> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation.md).

# Cortex XDR 3.x Documentation

- [Get started with Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme.md): Learn about key functionality within Cortex XDR, the available license plans, and the typical roles and responsibilities in a Security Operations Center (SOC) team.
- [What is Cortex XDR?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/what-is-cortex-xdr.md): Learn about Cortex XDR and the security challenges it addresses.
- [Concepts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/concepts.md): Learn more about the Cortex XDR main concepts.
- [Supported web browsers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/supported-web-browsers.md)
- [Use the interface](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/use-the-interface.md): Learn more about how to use the Cortex XDR interface.
- [What is Cortex Gateway?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/what-is-cortex-gateway.md): A brief introduction to Cortex Gateway
- [Understand Cortex XDR license plans](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans.md): Learn more about the available Cortex XDR licenses and add-ons.
- [Data retention in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/data-retention-in-cortex-xdr.md): Learn more about the default retention periods for all Cortex XDR licenses, and the available retention add-ons.
- [Data storage lifecycle](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/data-storage-lifecycle.md)
- [License allocation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/license-allocation.md): Learn more about how Cortex XDR regulates licenses.
- [License expiration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/license-expiration.md): Learn more about the Cortex XDR license expiration and validation period.
- [Upgrade your tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/understand-cortex-xdr-license-plans/upgrade-your-tenant.md)
- [Security Operations Center roles and responsibilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/security-operations-center-roles-and-responsibilities.md): Learn about the typical core roles that make up a SOC team.
- [In-product support case creation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/in-product-support-case-creation.md): Open a support case directly in Cortex XDR and record your console to capture your issues and have the case handled efficiently.
- [Upgrade to Cortex XDR 5.x](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/upgrade-to-cortex-xdr-5.x.md)
- [Onboard and configure Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr.md): Learn about the deployment preparation and procedures to onboard and configure Cortex XDR.
- [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps.md): Follow the steps in the onboarding checklist to successfully deploy and onboard Cortex XDR.
- [Plan and prepare](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/plan-and-prepare.md): Learn more about deployment considerations and onboarding steps.
- [Cortex XDR onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/cortex-xdr-onboarding-checklist.md): Review the steps to deploy and onboard Cortex XDR.
- [Step 1: Activate Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-1-activate-cortex-xdr.md): Learn how to activate your tenant.
- [Cortex XDR supported regions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-1-activate-cortex-xdr/cortex-xdr-supported-regions.md): Supported regions in which you want to host Cortex XDR and any associated services.
- [Enable access to required PANW resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-1-activate-cortex-xdr/enable-access-to-required-panw-resources.md): Learn more about enabling network access to the Cortex XDR resources.
- [Step 2: Pre-installation steps for Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents.md)
- [Assign user roles and groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/assign-user-roles-and-groups.md): Learn how to assign users to roles and user groups.
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication.md): Authenticate Cortex XDR users using SAML 2.0 or Cortex Gateway.
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Authenticate Cortex XDR users when using the Customer Support Portal.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication/authenticate-users-using-sso.md): Set up authentication in the Cortex XDR tenant using SSO.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md)
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md)
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/define-endpoint-groups.md): Define an endpoint group and then apply policy rules and manage specific endpoints.
- [Manage endpoint profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/manage-endpoint-profiles.md): Endpoint security profiles can be used immediately, or customized, to protect your endpoints from threats.
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/endpoint-data-collection.md): To aid in endpoint detection and alert investigation, the Cortex XDR agent collects endpoint information when an alert is triggered.
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-2-pre-installation-steps-for-cortex-xdr-agents/configure-global-agent-settings.md): Learn how to configure the Cortex XDR agent global settings that operate on your endpoints.
- [Step 3: Install Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents.md): Learn about the initial steps required to deploy Cortex XDR agent software to endpoints.
- [Plan your agent deployment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents/plan-your-agent-deployment.md)
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md): Learn more about how to control Cortex XDR agent and content upgrades.
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents/create-an-agent-installation-package.md): Learn how to create a Cortex XDR agent installation package to deploy to your endpoints.
- [Deploy agent installation packages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-3-install-cortex-xdr-agents/deploy-agent-installation-packages.md): Learn how to deploy an agent installation package on endpoints.
- [Step 4: Configure and deploy Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr.md)
- [Cortex XDR - Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr/cortex-xdr-analytics.md)
- [Configure Cortex XDR network parameters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr/cortex-xdr-analytics/configure-cortex-xdr-network-parameters.md)
- [Enable the Analytics Engine and Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr/cortex-xdr-analytics/enable-the-analytics-engine-and-identity-analytics.md)
- [Set up Cloud Identity Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-4-configure-and-deploy-cortex-xdr/set-up-cloud-identity-engine.md): Learn how to set up Cloud Identity Engine to use with Cortex XDR.
- [Step 5: Define data sources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-5-define-data-sources.md): Learn how to configure data ingestion ingest data from a variety of Palo Alto Networks and third-party sources.
- [Step 6: Perform health checks](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-6-perform-health-checks.md): Learn which health checks to perform after deployment.
- [Monitor agent operational status in Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/deployment-steps/step-6-perform-health-checks/monitor-agent-operational-status-in-cortex-xdr.md): View the operational status of any Cortex XDR agent that you manage.
- [Post-deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps.md)
- [Set up your environment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment.md)
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/configure-server-settings.md): Configure server settings such as keyboard shortcuts, timezone, and timestamp format.
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/configure-security-settings.md): Configure security settings such as session expiration, user login expiration, and dashboard expiration.
- [Log forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding.md): Stay informed and updated about events in your system by forwarding alerts and reports to an external service, such as a syslog receiver, a Slack channel, or an email account.
- [Forward logs from Cortex XDR to external services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services.md): Learn how to forward logs from Cortex XDR to external services such as email, Slack, or a syslog receiver.
- [Integrate a syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services/integrate-a-syslog-receiver.md): Define syslog settings and then configure notification forwarding to receive notifications about alerts and reports.
- [Integrate Slack for outbound notifications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services/integrate-slack-for-outbound-notifications.md): Learn how to integrate Cortex XDR with your Slack workspace and stay updated on important alerts and events.
- [Configure notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services/configure-notification-forwarding.md): Learn how to create a forwarding configuration that specifies the log type you want to forward.
- [Monitor administrative activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/forward-logs-from-cortex-xdr-to-external-services/monitor-administrative-activity.md): View all Cortex XDR administrator-initiated actions taken on alerts, incidents, and live terminal sessions.
- [Log notification formats](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats.md): Cortex XDR provides you with different formats for its log notifications.
- [Management audit log messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/management-audit-log-messages.md): View the types of Cortex XDR management audit log messages that are sent.
- [Alert notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/alert-notification-format.md): Learn about the formats used to forward Cortex XDR agent, BIOC, IOC, analytics, correlation, and third-party alerts.
- [Agent Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/agent-audit-log-notification-format.md): An email account or a syslog receiver are the notification channels through which the Agent Audit log is communicated.
- [Management Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/management-audit-log-notification-format.md): An email account or a syslog receiver are the notification channels through which the Management Audit log is communicated.
- [Log format for IOC and BIOC alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/log-format-for-ioc-and-bioc-alerts.md): An email account or a syslog receiver are the notification channels through which IOC and BIOC alerts are communicated.
- [Analytics log format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/analytics-log-format.md): Learn about the syntax and different variables that are used in the analytics log format.
- [Log formats](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/log-forwarding/log-notification-formats/log-formats.md): Learn about the different log formats that Cortex XDR can forward to an external server or email account.
- [Automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules.md): Use automation rules to define alert conditions that trigger an action that you specify within the rule.
- [Manage automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules/manage-automation-rules.md): Learn how to manage automation rules for Cortex XDR.
- [Automation settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules/automation-settings.md): Threshold limits may be implemented for settings of automation rules.
- [Automation rule actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules/automation-rule-actions.md): Includes the list of actions to take when the alert condition of the automation rule is triggered for Cortex XDR.
- [Automation Audit Log](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/set-up-your-environment/automation-rules/automation-audit-log.md): Includes the list of fields included in the Automation Audit Log for Cortex XDR.
- [Manage user roles and access management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management.md): Learn how to manage access for users, user roles, user groups, and Single Sign-On (SSO) for users on a specific Cortex XDR tenant.
- [Manage user roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-roles.md): Manage user roles that are assigned to Cortex XDR users or user groups in Cortex XDR Access Management.
- [Manage user access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access.md): Manage access permissions for Cortex XDR users.
- [User access reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access/user-access-reference-information.md)
- [Manage user scope](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope.md): Learn about Scope-Based Access Control (SBAC) and how to assign users to specific tags of different types in your organization.
