Access Management (under Configurations). Account Admin and Instance Administrator roles are granted this permission by default. For more information, see Predefined user roles in Set up users and roles.• To make users visible in the Users list within the Cortex tenant, an administrator must first assign them the Cortex User role on the Edit User screen in the Manage User Console of the Customer Support Portal (CSP). This role assignment in the CSP controls both the user's visibility in the tenant and their ability to authenticate via the CSP. For more information, see Cortex Gateway Administrator Guide.endhintendhintReview the following topics:### Role and permission management• Set up users and rolesWhile the CSP controls initial visibility and access, you must update the specific permissions associated with each role within the tenant itself or via the Roles tab in the Cortex Gateway.• User group management• Assign user roles and groups• Manage user roles and access management• Manage user scopeManage access permissions for Cortex XSIAM users.The following applies to user access and retention:• SSO-only access: To allow a user to appear in the tenant while restricting them to SSO login only, assign them the Cortex User role in the CSP, but do not assign them a direct role or a default role in the Cortex Gateway or the tenant.• Access revocation: If no role is assigned to a user (either directly or through a user group) in the Cortex Gateway or the tenant, the user cannot access the tenant. The user is subsequently revoked in the Cortex Gateway, and their information is no longer saved.### Manage users in the Cortex XSIAM tenantOnce users are visible in the tenant, perform the following tasks in Cortex XSIAM to edit permissions, import multiple users, view permissions, or manage user status.Edit user permissionsEdit user permissionsUpdate a user's role and scope, add a user to a user group, and view permissions based on the role, scope, and user groups assigned to the user.Update a user's role and scope, add a user to a user group, and view permissions based on the role, scope, and user groups assigned to the user.You can configure granular scoping for Scope-Based Access Control (SBAC) by granting access only to the relevant data that the user requires for their designated role. Administrators apply scopes to limit the data and content that users can be granted access to in Cortex XSIAM, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows, which can be applied as relevant to the enforcement area, entity, or dataset. For more information, see Manage user scope.You can configure granular scoping for Scope-Based Access Control (SBAC) by granting access only to the relevant data that the user requires for their designated role. Administrators apply scopes to limit the data and content that users can be granted access to in Cortex XSIAM, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows, which can be applied as relevant to the enforcement area, entity, or dataset. For more information, see Manage user scope.Show markdown source
@@ -4,28 +4,32 @@ description: >- SBAC scopes, and XQL dataset row controls. --- # Manage user access {% hint style="warning" %} ### Prerequisite -Managing users, roles, scopes, user groups, authentication settings in Cortex XSIAM Access Management requires **View/Edit** RBAC permissions for **Access Management** (under **Configurations**). Account Admin and Instance Administrator roles are granted this permission by default. For more information, see _Predefined user roles_ in [Set up users and roles](../../deployment-steps/set-up-users-and-roles). +* Managing users, roles, scopes, user groups, authentication settings in Cortex XSIAM Access Management requires **View/Edit** RBAC permissions for **Access Management** (under **Configurations**). Account Admin and Instance Administrator roles are granted this permission by default. For more information, see _Predefined user roles_ in [Set up users and roles](../../deployment-steps/set-up-users-and-roles). +* To make users visible in the **Users** list within the Cortex tenant, an administrator must first assign them the **Cortex User** role on the **Edit User** screen in the **Manage User Console** of the Customer Support Portal (CSP). This role assignment in the CSP controls both the user's visibility in the tenant and their ability to authenticate via the CSP. For more information, see [Cortex Gateway Administrator Guide](https://app.gitbook.com/s/nG6FTSH3MviWTK9yhAIg/cortex-gateway-admin-guide). {% endhint %} -Review the following topics: +### Role and permission management -* Set up users and roles -* User group management -* Assign user roles and groups -* Manage user roles and access management -* Manage user scope +While the CSP controls initial visibility and access, you must update the specific permissions associated with each role within the tenant itself or via the **Roles** tab in the **Cortex Gateway**. -Manage access permissions for Cortex XSIAM users. +The following applies to user access and retention: + +* SSO-only access: To allow a user to appear in the tenant while restricting them to SSO login only, assign them the **Cortex User** role in the CSP, but do not assign them a direct role or a default role in the Cortex Gateway or the tenant. +* Access revocation: If no role is assigned to a user (either directly or through a user group) in the Cortex Gateway or the tenant, the user cannot access the tenant. The user is subsequently revoked in the Cortex Gateway, and their information is no longer saved. + +### Manage users in the Cortex XSIAM tenant + +Once users are visible in the tenant, perform the following tasks in Cortex XSIAM to edit permissions, import multiple users, view permissions, or manage user status. <details> <summary>Edit user permissions</summary> Update a user's role and scope, add a user to a user group, and view permissions based on the role, scope, and user groups assigned to the user. You can configure granular scoping for Scope-Based Access Control (SBAC) by granting access only to the relevant data that the user requires for their designated role. Administrators apply scopes to limit the data and content that users can be granted access to in Cortex XSIAM, which are divided into different scoping areas. The scoping areas include Assets, Cases and Issues, Endpoints, and Datasets Rows, which can be applied as relevant to the enforcement area, entity, or dataset. For more information, see [Manage user scope](manage-user-scope). -
▸ ▾ Retrieve support file password modified +40 −12 Rewritten into a locate-the-token step and separate Action Center and endpoint procedures; names the _CRYPTO-INFO metadata file.
