For the complete documentation index, see llms.txt. This page is also available as Markdown.

Cortex Cloud Logging and Collection Service Management overview

The Cloud Logging and Collection Service (CLCS) Management APIs allow you to programmatically manage Next-Generation Firewalls (NGFWs) connected to your CLCS environment.

CLCS enables NGFWs to forward logs directly to Cortex XDR for analysis and threat detection. These APIs provide the ability to list all connected devices and disconnect one or more devices in bulk, replacing the slow, manual UI workflow that only supports one-at-a-time removal.

Required licenses: This feature is included with Cortex Cloud Runtime Security or Cortex Cloud Posture Management.

RBAC permissions:

  • List connected devices: Data Collection > Data Sources > View

  • Disconnect devices: Data Collection > Data Sources > Edit

Last updated

Was this helpful?