- [XQL query management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/xql-query-management.md): Administrators can set controls on running XQL queries.
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/onboard-and-configure-cortex-xdr/post-deployment-steps/dashboards-and-reports.md)
- [Endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security.md): Learn about configuring and managing endpoint security.
- [Endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection.md): This topic provides an overview of traditional endpoint protection versus the protection of endpoints using Cortex XDR.
- [Malware protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/malware-protection.md): Cortex XDR prevents malware attacks and provides protection on endpoints based on the different operating systems.
- [Exploit protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/exploit-protection.md): Cortex XDR prevents exploit attempts and provides protection on endpoints based on the different operating systems.
- [File analysis and protection flow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/file-analysis-and-protection-flow.md): The Cortex XDR agent utilizes advanced multi-method protection and prevention techniques to protect from both known and unknown malware and software exploits.
- [Endpoint protection capabilities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/endpoint-protection-capabilities.md): The endpoint protection capabilities vary depending on the platform (operating system) that is used on each of your endpoints.
- [Endpoint protection modules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/endpoint-protection-modules.md): Security modules are activated for your endpoints depending on the chosen security profile and the operating system on the endpoint.
- [Processes protected by exploit security policy](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/processes-protected-by-exploit-security-policy.md): Application processes that run on your endpoint are protected by the exploit security policy.
- [WildFire analysis concepts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/wildfire-analysis-concepts.md): Learn about the analysis concepts used by Wildfire.
- [About content updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/about-content-updates.md): To increase security coverage and quickly resolve any issues in policy, Palo Alto Networks can seamlessly deliver software packages called content updates.
- [Endpoint data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/endpoint-data-collection.md): To aid in endpoint detection and alert investigation, the Cortex XDR agent collects endpoint information when an alert is triggered.
- [Guidelines for keeping Cortex XDR agents and content updated](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/endpoint-protection/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md): Learn more about how to control Cortex XDR agent and content upgrades.
- [Install and manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints.md): Learn how to set up profiles, policies and other settings for endpoint protection, how to install Cortex XDR agent on endpoints, and how to manage them after installation.
- [Set up endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection.md): Set up endpoint protection profiles and policies, exceptions, endpoint hardening, and other endpoint settings.
- [Set up endpoint profiles and exception rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules.md): Endpoint security profiles can be used immediately, or customized, to protect your endpoints from threats.
- [Set up malware prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-malware-prevention-profiles.md): Configure malware prevention profiles to control the actions taken by Cortex XDR agents when known malware, macros, and unknown files try to run.
- [Set up exploit prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exploit-prevention-profiles.md): Exploit prevention profiles control the action that the Cortex XDR agent takes when attempts to exploit software vulnerabilities or flaws occur.
- [Set up agent settings profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-agent-settings-profiles.md): Use agent settings profiles to customize Cortex XDR agent settings for different platforms and groups of users.
- [Set up restrictions prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-restrictions-prevention-profiles.md): Restrictions prevention profiles limit where executables can run on an endpoint.
- [Set up exception profiles and rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules.md): Exception profiles can be configured to override security policies for known processes, files, digital signers, URLs, BTP rules, telephone numbers, and other exceptions.
- [Exception configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/exception-configuration.md): Learn how to configure exceptions from your baseline policy.
- [Alert exclusions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/alert-exclusions.md): Learn how to review and manage alert exclusions.
- [Add an alert exclusion rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/alert-exclusions/add-an-alert-exclusion-rule.md): Learn how to create a rule to exclude certain criteria from raising alerts in Cortex XDR.
- [Add an IOC or BIOC rule exception](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-an-ioc-or-bioc-rule-exception.md): Learn how to add an IOC or BIOC rule exception.
- [Add a disable prevention rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-prevention-rule.md): You can create granular exceptions to prevention actions defined for your endpoints.
- [Add a disable injection and prevention rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-disable-injection-and-prevention-rule.md): You can generate a temporary exception to bypass a process from prevention modules and injections.
- [Add a support exception rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-support-exception-rule.md): Learn how to add a support exception rule.
- [Add a legacy exception rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule.md): Learn how to use Cortex XDR Legacy Exception rules to configure an exception to prevention and protection modules on endpoints for selected profiles.
- [Add a new exceptions security profile](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule/add-a-new-exceptions-security-profile.md): Learn how to add a new exceptions security profile.
- [Add a global endpoint policy exception](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-up-endpoint-profiles-and-exception-rules/set-up-exception-profiles-and-rules/add-a-legacy-exception-rule/add-a-global-endpoint-policy-exception.md): Learn how to define and manage global endpoint policy exceptions in Cortex XDR.
- [Define endpoint groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/define-endpoint-groups.md): Define an endpoint group and then apply policy rules and manage specific endpoints.
- [Configure global agent settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/configure-global-agent-settings.md): Learn how to configure the Cortex XDR agent global settings that operate on your endpoints.
- [Apply profiles to endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/apply-profiles-to-endpoints.md): Learn how to apply security profiles to your endpoints, depending on the platform used.
- [Create an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package.md): Learn how to create a Cortex XDR agent installation package to deploy to your endpoints.
- [Manage an agent installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/create-an-agent-installation-package/manage-an-agent-installation-package.md): Learn how to make changes such as deleting an agent installation package or editing the package name.
- [Harden endpoint security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security.md): By hardening your endpoints with Cortex XDR agent, you can make these endpoints more secure and safer from attackers.
- [Device control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/device-control.md): Protect your Windows and macOS-based endpoints from connecting to malicious USB-connected removable devices, to Bluetooth devices, and to print jobs.
- [Host firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-firewall.md): Control communications on your endpoints based on the network location of your device by using the Cortex XDR host firewall.
- [Host firewall for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-firewall/host-firewall-for-windows.md): Control communications on your endpoints based on the network location of your device by using the host firewall.
- [Host firewall for macOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-firewall/host-firewall-for-macos.md): Control communications on your endpoints based on the network location of your device by using the host firewall.
- [Disk encryption](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/disk-encryption.md): For enhanced security, you can configure and apply disk encryption profiles to the disks of your Windows and Mac endpoints.
- [Host Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/host-inventory.md): Review the inventory of all your hosts (endpoints), and identify in the inventory any IT and security issues in your network.
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/harden-endpoint-security/vulnerability-assessment.md): Perform a vulnerability assessment of all endpoints in your network using Cortex XDR. This includes CVE, endpoint, and application analysis.
- [Set a Cortex XDR agent Critical Environment version](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-a-cortex-xdr-agent-critical-environment-version.md): Set the Cortex XDR agent as a Critical Environment (CE) version.
- [Set an application proxy for Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/set-an-application-proxy-for-cortex-xdr-agents.md): Set an application-specific proxy for the Cortex XDR agent without affecting the communication of other applications on the endpoint.
- [Pairing Prisma Cloud Compute with Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/set-up-endpoint-protection/pairing-prisma-cloud-compute-with-cortex-xdr.md): Learn how to pair Prisma Cloud Compute with Cortex XDR for use with the Cortex XDR Agent for Cloud.
- [Manage endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection.md)
- [Manage endpoint tags](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-tags.md): Segment your endpoints according to dynamic tags.
- [Set an alias for an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/set-an-alias-for-an-endpoint.md): Configure an alias to identify one or more endpoints by a name that is different from the endpoint hostname.
- [Manage endpoint prevention profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-endpoint-prevention-profiles.md): You can manage the endpoint prevention profiles of your Cortex XDR agent endpoints in various ways, including editing, duplicating, and populating endpoint prevention policy rules.
- [Upgrade Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/upgrade-cortex-xdr-agents.md): You can upgrade the Cortex XDR agent software by using the appropriate method for the endpoint operating system.
- [Restart agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/restart-agent.md): Learn how to restart the agent on the endpoint.
- [Uninstall the Cortex XDR agent](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/uninstall-the-cortex-xdr-agent.md): Uninstall Cortex XDR agent from one or more endpoints at any time using the Action Center, or one-by-one using the All Endpoints page.
- [Delete Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/delete-cortex-xdr-agents.md): Delete endpoints from Cortex XDR tenant views.
- [Manage agent tokens](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/manage-agent-tokens.md): Manage tokens per agent to retrieve the password used to run functions at the agent.
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/retrieve-support-file-password.md): Learn how to retrieve the password to access files from the Tech Support File (TSF), which is generated in a zip format protected by an encrypted password.
- [Move agents between managing servers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/move-agents-between-managing-servers.md): You can move Cortex XDR agents to other Cortex XDR managing servers.
- [Clear agent database](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/clear-agent-database.md): Learn how to clear the Cortex XDR agent database.
- [Send push notifications to iOS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/send-push-notifications-to-ios.md): Learn how to send push notifications to an iOS endpoint.