xsiam/protect-your-endpoints/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/retrieve-support-file-passwordRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,29 +1,57 @@------description: Retrieve the Cortex XSIAM support file password for endpoint troubleshooting.description: Retrieve the Cortex XSIAM support file password for endpoint troubleshooting.------# Retrieve support file password# Retrieve support file passwordFrom Cortex XDR agent, the Tech Support File (TSF) is generated by the Cytool commandlog collectin a zip format that is protected by an encrypted password. The TSF file is archived inside another file which includes a metadata file that contains a token. This token is used to retrieve the password to unzip the TSF file.The Cortex XDR agent generates the Tech Support File (TSF) as a password-protected zip archive. The TSF is packaged inside an outer archive that also contains a metadata file with the encrypted token used to retrieve the password. Follow the steps below to retrieve the password and unzip the file.There are two methods to retrieve the TSF file password:The TSF is generated in either of two ways:• Remotely from Cortex XSIAM - The Retrieve Support File action is initiated from the Action Center or from an endpoint's page. The resulting archive is downloaded from the Action Center.• Locally from the endpoint - Thecytool log collectcommand is run on the endpoint's command line. The resulting archive is saved on the endpoint's local filesystem.stepperstepperstepstep#### Retrieve the password from the endpoint, using the server Tokens and Passwords option.### Locate the tokenFind the encrypted token inside the archive.• Go to Inventory → Endpoints → All Endpoints1. Open the outer archive that contains the TSF. This is either the file you downloaded from the Action Center or the file saved locally on the endpoint.• At the top of the page, click the key icon (Tokens and Passwords) and select Retrieve Support File Password.2. Locate and open the metadata file (typically named_CRYPTO-INFO).• In the Retrieve Support File Password dialog box, in the Encrypted Password field, paste the token that you copied from the metadata file located in the saved file when running the Cytool log collect command.3. Copy the encrypted token string it contains.• Click the copy button to copy the password displayed and then click Ok. Use the password to unzip the TSF file.endstependstepstepstep#### Retrieve the password for the TSF file from the server Action Center.### Retrieve the TSF file passwordThe next steps depend on how the TSF was generated.From the Action CenterFollow these steps if the TSF was downloaded from the Action Center.1. Go to Action Center → All Actions.2. Locate your Support File Retrieval action.3. Right-click the action and select Retrieve Support File Password.4. In the Retrieve Support File Password dialog box, in the Encrypted Password field, paste the token that you copied in Step 1.5. Click the copy button to copy the displayed password and then click Ok. Use the password to unzip the TSF file.</details>From the endpointFollow these steps if the TSF was collected locally by running thecytool log collectcommand on the endpoint's command line.1. Go to Inventory → Endpoints → All Endpoints.2. At the top of the page, click the key icon
(Tokens and Passwords) and select Retrieve Support File Password.
