> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management.md).

# Dataset management

{% hint style="warning" %}

### Prerequisite

Dataset Management requires **View/Edit** RBAC permissions for **Data Management** (under **Configurations** → **Data Management**), which are the same permissions required for Parsing Rules, Data Model Rules, and Event Forwarding.
{% endhint %}

The **Dataset Management** page enables you to manage your datasets and understand your overall data storage duration for different retention periods and datasets based on your hot and cold storage licenses, and retention add-ons that extend your storage. You can view details about your Cortex Cloud licenses and retention add-ons by selecting **Settings** → **Cortex Cloud License**.

{% hint style="info" %}

### Important

Cortex Cloud enforces retention on all log-type datasets excluding Host Inventory, Vulnerability Assessment, Metrics, and Users.
{% endhint %}

<details>

<summary>Hot and cold storage</summary>

Your current hot and cold storage licenses, including the default license retention and any additional retention add-ons to extend storage, are listed within the **Hot Storage License** and **Cold Storage License** sections of the **Dataset Management** page. Whenever you extend your license retention, depending on your requirements and license add-ons for both hot storage and cold storage, the add-ons are listed.

{% hint style="info" %}

### Note

Cold storage, in addition to a cold storage license, requires compute units (CU) to run cold storage queries. For more information on CU, see [Manage compute units](/cortex-cloud-posture-management/data-management/manage-compute-units.md).
{% endhint %}

</details>

<details>

<summary>Additional hot storage</summary>

You can expand your license retention to include flexible Hot Storage based retention to help accommodate varying storage requirements for different retention periods and datasets. This add-on license is available to purchase based on your storage requirements for a minimum of 1,000 GB. If this license is purchased, an **Additional Storage** subheading in the **Hot Storage License** section is displayed on the **Dataset Management** page with a bar indicating how much of the storage is used.

{% hint style="info" %}

### Note

Only datasets that are already handled as part of the GB license are supported for this license. In addition, the retention configuration is only available in Cortex Cloud, as opposed to the public APIs.
{% endhint %}

</details>

<details>

<summary>Edit the retention plan</summary>

On any dataset configured to use Additional Hot Storage, you can edit the retention period. This enables you to view the current retention details and configure the retention. This includes setting the amount of flexible hot storage-based retention designated for a dataset and the priority for the dataset's hot storage.

</details>

<details>

<summary>Datasets table</summary>

For each dataset listed in the table, the following information is available:

{% hint style="info" %}

### Note

* Certain fields are exposed and hidden by default. An asterisk (\*) is beside every field that is exposed by default.
* Datasets include dataset permission enforcements in the Cortex Query Language(XQL), Query Center, and XQL Widgets. For example, to view or access any of the **`endpoints`** and **`host_inventory`** datasets, you need role-based access control (RBAC) permissions to the **Endpoint Administration** and **Host Inventory** views. Managed Security Services Providers (MSSP) administration permissions are not enforced on child tenants, but only on the MSSP tenant.
  {% endhint %}