- [Monitor agent operational status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-operational-status.md): You can view the operational status of any Cortex XDR agent that you manage.
- [Monitor agent activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-activity.md): You can monitor the activity of any Cortex XDR Broker VM that you manage.
- [Monitor agent upgrade status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/endpoint-security/install-and-manage-endpoints/manage-endpoint-protection/monitor-agent-upgrade-status.md)
- [Detect threats and analyze data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data.md)
- [Detection rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules.md): Cortex XDR uses rules to detect threats and raise alerts.
- [What's an IOC?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-an-ioc.md): Indicators of compromise (IOCs) alert you about known malicious objects on your endpoints.
- [IOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-an-ioc/ioc-rule-details.md): Manage all indicators of compromise (IOCs) configured from or uploaded to Cortex XDR.
- [Create an IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-an-ioc/create-an-ioc-rule.md): From the Cortex XDR management console, you can upload or configure indicator of compromise (IOC) rules criteria.
- [What's a BIOC?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc.md): Behavioral indicators of compromise (BIOCs) alert you to respond to potentially compromising behaviors.
- [BIOC rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc/bioc-rule-details.md): From the Cortex XDR management console, you can define your own rules based on behavior with the behavioral indicator of compromise (BIOC) rules.
- [Create a BIOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc/create-a-bioc-rule.md): You can configure rules for behavioral indicators of compromise (BIOCs) to trigger an alert on an identified threat.
- [Manage Global BIOC Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-bioc/manage-global-bioc-rules.md): Update and copy BIOC rules, and add rule exceptions in Cortex XDR.
- [What's a correlation rule?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule.md)
- [Correlation rule details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/correlation-rule-details.md): In the Correlation Rules page, you can view all of your enabled rules in a table format and the various fields displayed.
- [Create a correlation rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/create-a-correlation-rule.md): Create new correlation rules from either the Correlation Rules page or when building a query in XQL Search, or import a many correlation rules from a file.
- [Field replacement syntax in correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/field-replacement-syntax-in-correlation-rules.md): Learn more about how to use field replacement syntax when creating correlation rules.
- [Manage correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/manage-correlation-rules.md): View and manage your correlation rules
- [Monitor correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/monitor-correlation-rules.md): You can monitor your correlation executions with the correlations\_auditing dataset.
- [Troubleshoot server errors in scheduled correlation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/whats-a-correlation-rule/troubleshoot-server-errors-in-scheduled-correlation-rules.md): Learn more about how to troubleshoot server errors in scheduled correlation rules.
- [Manage existing indicators](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/detection-rules/manage-existing-indicators.md): Edit, export, copy, disable, or remove rules, and add rule exceptions for existing indicators in Cortex XDR.
- [Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics.md): Cortex XDR uses an Analytics engine to examine logs and data from your sensors.
- [Analytics engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/analytics-engine.md)
- [Analytics sensors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/analytics-sensors.md)
- [Coverage of MITRE Attack tactics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/coverage-of-mitre-attack-tactics.md)
- [Analytics detection time intervals](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/analytics-detection-time-intervals.md)
- [Analytics alerts and Analytics BIOCs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/analytics-alerts-and-analytics-biocs.md)
- [View and manage Analytics rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/view-and-manage-analytics-rules.md): View and manage all Analytics rules
- [Identity Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/identity-analytics.md)
- [Identity Threat Module](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/analytics/identity-threat-module.md)
- [Forensic investigations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations.md): Learn about forensics, how to create forensic investigations, how to create and manage data collections, and how to assess other forensic related settings.
- [Manage an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation.md): Manage an investigation by adding collections, managing alerts, adjusting the timeline, analyzing assets and artifacts.
- [Create a new investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation/create-a-new-investigation.md): Learn how to create a forensics investigation. This includes adding a collection, exporting the data collection, managing alerts and key assets & artifacts.
- [Edit an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation/edit-an-investigation.md): Edit an existing investigation from the Forensic Investigations page.
- [Close an investigation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation/close-an-investigation.md): Close an existing investigation from the Forensic Investigations page.
- [User permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/manage-an-investigation/user-permissions.md): You can assign users to the investigation for them to view and manage the investigation.
- [Data collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection.md)
- [Hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/hunting.md): Search for specific data across a large number of hosts.
- [Create a hunt](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/hunting/create-a-hunt.md): Hunt collections enable you to search endpoints for suspicious activity to contribute to helping resolve the investigation.
- [Hunt results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/hunting/hunt-results.md): The hunt results page consolidates information collected by the Cortex XDR agent enabling you to investigate and take action on your endpoints.
- [Hunt status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/hunting/hunt-status.md): In the Actions table, you can scroll or use the filters to see the status of any search within a hunt across any of the targeted endpoints.
- [Triage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage.md): Triage collection gathers a wide range of artifacts that can be used to help understand the event that occurred on an endpoint.
- [Create a triage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/create-a-triage.md): Triage collections enable you to obtain additional information for certain activities that have occurred on the endpoints. This helps towards the forensics analytics of an investigation.
- [Upload an offline triage package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/upload-an-offline-triage-package.md): Use the Upload Offline Triage to upload archives containing forensic data collected by the offline collector.
- [Offline triage collection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/offline-triage-collection.md): Offline triage collection is supported for endpoints with no network connection or no Cortex XDR agent currently installed.
- [Triage results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/triage-results.md): You can drill down from the triage collection to review the results.
- [Triage status](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/data-collection/triage/triage-status.md): From the Actions table, you can view the search status of all the artifacts for the triage.
- [Analysis and documentation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/analysis-and-documentation.md): Learn more about your investigation by reviewing the additional data for analysis and documentation purposes.
- [Review alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/analysis-and-documentation/review-alerts.md): The alerts table displays all the collections within the investigation that has identified suspicious or malicious activity within the forensics data sets.
- [Investigation timeline](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/analysis-and-documentation/investigation-timeline.md): Investigation timeline shows the tagged forensic artifacts that were tagged. The tags display details of the forensic data collected from the endpoints.
- [Key assets & artifacts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/analysis-and-documentation/key-assets-and-artifacts.md): Displays the forensic investigation based on the tagged data and aligns it to the corresponding category.
- [Export](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/forensic-investigations/export.md): Select the export option to export data collection for long-term retention or offline analysis.
- [Asset management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management.md)
- [Vulnerability Assessment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/vulnerability-assessment.md): Perform a vulnerability assessment of all endpoints in your network using Cortex XDR. This includes CVE, endpoint, and application analysis.
- [Network configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/network-configuration.md): Cortex XDR Network Configuration provides a representation of your network assets by collecting and analyzing your network resources.
- [Configure your network parameters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/network-configuration/configure-your-network-parameters.md): Define the IP address ranges and domain names used by Cortex XDR to identify your network assets.
- [Cloud Compliance](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-compliance.md): Learn more about Cloud Compliance in Cortex XDR.
- [Manage Asset Scores](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/manage-asset-scores.md): Learn how to view and investigate User Scores and Host Scores using the Asset Scores page.
- [Asset Inventory](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-inventory.md): From the Cortex XDR management console, you can manage your different network assets.
- [All Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-inventory/all-assets.md): Cortex XDR enables you to view all external assets from the various asset categories on the All Assets page.
- [Specific Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-inventory/specific-assets.md): Cortex XDR enables you to view specific external assets from a designated assets category in the Specific Assets page.
- [Asset Roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles.md): View asset roles and the number of assets that are associated with each role. Learn how to manage asset roles for users and endpoints.
- [Manage Asset Roles for Users](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles/manage-asset-roles-for-users.md): Learn how to edit the user lists assigned to asset roles.
- [Honey user](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles/manage-asset-roles-for-users/honey-user.md): Honey users are decoy users designed to attract potential attackers.
- [Manage Asset Roles for Endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/asset-roles/manage-asset-roles-for-endpoints.md): Learn how to edit the host lists assigned to asset roles.
- [Cloud Inventory Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets.md): Cortex XDR provides a unified, normalized asset inventory for cloud assets to provide deeper visibility and context for incident investigation.
- [All Cloud Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/all-cloud-assets.md): Cortex XDR enables you to view all your cloud assets from the various cloud assets categories on the All Cloud Assets page.
- [Specific Cloud Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/specific-cloud-assets.md): Cortex XDR enables you to view specific cloud assets from a designated cloud assets category in the Specific Cloud Asset pages.
- [Manage Your Cloud Inventory Assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/detect-threats-and-analyze-data/asset-management/cloud-inventory-assets/manage-your-cloud-inventory-assets.md): Cortex XDR provides a central location to view and investigate information relating to inventory assets in the cloud.
- [Configure incidents and alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts.md)
- [External integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/external-integrations.md): Gain additional verification on key artifacts by integrating Cortex XDR with other Palo Alto Networks and third-party security products.
