Documentation — September 04, 2026
3 files changed, 10 insertions, 12 deletions — view the commit on the mirror.
The FedRAMP caveat on AWS CloudTrail ingestion is dropped; SaaS AI agent onboarding links resolve
- AWS CloudTrail loses the paragraph advising against ingesting data from an AWS commercial environment into a FedRAMP-certified Cortex XSIAM tenant.
- SaaS AI Agent Security replaces all eight
broken-referenceplaceholders on the onboarding index with real per-platform paths. - Nothing else moved: the only other change is a wording tweak to the Attack Surface Management overview’s description.
Highlights
-
The FedRAMP warning on ingesting AWS commercial data is gone
The paragraph saying Palo Alto Networks does not recommend ingesting data from an AWS commercial environment into a FedRAMP-certified Cortex XSIAM tenant, and to contact Customer Support if you must, was deleted with nothing put in its place.
-
Eight SaaS AI agent onboarding links stop pointing at broken-reference
Atlassian Rovo, Box AI Agents, ChatGPT Enterprise, Cursor Enterprise, Gemini Enterprise, Microsoft 365 Copilot, Microsoft Copilot Studio and ServiceNow AI Platform each now link to a page under onboard-saas-ai-agents/.
Changes
3 files listed, 3 written up and shaded below.
-
▸ ▾ Onboard SaaS AI Agents modified +8 −8 All eight platform links on the onboarding index change from broken-reference placeholders to relative paths under onboard-saas-ai-agents/.
xsiam/cloud-security/cortex-cloud-saas-security/saas-ai-agent-security/onboard-saas-ai-agentsRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,18 +3,18 @@ description: Learn how to onboard supported SaaS AI agents in Cortex XSIAM.------# Onboard SaaS AI Agents# Onboard SaaS AI AgentsAs you increasingly integrate AI agents—software powered by Large Language Models (LLMs) that connect to your enterprise systems and utilize memory to execute workflows—you also introduce new attack vectors. Effectively onboarding your AI agent platforms into a comprehensive AISPM framework is the critical first step to managing these risks.As you increasingly integrate AI agents—software powered by Large Language Models (LLMs) that connect to your enterprise systems and utilize memory to execute workflows—you also introduce new attack vectors. Effectively onboarding your AI agent platforms into a comprehensive AISPM framework is the critical first step to managing these risks.Onboard your new and existing SaaS-based agent platforms to establish a secure, compliant cloud environment. Select a specific SaaS AI Agent to onboard:Onboard your new and existing SaaS-based agent platforms to establish a secure, compliant cloud environment. Select a specific SaaS AI Agent to onboard:• Atlassian Rovo• Atlassian Rovo• Box AI Agents• Box AI Agents• ChatGPT Enterprise• ChatGPT Enterprise• Cursor Enterprise• Cursor Enterprise• Gemini Enterprise• Gemini Enterprise• Microsoft 365 Copilot• Microsoft 365 Copilot• Microsoft Copilot Studio• Microsoft Copilot Studio• ServiceNow AI Platform• ServiceNow AI Platform
Show markdown source
@@ -3,18 +3,18 @@ description: Learn how to onboard supported SaaS AI agents in Cortex XSIAM. --- # Onboard SaaS AI Agents As you increasingly integrate AI agents—software powered by Large Language Models (LLMs) that connect to your enterprise systems and utilize memory to execute workflows—you also introduce new attack vectors. Effectively onboarding your AI agent platforms into a comprehensive AISPM framework is the critical first step to managing these risks. Onboard your new and existing SaaS-based agent platforms to establish a secure, compliant cloud environment. Select a specific SaaS AI Agent to onboard: -* [Atlassian Rovo](broken-reference) -* [Box AI Agents](broken-reference) -* [ChatGPT Enterprise](broken-reference) -* [Cursor Enterprise](broken-reference) -* [Gemini Enterprise](broken-reference) -* [Microsoft 365 Copilot](broken-reference) -* [Microsoft Copilot Studio](broken-reference) -* [ServiceNow AI Platform](broken-reference) +* [Atlassian Rovo](onboard-saas-ai-agents/onboard-atlassian-rovo) +* [Box AI Agents](onboard-saas-ai-agents/onboard-box-ai-agents) +* [ChatGPT Enterprise](onboard-saas-ai-agents/onboard-chatgpt-enterprise) +* [Cursor Enterprise](onboard-saas-ai-agents/onboard-cursor-enterprise) +* [Gemini Enterprise](onboard-saas-ai-agents/onboard-gemini-enterprise) +* [Microsoft 365 Copilot](onboard-saas-ai-agents/onboard-m365-copilot) +* [Microsoft Copilot Studio](onboard-saas-ai-agents/onboard-microsoft-copilot-studio) +* [ServiceNow AI Platform](onboard-saas-ai-agents/onboard-service-now) <br>
-
▸ ▾ Ingest audit logs from AWS CloudTrail modified +0 −2 Removes the recommendation against ingesting AWS commercial environment data into a FedRAMP-certified tenant, and the pointer to Customer Support with it.
xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/vendor-specific-data-sources-and-connectors/amazon/amazon-s3/ingest-audit-logs-from-aws-cloudtrailRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -3,18 +3,16 @@ description: Collect audit logs from AWS CloudTrail in Cortex XSIAM.------# Ingest audit logs from AWS CloudTrail# Ingest audit logs from AWS CloudTrailYou can forward audit logs for the relative service to Cortex XSIAM from AWS CloudTrail.You can forward audit logs for the relative service to Cortex XSIAM from AWS CloudTrail.To receive audit logs from Amazon Simple Storage Service (Amazon S3) via AWS CloudTrail, you must first configure data collection from Amazon S3. You can then configure the Data Sources & Integrations settings in Cortex XSIAM for Amazon S3. After you set up collection integration, Cortex XSIAM begins receiving new logs and data from the source.To receive audit logs from Amazon Simple Storage Service (Amazon S3) via AWS CloudTrail, you must first configure data collection from Amazon S3. You can then configure the Data Sources & Integrations settings in Cortex XSIAM for Amazon S3. After you set up collection integration, Cortex XSIAM begins receiving new logs and data from the source.We do not recommend ingestion of data from an AWS commercial environment into a FedRAMP-certified Cortex XSIAM tenant. However, if you must do so, contact Customer Support for assistance.hint infohint infoNoteNoteFor more information on configuring data collection from Amazon S3 using AWS CloudTrail, see the AWS CloudTrail Documentation.For more information on configuring data collection from Amazon S3 using AWS CloudTrail, see the AWS CloudTrail Documentation.endhintendhintWhen Cortex XSIAM begins receiving logs, the app automatically creates an Amazon S3 Cortex Query Language (XQL) dataset (aws_s3_raw). This enables you to search the logs with XQL Search using the dataset. For example queries, refer to the in-app XQL Library.When Cortex XSIAM begins receiving logs, the app automatically creates an Amazon S3 Cortex Query Language (XQL) dataset (aws_s3_raw). This enables you to search the logs with XQL Search using the dataset. For example queries, refer to the in-app XQL Library.Show markdown source
@@ -3,18 +3,16 @@ description: Collect audit logs from AWS CloudTrail in Cortex XSIAM. --- # Ingest audit logs from AWS CloudTrail You can forward audit logs for the relative service to Cortex XSIAM from AWS CloudTrail. To receive audit logs from Amazon Simple Storage Service (Amazon S3) via AWS CloudTrail, you must first configure data collection from Amazon S3. You can then configure the Data Sources & Integrations settings in Cortex XSIAM for Amazon S3. After you set up collection integration, Cortex XSIAM begins receiving new logs and data from the source. -We do not recommend ingestion of data from an AWS commercial environment into a FedRAMP-certified Cortex XSIAM tenant. However, if you must do so, contact Customer Support for assistance. - {% hint style="info" %} **Note** For more information on configuring data collection from Amazon S3 using AWS CloudTrail, see the [AWS CloudTrail Documentation](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-create-a-trail-using-the-console-first-time.html). {% endhint %} When Cortex XSIAM begins receiving logs, the app automatically creates an Amazon S3 Cortex Query Language (XQL) dataset (`aws_s3_raw`). This enables you to search the logs with XQL Search using the dataset. For example queries, refer to the in-app XQL Library. -
▸ ▾ Learn about Attack Surface Management modified +2 −2 The page description now expands Attack Surface Management to "(ASM)" on first use; the body is untouched.
xsiam/detect-investigate-and-respond-to-threats/attack-surface-management/get-started-with-attack-surface-managementRead it on the Cortex docs portal ↗ Read it here → This file's diff on GitHub ↗
Before After@@ -1,12 +1,12 @@------description: >-description: >-Learn about Cortex XSIAM Attack Surface Management capabilities for finding,Learn about Cortex XSIAM Attack Surface Management (ASM) capabilities forprioritizing, and remediating external asset exposures.finding, prioritizing, and remediating external asset exposures.------# Learn about Attack Surface Management# Learn about Attack Surface ManagementBefore you get started with Cortex XSIAM Attack Surface Management, review the topics in this section to better understand what attack surface management is, what the key use cases are, and how it works.Before you get started with Cortex XSIAM Attack Surface Management, review the topics in this section to better understand what attack surface management is, what the key use cases are, and how it works.## What is attack surface management?## What is attack surface management?Show markdown source
@@ -1,12 +1,12 @@ --- description: >- - Learn about Cortex XSIAM Attack Surface Management capabilities for finding, - prioritizing, and remediating external asset exposures. + Learn about Cortex XSIAM Attack Surface Management (ASM) capabilities for + finding, prioritizing, and remediating external asset exposures. --- # Learn about Attack Surface Management Before you get started with Cortex XSIAM Attack Surface Management, review the topics in this section to better understand what attack surface management is, what the key use cases are, and how it works. ## **What is attack surface management?**