| Field                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| \*TYPE                   | Displays the type of dataset based on the method used to upload the data. The possible values include: Correlation, Lookup, Raw, Snapshot, System, and User. For more information on each dataset type, see [What are datasets?](/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/what-are-datasets.md).                                                                                                                                                                                                                                                    |
| \*LOG UPDATE TYPE        | Event logs are updated either continuously (**Logs**) or the current state is updated periodically (**State**) as detailed in the **Last Updated** column.                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| \*LAST UPDATED           | <p>Last time the data in the dataset logs were updated.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Important</strong></p><p>This column is updated once a day. Therefore, if the dataset was created or updated by the target or lookup flows, it's possible that the <strong>Last Updated</strong> value is a day behind when the queries or reports were run as it was before this column was updated.</p></div>                                                                                                                   |
| \*ADDITIONAL STORAGE     | Amount of flexible hot storage-based retention designated for this dataset in months, where a month is calculated as 31 days.                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| \*TOTAL DAYS STORED      | Actual number of days that the data is stored in the Cortex Cloud tenant, which is comprised of the **HOT RANGE** + the **COLD RANGE**.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| \*HOT RANGE              | Details the exact period of the Hot Storage from the start date to the end date.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| \*COLD RANGE             | Details the exact period of the Cold Storage from the start date to the end date.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| \*TOTAL SIZE STORED      | Actual size of the data that is stored in the Cortex Cloud tenant. This number is dependent on the events stored in the hot storage. For the **`xdr_data`** dataset, where the first 31 days of storage are included with your license, the first 31 days are not included in the **TOTAL SIZE STORED** number.                                                                                                                                                                                                                                                                            |
| \*ADDITIONAL SIZE STORED | Actual size of the additional flexible hot storage data that is stored in the Cortex Cloud tenant in GB. This number is dependent on the events stored in the hot storage.                                                                                                                                                                                                                                                                                                                                                                                                                 |
| \*AVERAGE DAILY SIZE     | Average daily amount stored in the Cortex Cloud tenant. This number is dependent on the events stored in the hot storage.                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| \*HOT STORAGE PRIORITY   | Indicates the priority set for the dataset's hot storage as either **Low**, **Medium**, or **High**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| \*TOTAL EVENTS           | Number of total events/logs that are stored in the Cortex Cloud tenant. This number is dependent on the events stored in the hot storage.                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| \*AVERAGE EVENT SIZE     | Average size of a single event in the dataset (**TOTAL SIZE STORED** divided by the **TOTAL EVENTS**). This number is dependent on the events stored in the hot storage.                                                                                                                                                                                                                                                                                                                                                                                                                   |
| \*TTL                    | <p>For lookup datasets, displays the value of the time to live (TTL) configured for when lookup entries expire and are removed automatically from the dataset. The possible values are:</p><ul><li><strong>Forever</strong>: Lookup entries never expire (default).</li><li><strong>Custom</strong>: Lookup entries expire according to a set number of days, hours, and minutes. The maximum number of days is 99999.</li></ul><p>For more information, see <a href="/pages/9ot3mTzlSvcqn5JJFXJe#UUID-03b106af-2adc-f17b-fad7-a2d023306214">Set time to live for lookup datasets</a>.</p> |
| DEFAULT QUERY TARGET     | Details whether the dataset is configured to use as your default query target in XQL Search, so when you write your queries you do not need to define a dataset. By default, only the **`xdr_data`** dataset is configured as the **DEFAULT QUERY TARGET** and this field is set to **Yes**. All other datasets have this field set to **No**. When setting multiple default datasets, your query does not need to mention any of the dataset names, and Cortex Cloud queries the default datasets using a **`join`**.                                                                     |
| TOTAL HOT RETENTION      | Total hot storage retention configured for the dataset in months, where a month is calculated as 31 days.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| TOTAL COLD RETENTION     | Total cold storage retention configured for the dataset in months, where a month is calculated as 31 days.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |

</details>

<details>

<summary>Dataset views</summary>

Cortex Cloud supports creating dataset views in the `Dataset Management` page to enhance data efficiency and security. Dataset views provide a virtual representation of data from one or more datasets, based on the Cortex Query Language (XQL) query defined, and provide multiple benefits, such as joining datasets into logical subsets through defined queries, manipulating data without altering underlying datasets, and segregating data for specific user needs or access privileges through the Role-based access control (RBAC) settings.

Once a dataset view is created, you can edit or delete the dataset view by right-clicking the dataset view in the **Dataset Views** table. A dataset view can only be deleted if there are no other dependencies. For example, if a Correlation Rule is based on a dataset view, you wouldn't be able to delete the dataset view until you removed the dataset view from the XQL query of the Correlation Rule.

Cortex Cloud logs entries for events related to creating, editing, and deleting datasets or dataset views. These monitored activities are available to view in the datasets and dataset views audit logs in the Management Audit Logs. For more information, see [Monitor datasets and dataset views activity](/cortex-cloud-posture-management/data-management/dataset-management/monitor-datasets-and-dataset-views-activity.md).

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/data-management/dataset-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