- [Prioritize incidents with starring and scoring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring.md): Prioritize and filter your incidents by using incident starring and incident scoring.
- [Incident starring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring/incident-starring.md): Starring incidents can help you to prioritize and filter your incidents.
- [Incident scoring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring/incident-scoring.md): Learn about the different incident scoring methods.
- [Set up incident scoring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/prioritize-incidents-with-starring-and-scoring/incident-scoring/set-up-incident-scoring.md): Set up incident scoring by enabling SmartScore and defining scoring rules.
- [Automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/automation-rules.md): Automation rules enable you to create rules comprised of alert conditions that trigger an action.
- [Automation settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/automation-rules/automation-settings.md): Threshold limits may be implemented for settings of automation rules.
- [Automation rule actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/automation-rules/automation-rule-actions.md): Includes the list of actions to take when the alert condition of the automation rule is triggered for Cortex XDR.
- [Automation audit log](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/configure-incidents-and-alerts/automation-rules/automation-audit-log.md): Includes the list of fields included in the automation audit log for Cortex XDR.
- [Investigate and respond to incidents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents.md): Learn about the Cortex XDR investigation and response operations.
- [Incident handling](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling.md): Learn about how incidents are created, the information contained in an incident, and how to prioritize and manage incidents.
- [What are incidents?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/what-are-incidents.md): Learn about how incidents are created, incident terminology, incident thresholds, and incident planning and response
- [Understanding the Incidents page](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/understanding-the-incidents-page.md): Use the Incidents page to review incident details and take remedial action.
- [Incidents table view reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/understanding-the-incidents-page/incidents-table-view-reference-information.md): Describes the fields in the table view.
- [Manage incidents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/manage-incidents.md): Lean how to investigate and manage your incidents.
- [Resolution reasons for incidents and alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/incident-handling/manage-incidents/resolution-reasons-for-incidents-and-alerts.md): Describes the resolution reasons for incidents and alerts.
- [Investigate artifacts and assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets.md): You can investigate specific artifacts and assets on dedicated views related to IP address, Network Assets, and File and Process Hash information.
- [Investigate an IP address](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-an-ip-address.md): Investigate incidents, connections, and threat intelligence reports related to a specific IP address on the IP View.
- [Investigate an asset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-an-asset.md): Investigate host assets and view host insights on the Asset View.
- [Investigate a host](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-host.md): Investigate host assets associated with your incidents
- [Investigate a file and process hash](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-file-and-process-hash.md): Investigate incidents, actions, and threat intelligence reports related to a specific file or process hash on the Hash View.
- [Investigate a user](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-artifacts-and-assets/investigate-a-user.md): Investigate user assets associated with your incidents.
- [Investigate alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts.md): Cortex XDR generates alerts to bring your attention to security risks in your framework.
- [Overview of the Alerts page](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/overview-of-the-alerts-page.md): The Alerts page consolidates all non-informational alerts from your detection sources, and helps you to analyze and triage the alerts on your system.
- [Triage and investigate alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts.md): You can triage, investigate, and take actions on alerts from the Alerts page.
- [Copy alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/copy-alerts.md): You can copy an alert into memory.
- [Analyze an alert](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/analyze-an-alert.md): Learn more about analyzing alerts in the alert side panel and the causality view.
- [Create profile exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/create-profile-exceptions.md): You can create profile exceptions for agent alerts.
- [Add a file path to a malware profile allow list](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/add-a-file-path-to-a-malware-profile-allow-list.md): You can add a file path to an existing malware profile.
- [Create a featured alert field](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/create-a-featured-alert-field.md): You can label specific alert attributes as featured alert fields.
- [View generating BIOC or IOC rule](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/view-generating-bioc-or-ioc-rule.md): You can view the BIOC or IOC rules that generated alerts directly from the Alerts table.
- [Retrieve additional alert details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/retrieve-additional-alert-details.md): Access additional information relating to an alert, including related files and memory content analysis.
- [Alert deduplication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/alert-deduplication.md): Learn about how Cortex XDR deduplicates alerts
- [Export alert details to a file](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/export-alert-details-to-a-file.md): You can review alert details offline by exporting alerts to a TSV file.
- [Exclude an alert](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/exclude-an-alert.md): You can exclude alerts that are not deemed to be a threat.
- [Investigate contributing events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/investigate-contributing-events.md): You can investigate the events created by an alert.
- [Query incident and alert data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/query-incident-and-alert-data.md): You can run queries on incident and alert data with the incidents and alerts datasets.
- [Manage automation rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/triage-and-investigate-alerts/manage-automation-rules.md): Procedure of how to manage the automation rules of Cortex XDR as needed, which includes to edit, save as new, disable, delete or copy.
- [Alert investigation views](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views.md): From the Alerts page, you can pivot on an alert to open the alert investigation views.
- [Alert side panel](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/alert-side-panel.md): The alert side panel provides detailed information about alerts at a glance and in the context of the incident.
- [Causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/causality-view.md): See the causality of an alert—the entire process execution chain that led up to the alert in the Cortex XDR app.
- [Network causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/network-causality-view.md): The network causality view shows a chain of individual network processes that together and in a particular sequence of operation triggered an alert.
- [Cloud causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/cloud-causality-view.md): See the causality of a cloud-type alert—the entire process execution chain that led up to the alert in the Cortex XDR app.
- [SaaS causality view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/saas-causality-view.md): Learn more about the SaaS causality view used to identify and investigate SaaS-specific data associated with SaaS-related alerts and SaaS audit logs.
- [Analytics alert view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/analytics-alert-view.md): From the Cortex XDR management console, you can view a detailed summary of the behavior that triggered analytics alerts.
- [Timeline](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-alerts/alert-investigation-views/timeline.md): From the Cortex XDR tenant you can view the sequence (or timeline) of events and alerts that are involved in any particular threat.
- [Investigate endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints.md): You can investigate and take actions on your endpoints in the Action Center.
- [Overview of the Action Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/overview-of-the-action-center.md): From the Action Center, you can track the progress of all investigation, response, and maintenance actions performed on your endpoints.
- [Initiate and monitor endpoint actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/overview-of-the-action-center/initiate-and-monitor-endpoint-actions.md): Take these steps to initiate and monitor actions on your endpoints.
- [Action Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/overview-of-the-action-center/action-center-reference-information.md): See descriptions of the fields in the Action Center.
- [Manage endpoints](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/manage-endpoints.md): You can view and take actions on endpoints on the All Endpoints page.
- [Retrieve files from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/retrieve-files-from-an-endpoint.md): You can retrieve files from one or more endpoints by initiating a files retrieval request.
- [Retrieve support logs from an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/retrieve-support-logs-from-an-endpoint.md): Retrieve support logs from an endpoint when additional forensic data is needed.
- [Retrieve support file password](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/retrieve-support-file-password.md): Learn how to retrieve the password to access files from the Tech Support File (TSF), which is generated in a zip format protected by an encrypted password.
- [Scan an endpoint for malware](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-endpoints/scan-an-endpoint-for-malware.md): The agent can scan your Windows and Mac endpoints and attached removable drives for dormant malware that is not actively attempting to run.
- [Investigate files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files.md)
- [Manage file execution](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files/manage-file-execution.md): Set rules for the execution (or running) of particular files on your endpoints in Cortex XDR.
- [Manage quarantined files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files/manage-quarantined-files.md): You can review and manage all files that have been quarantined by the agent due to a security incident.
- [Review WildFire analysis details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files/review-wildfire-analysis-details.md): For each file, Cortex XDR receives a file verdict and the WildFire Analysis Report detailing additional information you can use to assess the nature of a file.
- [Import file hash exceptions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/investigate-files/import-file-hash-exceptions.md): You can import file hash exceptions from the Endpoint Security Manager or from external feeds.
- [Response actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions.md): As a result of an incident investigation, different response actions are possible.
- [Initiate a Live Terminal session](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/initiate-a-live-terminal-session.md): Initiate a Live Terminal session from the Cortex XDR management console to control the endpoint remotely.
- [Isolate an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/isolate-an-endpoint.md): In the event that an endpoint is compromised, you can immediately isolate it to reduce an attacker’s mobility.
- [Pause endpoint protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/pause-endpoint-protection.md): Disable the Cortex XDR agent protection capabilities on an endpoint.
- [Remediate changes from malicious activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/remediate-changes-from-malicious-activity.md): You can obtain action remediation suggestions from Cortex XDR about malicious causality chains that have been detected.
- [Run scripts on an endpoint](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/run-scripts-on-an-endpoint.md): Execute Python scripts from Cortex XDR directly on the endpoint to perform actions, retrieve data, and retrieve files.