3. In the Retrieve Support File Password dialog box, in the Encrypted Password field, paste the token that you copied in Step 1.4. Click the copy button to copy the password displayed and then click Ok. Use the password to unzip the TSF file.• Go to Action Center+All Actions</details>• Right-click the action and select Retrieve Support File Password.• In the Retrieve Support File Password dialog box, in the Encrypted Password field, paste the token that you copied from the metadata file located in the download file.• Click the Copy button to copy the password displayed and then click Ok. Use the password to unzip the TSF file.endstependstependstepperendstepperShow markdown source
@@ -1,29 +1,57 @@ --- description: Retrieve the Cortex XSIAM support file password for endpoint troubleshooting. --- # Retrieve support file password -From Cortex XDR agent, the Tech Support File (TSF) is generated by the Cytool command `log collect` in a zip format that is protected by an encrypted password. The TSF file is archived inside another file which includes a metadata file that contains a token. This token is used to retrieve the password to unzip the TSF file. +The Cortex XDR agent generates the Tech Support File (TSF) as a password-protected zip archive. The TSF is packaged inside an outer archive that also contains a metadata file with the encrypted token used to retrieve the password. Follow the steps below to retrieve the password and unzip the file. -There are two methods to retrieve the TSF file password: +The TSF is generated in either of two ways: + +* **Remotely from Cortex XSIAM -** The **Retrieve Support File** action is initiated from the **Action Center** or from an endpoint's page. The resulting archive is downloaded from the Action Center. +* **Locally from the endpoint** - The `cytool log collect` command is run on the endpoint's command line. The resulting archive is saved on the endpoint's local filesystem. {% stepper %} {% step %} -#### Retrieve the password from the endpoint, using the server Tokens and Passwords option. +### Locate the token + +Find the encrypted token inside the archive. -* Go to **Inventory → Endpoints → All Endpoints** -* At the top of the page, click the key icon (**Tokens and Passwords**) and select **Retrieve Support File Password**. -* In the **Retrieve Support File Password** dialog box, in the **Encrypted Password** field, paste the token that you copied from the metadata file located in the saved file when running the Cytool log collect command. -* Click the copy button to copy the password displayed and then click **Ok**. Use the password to unzip the TSF file. +1. Open the outer archive that contains the TSF. This is either the file you downloaded from the **Action Center** or the file saved locally on the endpoint. +2. Locate and open the metadata file (typically named `_CRYPTO-INFO`). +3. Copy the encrypted token string it contains. {% endstep %} {% step %} -#### Retrieve the password for the TSF file from the server Action Center. +### Retrieve the TSF file password + +The next steps depend on how the TSF was generated.  + +<details> + +<summary>From the Action Center</summary> + +Follow these steps if the TSF was downloaded from the **Action Center**. + +1. Go to **Action Center** → **All Actions**. +2. Locate your **Support File Retrieval** action. +3. Right-click the action and select **Retrieve Support File Password**. +4. In the **Retrieve Support File Password** dialog box, in the **Encrypted Password** field, paste the token that you copied in Step 1. +5. Click the copy button to copy the displayed password and then click **Ok**. Use the password to unzip the TSF file. + +</details> + +<details> + +<summary>From the endpoint</summary> + +Follow these steps if the TSF was collected locally by running the `cytool log collect` command on the endpoint's command line.  + +1. Go to **Inventory** → **Endpoints** → **All Endpoints**. +2. At the top of the page, click the key icon <img src="https://2786854933-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FAEIjuYE3RXcIfmuQnBbm%2Fuploads%2Fgit-blob-e6a03305250c113a69f127e31e02e2d623fdac04%2F48eece5124cdca27f9a7a4ee50ae57b15cd6e3a3e056df865cf847c10efd7ae9.png?alt=media" alt="Screenshot_2025-08-04_at_15_40_52.png" data-size="line"> (**Tokens and Passwords**) and select **Retrieve Support File Password**. +3. In the **Retrieve Support File Password** dialog box, in the **Encrypted Password** field, paste the token that you copied in Step 1. +4. Click the copy button to copy the password displayed and then click **Ok**. Use the password to unzip the TSF file. -* Go to **Action Center+All Actions** -* Right-click the action and select **Retrieve Support File Password**. -* In the **Retrieve Support File Password** dialog box, in the **Encrypted Password** field, paste the token that you copied from the metadata file located in the download file. -* Click the Copy button to copy the password displayed and then click **Ok**. Use the password to unzip the TSF file. +</details> {% endstep %} {% endstepper %}