- [Search and destroy malicious files](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/search-and-destroy-malicious-files.md): Cortex XDR enables you to effectively hunt down any identified malicious file that may exist on any of your endpoints.
- [Manage external dynamic lists](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/manage-external-dynamic-lists.md): Configure and manage your external dynamic lists in Cortex XDR.
- [Collect a memory image](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/response-actions/collect-a-memory-image.md): Collect a memory image from a Windows endpoint.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, incident expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md): Learn more about some important information before getting started with XQL queries.
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md): Learn about useful XQL query features in the user interface.
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md): Learn about best practices for streamlining XQL queries.
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md): Learn what to expect in the query results when querying fields.
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/create-xql-query.md): Learn how to create queries using the Cortex Query Language (XQL).
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md): Learn more about reviewing the results returned from an XQL query.
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md): Learn how to translate your Splunk queries to XQL queries in Cortex XDR.
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/how-to-build-xql-queries/graph-query-results.md): Cortex XDR enables you to generate helpful visualizations of your XQL query results.
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities.md): Learn more about the Cortex Query Language (XQL) entities available in the Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-authentication-query.md): Learn more about creating a query to investigate any authentication activity.
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-event-log-query.md): Learn more about creating a query to investigate Windows and Linux event log attributes and investigate event logs across endpoints.
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-file-query.md): Learn more about creating a query to investigate the connections between file activity and endpoints.
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-image-load-query.md): Learn more about create a query to investigate the connections between image load activity, acting processes, and endpoints.
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-network-connections-query.md): Learn more about creating a query to investigate the connections between firewall logs, endpoints, and network activity.
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-network-query.md): Learn more about creating a query to investigate the connections between network activity, acting processes, and endpoints.
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-process-query.md): Learn more about creating a query to investigate connections between processes, child processes, and endpoints.
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/create-registry-query.md): Learn more about creating a query to investigate connections between registry activity, processes, and endpoints.
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/xql-query-entities/query-across-all-entities.md): From the Cortex XDR management console, you can search for endpoints and processes across all endpoint activity.
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and rerun queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/overview-of-the-query-center/edit-and-rerun-queries-in-query-center.md): Learn more about viewing the results of a query, modifying a query, and rerunning queries from Query Center.
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/overview-of-the-query-center/edit-and-rerun-queries-in-query-center/query-center-reference-information.md): Descriptions of the fields in the Query Center table.
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md): Descriptions of the fields in the Scheduled Queries table.
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/build-xql-queries/manage-your-personal-query-library.md): Cortex XDR provides as part of the Query Library a personal library for saving and managing your own queries.
- [Dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards.md): Cortex XDR dashboards help you to monitor system activity in your environment. You can use any of the predefined dashboards that are provided in Cortex XDR, or you can create your own custom dashboard
- [About dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/about-dashboards.md): Dashboards help you to monitor system activity in your environment. Select a dashboard from the drop-down menu, or take actions on your dashboards from the Dashboard Manager.
- [Predefined dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/predefined-dashboards.md): Predefined dashboards are set up to help you monitor different aspects of your environment.
- [Custom dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards.md): Custom dashboards can support your day-to-day operations by providing options that are tailored to your unique workflow.
- [Build a custom dashboard](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/build-a-custom-dashboard.md): Build customized dashboards to display and filter the information that is most relevant to you.
- [Manage your Widget Library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/manage-your-widget-library.md): Create, search, and view custom widgets in Cortex XDR, or use predefined widgets.
- [Create a text widget](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/create-a-text-widget.md): Create a text-based widget to present information in a dashboard or report. Markdown is supported for formatting.
- [Create custom XQL widgets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/create-custom-xql-widgets.md): You can create custom XQL widgets based on a Cortex Query Language (XQL) query, and add parameters that you can configure as fixed filters or dashboard drilldowns.
- [Configure fixed dashboard filters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/configure-fixed-dashboard-filters.md): Configure fixed filters that enable dashboard users to alter the scope of the dashboard by selecting predefined and dynamic values.
- [Configure dashboard drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/configure-dashboard-drilldowns.md): Configure drilldowns on custom dashboards to provide users with interactive data insights when clicking on data points in a widget
- [Variables in drilldowns](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/custom-dashboards/configure-dashboard-drilldowns/variables-in-drilldowns.md): Learn about the widget variable values that you can use in dashboard drilldowns.
- [Reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/reports.md): Create, edit, and customize reports in Cortex XDR. Schedule reports with Cron expressions.
- [Report templates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/reports/report-templates.md): View, import, export, create, and modify report templates
- [Run or schedule reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/dashboards/reports/run-or-schedule-reports.md): You can run reports that are based on dashboard templates, or you can create reports from scratch.
- [Quick Launcher](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/quick-launcher.md): The Quick Launcher provides a quick, in-context shortcut that you can use to search for information, perform common investigation tasks, or initiate actions.
- [Research a known threat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/investigate-and-respond-to-incidents/research-a-known-threat.md): Cortex XDR enables you to investigate any threat, also referred to as a lead, which has been detected.
- [Data management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management.md)
- [Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm.md): Set up a Broker VM to establish a secure connection in which you can route your endpoints, and collect and forward logs and files for analysis.
- [What is the Broker VM?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/what-is-the-broker-vm.md): Learn about the Cortex XDR Broker virtual machine (VM) and why use it in your network configuration.
- [Set up and configure Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm.md): Learn more about how to set up and configure a Broker VM as a standalone broker or add the broker to a high availability (HA) cluster.
- [Broker VM image installations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations.md): Learn more about the Broker VM image types available that are compatible with your viirtual machine (VM).
- [Set up Broker VM on Alibaba Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-alibaba-cloud.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on Alibaba Cloud.
- [Set up Broker VM on Amazon Web Services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-amazon-web-services.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on AWS.
- [Set up Broker VM on Google Cloud Platform (GCP)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-google-cloud-platform-gcp.md): Learn more about how to set up your Cortex XDR Broker VM on Google Cloud Platform.
- [Set up Broker VM on KVM using Ubuntu](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-kvm-using-ubuntu.md): Learn set up your Cortex XDR Broker virtual machine (VM) on a KVM using Ubuntu.
- [Set up Broker VM on Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-azure.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on Microsoft Azure.
- [Set up Broker VM on Microsoft Hyper-V](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-microsoft-hyper-v.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on Microsoft Hyper-V.
- [Set up Broker VM on Nutanix Hypervisor](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-nutanix-hypervisor.md): Learn how to set up your Cortex XDR Broker virtual machine (VM) on Nutanix Hypervisor.
- [Set up Broker VM on VMware ESXi using vSphere Client](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-image-installations/set-up-broker-vm-on-vmware-esxi-using-vsphere-client.md): Learn more about how to set up you Cortex XDR Broker VM on VMware ESXi.
- [Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets.md): Learn more about the different Broker VM data collector applets available to configure.
- [Activate Apache Kafka Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-apache-kafka-collector.md): Learn more about activating the Broker VM with an Apache Kafka Collector applet.
- [Activate CSV Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-csv-collector.md): Learn more about activating the Broker VM with a CSV Collector applet.
- [Activate Database Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-database-collector.md): Learn more about activating a Broker VM with a Database Collector applet.
- [Activate Files and Folders Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-files-and-folders-collector.md): Learn more about activating a Broker VM with a Files and Folders Collector applet.
- [Activate FTP Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-ftp-collector.md): Learn more about activating a Broker VM with a FTP Collector applet.
- [Activate Local Agent Settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-local-agent-settings.md): Learn more about activating a Local Agent Settings applet on a Broker VM.
- [Activate NetFlow Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-netflow-collector.md): Learn more about activating a Broker VM with a NetflFlow Collector applet.
- [Activate Network Mapper](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-network-mapper.md): Learn more about activating the Network Mapper to scan your network.
- [Activate Syslog Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-syslog-collector.md): Learn how to set up and activate the Syslog Collector applet on a Broker VM within your network.
- [Activate Windows Event Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-windows-event-collector.md): Set up your Windows Event Collector to connect with the Cortex XDR Broker VM and collect events.
- [Activate Windows Event Collector on Windows Core](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-windows-event-collector/activate-windows-event-collector-on-windows-core.md): Learn more about activating the Windrows Event Collector on Windows Core OS to connect with the Broker VM.
- [Renew WEC certificates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/set-up-and-configure-broker-vm/broker-vm-data-collector-applets/activate-windows-event-collector/renew-wec-certificates.md): Learn more about renewing your WEC certificates in Cortex XDR.
- [Manage Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm.md): Learn more about managing your Broker VMs from the management console.
- [Edit Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/edit-broker-vm-configuration.md): Learn more about editing the configuration of a Broker VM.
- [Increase Broker VM storage allocated for data caching](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/increase-broker-vm-storage-allocated-for-data-caching.md): Learn more about increasing the storage allocated for data caching in the Broker VM.
- [Monitor Broker VM using Prometheus](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/monitor-broker-vm-using-prometheus.md): Learn more on monitoring the Broker VM using Prometheus.
- [Collect Broker VM Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/collect-broker-vm-logs.md): Learn more about collecting logs from a Broker VM to review them as part of an investigation.
- [Upgrade Broker VM](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/upgrade-broker-vm.md): Learn more about upgrading the Broker VM from the Cortex XDR management console.
- [Update Broker VM applets independently](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/update-broker-vm-applets-independently.md)
- [Import Broker VM Configuration](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/import-broker-vm-configuration.md): Learn more about importing one Broker VM configuration to another.
- [Open Live Terminal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/open-live-terminal.md): Learn more about remotely connecting to a Cortex XDR Broker VM.
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/add-broker-vm-to-cluster.md): Learn more about adding a Broker VM to a high availability cluster.
- [Switchover Primary Node in Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/switchover-primary-node-in-cluster.md): Learning more about changing the role of the current Primary node in a HA cluster.
- [Remove from Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm/remove-from-cluster.md): Learn more about removing a Broker VM node from a high availability cluster.
- [Broker VM High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster.md): Learn more about creating Broker VMs in a High Availability cluster
- [Configure High Availability Cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/configure-high-availability-cluster.md): Learn how to configure a High Availablity Cluster.
- [Manage Broker VM clusters](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters.md): Learn more about managing your broker VM clusters from the Clusters tab of the Broker VMs page.
- [View cluster details](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/view-cluster-details.md): Learn more about viewing the details of any particular cluster.
- [Edit cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/edit-cluster.md): Learn how to edit a High Availability cluster.
- [Add applet to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-applet-to-cluster.md): Learn more about adding an applet to a High Availability cluster.
- [Add Broker VM to cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/add-broker-vm-to-cluster.md): Learn more about adding a Broker VM to a high availability cluster.
- [Remove cluster](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-high-availability-cluster/manage-broker-vm-clusters/remove-cluster.md): Learn more about removing a high availability cluster.
- [Manage Broker VM data collector applets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/manage-broker-vm-data-collector-applets.md): Learn more about managing your Broker VM data collector applets from the Broker VMs page.
- [Broker VM notifications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/broker-vm-notifications.md): Learn about the notifications that are relevant to Cortex XDR Broker VMs.
- [Monitor Broker VM activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/monitor-broker-vm-activity.md): Learn more about the monitored Cortex XDR Broker VM activities.
- [Troubleshoot Broker VM applet errors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/broker-vm/troubleshoot-broker-vm-applet-errors.md): Learn more about how to verify the Broker VM applet application, connectivity, and processing errors and troubleshoot.
- [XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors.md): Learn how XDR Collectors can be used for on-premise data collection on Windows and Linux machines.
- [XDR Collector audit logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/xdr-collector-audit-logs.md): Learn more about XDR Collector audit logs.
- [XDR Collector machine requirements and supported operating systems](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/xdr-collector-machine-requirements-and-supported-operating-systems.md): Learn about the supported operating systems and requirements for the collector machines used for the Cortex XDR Collectors.
- [Resources required to enable access to XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/resources-required-to-enable-access-to-xdr-collectors.md): Depending on your network environment settings, you should enable network access to the Cortex XDR Collectors resources.
- [Manage XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors.md): Manage Cortex XDR collectors.
- [Configure the XDR Collector upgrade scheduler](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/configure-the-xdr-collector-upgrade-scheduler.md): You can configure the Cortex XDR Collector upgrade scheduler and the number of parallel upgrades.
- [Create an XDR Collector installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/create-an-xdr-collector-installation-package.md): Learn how to create an XDR Collector installation package for a Windows or Linux collector machine.
- [Install the XDR Collector installation package for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows.md): Learn about the Cortex XDR Collector installation options on Windows collector machines.
- [Install the XDR Collector on Windows using the MSI](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-the-msi.md): Learn how to install the Cortex XDR Collector on Windows using the MSI.
- [Install the XDR Collector on Windows using Msiexec](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-windows/install-the-xdr-collector-on-windows-using-msiexec.md): Learn how to install the Cortex XDR Collectors on Windows using the Msiexec.
- [Install the XDR Collector installation package for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/install-the-xdr-collector-installation-package-for-linux.md): Learn how to install the Cortex XDR Collector on Linux collector machines.
- [XDR Collectors installation resource for Windows and Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/xdr-collectors-installation-resource-for-windows-and-linux.md): Cortex XDR Collectors installation resource for Windows and Linux.
- [Set an application proxy for XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/set-an-application-proxy-for-xdr-collectors.md): You can set an application-specific proxy for a Cortex XDR Collector without affecting the communication of other applications on the collector machine.
- [Upgrade XDR Collectors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/upgrade-xdr-collectors.md): You can upgrade the Cortex XDR Collector software by using the appropriate method for the collector machine operating system.
- [Uninstall the XDR Collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/uninstall-the-xdr-collector.md): You can uninstall the Cortex XDR Collector from one or more Windows or Linux collector machines at any time.
- [Set an alias for an XDR Collector machine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/manage-xdr-collectors/set-an-alias-for-an-xdr-collector-machine.md): Configure an alias to identify one or more collector machines by a name that is different from the collector machine hostname.
- [Define XDR Collector machine groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/define-xdr-collector-machine-groups.md): To easily apply policy rules and manage specific collector machines, you can define a collector machine group.
- [About Cortex XDR Collector content updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/about-cortex-xdr-collector-content-updates.md): To quickly resolve any issues in policy, Palo Alto Networks can seamlessly deliver software packages called content updates.
- [XDR Collector profiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/xdr-collector-profiles.md): Add an XDR collector profile to define the type of data to collect from a Linux or Windows platform.
- [Add an XDR Collector Profile for Windows](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-windows.md): Add a Cortex XDR Collector profile, which defines the data that is collected from a Windows collector machine, and defines automatic XDR Collector upgrade settings.
- [Ingest Logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-windows/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md): Learn how to configure Cortex XDR to receive Windows DHCP logs.
- [Ingest Windows DNS debug logs using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-windows/ingest-windows-dns-debug-logs-using-elasticsearch-filebeat.md): Extend Cortex XDR visibility into Windows DNS Debug logs using Elasticsearch Filebeat with an XDR Collectors profile.
- [Query Windows Event Log records](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-windows/query-windows-event-log-records.md)
- [Add an XDR Collector profile for Linux](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/add-an-xdr-collector-profile-for-linux.md): Add a Cortex XDR Collector profile, which defines the data that is collected from a Linux collector machine, and defines automatic XDR Collector upgrade settings.
- [Apply profiles to collection machine policies](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/apply-profiles-to-collection-machine-policies.md): Enable a Cortex XDR Collector profile by mapping it to a policy.
- [XDR Collector datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/xdr-collectors/xdr-collector-datasets.md): After Cortex XDR begins receiving data from your XDR Collectors configuration, the app automatically creates an XQL dataset.
- [Data Ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion.md): Data can be ingested both from Palo Alto Networks products, and from third-party vendor products.
- [Visibility of logs and alerts from external sources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/visibility-of-logs-and-alerts-from-external-sources.md): Cortex XDR provides visibility into your external logs. The availability of logs and alerts varies by the data source.
- [Visibility of Cortex XDR audit and authentication logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/visibility-of-cortex-xdr-audit-and-authentication-logs.md): Monitor Cortex XDR authentication and audit logs for detecting attacks on Cortex XDR.
- [External data ingestion vendor support](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion-vendor-support.md): To augment your Cortex XDR data, you can set up Cortex XDR to ingest data from a variety of external third-party sources.
- [Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations.md): Cortex XDR supports Palo Alto Networks data ingestion.
- [About Palo Alto Networks integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/about-palo-alto-networks-integrations.md): Stream data directly from other Palo Alto Networks products to Cortex XDR.
- [Ingest data from Next-Generation Firewall](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-data-from-next-generation-firewall.md): Learn how to ingest detection data from Next-Generation Firewall and Panorama.
- [Ingest Next-Generation Firewall logs using the Syslog collector](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-data-from-next-generation-firewall/ingest-next-generation-firewall-logs-using-the-syslog-collector.md): Use the Syslog collector to ingest NGFW logs in CEF format. This method is useful when your firewalls are located in a different region, or bandwidth issues are encountered due to large log size.
- [Ingest data from Prisma Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-data-from-prisma-access.md): Learn how to ingest detection data from Prisma Access.
- [Ingest logs from Prisma Access Browser](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-logs-from-prisma-access-browser.md): Ingest Prisma Browser logs into Cortex XDR.
- [Ingest Alerts from Prisma Cloud Compute](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-alerts-from-prisma-cloud-compute.md): Configure Data Collection Settings to receive alerts from Prisma Cloud Compute.
- [Ingest Alerts from Prisma Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-alerts-from-prisma-cloud.md): Configure Data Collection Settings in Cortex XDR to receive alerts from Prisma Cloud.
- [Ingest detection data from Strata Logging Service](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-detection-data-from-strata-logging-service.md): Learn how to ingest detection data from Strata Logging Service.
- [Ingest Alerts and Assets from PAN IoT Security (Deprecated)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-alerts-and-assets-from-pan-iot-security.md): Ingest alerts and device data from IoT Security.
- [Ingest alerts and assets from Device Security](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/ingest-alerts-and-assets-from-device-security.md)
- [Collecting URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/collecting-url-and-file-log-types.md): Learn about the implications of turning off or on collection of URL and File logs.
- [Detectors connected to URL and File log types](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/palo-alto-networks-integrations/collecting-url-and-file-log-types/detectors-connected-to-url-and-file-log-types.md): A list of detectors connected to URL and File log types.
- [External data ingestion](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion.md): Cortex XDR supports external data ingestion for a variety of service types and vendors.
- [External applications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/external-applications.md): Learn more about integrating Slack and a Syslog Receiver to Cortex XDR.
- [Ingest network connection logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs.md): Cortex XDR can ingest network connection logs from different third-party sources.
- [Ingest network flow logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-flow-logs-from-amazon-s3.md): Take advantage of Cortex XDR investigation capabilities and set up network flow log ingestion for your Amazon S3 logs using an AWS CloudFormation Script.
- [Create an assumed role](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-flow-logs-from-amazon-s3/create-an-assumed-role.md): Learn about creating an AWS Assumed Role for Cortex XDR.
- [Configure data collection from Amazon S3 manually](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-flow-logs-from-amazon-s3/configure-data-collection-from-amazon-s3-manually.md): Set up network flow log ingestion for your Amazon S3 logs manually (without a script).
- [Ingest Network Route 53 Logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-route-53-logs-from-amazon-s3.md): Take advantage of Cortex XDR investigation capabilities and set up network Route 53 ingestion for your Amazon S3 logs using an AWS CloudFormation Script.
- [Ingest logs from Check Point firewalls](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-check-point-firewalls.md): To take advantage of Cortex XDR investigation and detection capabilities while using Check Point firewalls, forward your firewall logs to Cortex XDR.
- [Ingest logs from Cisco ASA firewalls and AnyConnect](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-cisco-asa-firewalls-and-anyconnect.md): Extend Cortex XDR visibility into logs from Cisco ASA firewalls and Cisco AnyConnect VPN.
- [Ingest logs from Corelight Zeek](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-corelight-zeek.md): Extend Cortex XDR visibility into logs from Corelight Zeek.
- [Ingest logs from Fortinet Fortigate firewalls](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-fortinet-fortigate-firewalls.md): Extend Cortex XDR visibility into logs from Fortinet Fortigate firewalls.
- [Ingest Logs and Data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-and-data-from-a-gcp-pubsub.md): If you use the Pub/Sub messaging service from Global Cloud Platform (GCP), you can send logs and data from GCP to Cortex XDR.
- [Ingest Logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-microsoft-azure-event-hub.md): Ingest logs from Microsoft Azure Event Hub with an option to ingest audit logs to use in Cortex XDR authentication stories.
- [Ingest network flow logs from Microsoft Azure Network Watcher](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-network-flow-logs-from-microsoft-azure-network-watcher.md): Ingest network security group (NSG) or Virtual network (VNet) flow logs from Microsoft Azure Network Watcher for use in Cortex XDR network stories.
- [Ingest Logs and Data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-and-data-from-okta.md): Ingest authentication logs and data from Okta for use in Cortex XDR authentication stories.
- [Ingest logs from Windows DHCP using Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-windows-dhcp-using-elasticsearch-filebeat.md): Learn how to configure Cortex XDR to receive Windows DHCP logs.
- [Ingest logs from Zscaler Internet Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-zscaler-internet-access.md): Extend Cortex XDR visibility into logs from Zscaler Internet Access (ZIA).
- [Ingest logs from Zscaler Private Access](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-network-connection-logs/ingest-logs-from-zscaler-private-access.md): Extend Cortex XDR visibility into logs from Zscaler Private Access (ZPA).
- [Ingest authentication logs and data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data.md): Ingest authentication logs from external authentication services—such as Okta and Azure AD—into authentication stories with Cortex XDR.
- [Ingest audit logs from AWS Cloud Trail](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-audit-logs-from-aws-cloud-trail.md): Take advantage of Cortex XDR investigation capabilities and set up audit log ingestion for your AWS CloudTrail logs.
- [Ingest Logs and Data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-a-gcp-pubsub.md): If you use the Pub/Sub messaging service from Global Cloud Platform (GCP), you can send logs and data from GCP to Cortex XDR.
- [Ingest Logs and Data from Google Workspace](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-google-workspace.md): Ingest logs and data from Google Workspace for use in Cortex XDR.
- [Ingest Logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-from-microsoft-azure-event-hub.md): Ingest logs from Microsoft Azure Event Hub with an option to ingest audit logs to use in Cortex XDR authentication stories.
- [Ingest logs and data from Microsoft 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-microsoft-365.md): Learn more about collecting logs and data from Microsoft 365.
- [Ingest Logs from Microsoft Office 365](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-from-microsoft-office-365.md): Ingest logs and data from Microsoft Office 365 Management Activity API and Microsoft Graph API for use in Cortex XDR.
- [Ingest Logs and Data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-okta.md): Ingest authentication logs and data from Okta for use in Cortex XDR authentication stories.
- [Ingest Logs and Data from OneLogin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-logs-and-data-from-onelogin.md): Learn how to ingest different types of logs and data from OneLogin.
- [Ingest authentication logs from PingFederate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-authentication-logs-from-pingfederate.md): Ingest authentication logs and data from PingFederate for use in Cortex XDR authentication stories.
- [Ingest Authentication Logs and Data from PingOne](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-authentication-logs-and-data/ingest-authentication-logs-and-data-from-pingone.md): Ingest authentication logs and data from PingOne for Enterprise for use in Cortex XDR authentication stories.
- [Ingest operation and system logs from cloud providers](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers.md): Learn how to ingest operation and system logs from supported cloud providers into Cortex XDR.
- [Ingest generic logs from Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-generic-logs-from-amazon-s3.md)
- [Ingest logs from Amazon CloudWatch](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-from-amazon-cloudwatch.md): Take advantage of Cortex XDR investigation capabilities and set up generic or EKS log ingestion for your Amazon CloudWatch logs.
- [Ingest Logs and Data from a GCP Pub/Sub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-and-data-from-a-gcp-pubsub.md): If you use the Pub/Sub messaging service from Global Cloud Platform (GCP), you can send logs and data from GCP to Cortex XDR.
- [Ingest logs from Google Kubernetes Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-from-google-kubernetes-engine.md): Forward your Google Kubernetes Engine (GKE) logs directly to Cortex XDR using Elasticsearch Filebeat.
- [Ingest Logs from Microsoft Azure Event Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-from-microsoft-azure-event-hub.md): Ingest logs from Microsoft Azure Event Hub with an option to ingest audit logs to use in Cortex XDR authentication stories.
- [Ingest Logs and Data from Okta](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-operation-and-system-logs-from-cloud-providers/ingest-logs-and-data-from-okta.md): Ingest authentication logs and data from Okta for use in Cortex XDR authentication stories.
- [Ingest endpoint data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-endpoint-data.md): Cortex XDR enables you to ingest endpoint data.
- [Ingest cloud assets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets.md): You can ingest cloud assets from different third-party sources using Cortex XDR.
- [Ingest Cloud Assets from AWS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets/ingest-cloud-assets-from-aws.md): Extend Cortex XDR visibility into cloud assets from AWS.
- [Ingest Cloud Assets from Google Cloud Platform](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets/ingest-cloud-assets-from-google-cloud-platform.md): Extend Cortex XDR visibility into cloud assets from Google Cloud Platform.
- [Ingest Cloud Assets from Microsoft Azure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/ingest-cloud-assets/ingest-cloud-assets-from-microsoft-azure.md): Extend Cortex XDR visibility into cloud assets from Microsoft Azure.
- [Additional log ingestion methods](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods.md): Cortex XDR supports custom log ingestion methods.
- [Ingest logs from a Syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-a-syslog-receiver.md): To extend visibility, Cortex XDR can receive Syslog from additional vendors that use CEF or LEEF formatted over Syslog (TLS not supported).
- [Ingest Apache Kafka events as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-apache-kafka-events-as-datasets.md): Cortex XDR can receive logs and data from Apache Kafka directly to your log repository for query and visualization purposes.
- [Ingest CSV files as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-csv-files-as-datasets.md): Cortex XDR can receive CSV log files from a shared Windows directory, where the CSV log files must conform to specific guidelines.
- [Ingest database data as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-database-data-as-datasets.md): Cortex XDR can receive data from a client relational database directly to your log repository.
- [Ingest logs in a network share as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-in-a-network-share-as-datasets.md): Cortex XDR can receive logs from files and folders in a network share directly to your log repository for query and visualization purposes.
- [Ingest FTP files as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-ftp-files-as-datasets.md): Cortex XDR can receive logs from files and folders via FTP, FTPS, and SFTP directly to your log repository for query and visualization purposes.
- [Ingest NetFlow flow records as datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-netflow-flow-records-as-datasets.md): Cortex XDR can receive NetFlow flow records and IPFIX from a UDP port directly to your log repository for query and visualization purposes.
- [Set up an HTTP Log Collector to Receive Logs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/set-up-an-http-log-collector-to-receive-logs.md): You can set up Cortex XDR to receive logs from third-party sources, and automatically parse and process these logs.
- [Ingest logs from BeyondTrust Privilege Management Cloud](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-beyondtrust-privilege-management-cloud.md): Extend Cortex XDR visibility into logs from BeyondTrust Privilege Management Cloud.
- [Ingest Logs and Data from Box](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-and-data-from-box.md): Ingest logs and data from Box enterprise accounts via the Box REST APIs.
- [Ingest Logs and Data from Dropbox](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-and-data-from-dropbox.md): Ingest logs and data from Dropbox Business accounts via the Dropbox Business API.
- [Ingest Logs from Elasticsearch Filebeat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-elasticsearch-filebeat.md): Cortex XDR can ingest logs from Elasticsearch Filebeat, a file system logger that logs file activity on your endpoints and servers.
- [Ingest logs from Forcepoint DLP](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-forcepoint-dlp.md): Extend Cortex XDR visibility into logs from Forcepoint DLP.
- [Ingest Logs from Proofpoint Targeted Attack Protection](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-from-proofpoint-targeted-attack-protection.md): Ingest logs from Proofpoint Targeted Attack Protection (TAP).
- [Ingest logs and data from Salesforce.com](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-logs-and-data-from-salesforce.com.md): Use the Cortex XDR data collector to collect Audit Trail and Security Monitoring event logs from Salesforce.com.
- [Ingest Data from ServiceNow CMDB](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-data-from-servicenow-cmdb.md): Extend Cortex XDR visibility into data from ServiceNow CMDB.
- [Ingest Report Data from Workday](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-report-data-from-workday.md): Extend Cortex XDR visibility into reports data from Workday.
- [Ingest external alerts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/external-data-ingestion/additional-log-ingestion-methods/ingest-external-alerts.md): For a more complete and detailed picture of the activity involved in an incident, Cortex XDR can ingest alerts from any external source.
- [Overview of data ingestion metrics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/overview-of-data-ingestion-metrics.md): Learn more about the data ingestion health metrics in the metrics\_source dataset and the metrics\_view preset.
- [Creating correlation rules to monitor data ingestion health](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/creating-correlation-rules-to-monitor-data-ingestion-health.md): See examples of correlation rules for monitoring data ingestion health.
- [Measuring data freshness](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/measuring-data-freshness.md): Learn more about the data freshness metrics collected by Cortex XDR.
- [Verifying collector connectivity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/data-ingestion/verifying-collector-connectivity.md): Verify collector connectivity and troubleshoot collector errors.
- [Dataset management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management.md): Learn more about managing your datasets and understanding your overall data storage, period based retention.
- [What are datasets?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/what-are-datasets.md): Learn how to import, delete, and interact with custom or third-party datasets in Cortex XDR.
- [Lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/lookup-datasets.md): Learn more about lookup datasets to correlate data from a data source with events in your environment.
- [Import a lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/lookup-datasets/import-a-lookup-dataset.md): Learn more about importing data from an external file to create or update a lookup dataset in Cortex XDR.
- [Download JSON file of lookup dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/lookup-datasets/download-json-file-of-lookup-dataset.md): Learn more about downloading a lookup dataset as a JSON file.
- [Set time to live for lookup datasets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/lookup-datasets/set-time-to-live-for-lookup-datasets.md): Learn more about setting the time to live (TTL) for lookup datasets in Cortex XDR.
- [Monitor datasets and dataset views activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/dataset-management/monitor-datasets-and-dataset-views-activity.md): Learn more about the monitored Cortex XDR datasets and dataset views activities.
- [Parsing Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules.md): Learn more about Cortex XDR Parsing Rules.
- [What are Parsing Rules?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/what-are-parsing-rules.md): Learn more about what are Parsing Rules and what they are used for.
- [Parsing Rules editor views](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-editor-views.md): Learn about the Parsing Rules editor User Defined Rules, Default Rules, Both, and Simulate views.
- [Parsing Rules file structure and syntax](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax.md): The Parsing Rules file consists of multiple sections of three types, which also represent the custom syntax specific to Parsing Rules.
- [INGEST](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest.md): Understanding how to write an \\\[INGEST\\] section in a Parsing Rules file and the syntax to use.
- [fields stage in INGEST](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/fields-stage-in-ingest.md): Use 'fields' in Cortex XDR Parsing Rules.
- [parse\_cef](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cef.md)
- [parse\_cisco](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_cisco.md): Learn more about the parse\_cisco() parsing rule function that parses a Cisco string to an object.
- [parse\_json](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/ingest/parse_json.md)
- [COLLECT](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/collect.md): Understand how to write a \\\[COLLECT\\] section in a Parsing Rules file, and the syntax to use.
- [CONST](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/const.md): Learn how to write a \\\[CONST\\] section in a Parsing Rules file and the syntax to use.
- [RULE](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-file-structure-and-syntax/rule.md): Understanding how to write a \\\[RULE\\] section in a Parsing Rules file and the syntax to use.
- [Create Parsing Rules](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/create-parsing-rules.md): Cortex XDR includes an editor for creating 3rd party Parsing Rules.
- [Troubleshooting Parsing rules errors](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/troubleshooting-parsing-rules-errors.md): Learn how to easily identify and resolve parsing errors.
- [Parsing Rules Raw Dataset](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/parsing-rules/parsing-rules-raw-dataset.md): Each vendor and product has its own raw dataset with its own default format that can be overridden in an INGEST section.
- [Manage Event Forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/manage-event-forwarding.md): Save your ingested, parsed data in an external location by exporting your event logs to a temporary GCP storage bucket.
- [Endpoints Event Forwarding - included/excluded fields by event type](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/manage-event-forwarding/endpoints-event-forwarding-includedexcluded-fields-by-event-type.md): Learn more about the included/excluded fields by event type for Endpoint Event Forwarding in Cortex XDR.
- [Manage compute units](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/manage-compute-units.md): Learn more about managing and tracking your compute units usage for API and Cold Storage XQL queries.
- [Compute units usage](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/data-management/manage-compute-units/compute-units-usage.md): Learn more about how to compute units (CU) works according to your license and available options after reaching your quota.
- [Cortex XDR XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql.md)
- [Get started with XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql.md): XQL is the Palo Alto Networks Cortex Query Language used in Cortex XDR.
- [XQL language features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/xql-language-features.md): Learn more about the Cortex Query Language features to query for raw network and endpoint data.
- [XQL Language Structure](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/xql-language-structure.md): Learn more about the Cortex Query Language structure when creating a query.
- [Adding comments in queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/xql-language-structure/adding-comments-in-queries.md): Learn more about adding comments in Cortex Query Language queries.
- [Supported operators](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/supported-operators.md): Cortex Query Language supports specific comparison, boolean, and set operators in Cortex XDR.
- [Datasets and presets](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/datasets-and-presets.md): The Cortex Query Language supports built-in datasets, custom datasets, and presets.
- [About examples](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/about-examples.md): Learn more about the Cortex Query Language (XQL) examples provided.
- [JSON functions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/json-functions.md): Learn more about how Cortex XDR treats JSON functions in the Cortex Query Language.
- [How to filter for empty values in the results table](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/how-to-filter-for-empty-values-in-the-results-table.md): Learn how to filter for empty values in the results table in Cortex Query Language.
- [Understanding string manipulation in XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/get-started-with-xql/understanding-string-manipulation-in-xql.md): Learn more about string manipulation in Cortex Query Language (XQL) using double and triple quotes.
- [Build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries.md): Learn more about how to build Cortex Query Language (XQL) queries using the Query Builder.
- [About the Query Builder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/about-the-query-builder.md): The Query Builder facilitates threat detection, incident expansion, and data analytics for suspected threats.
- [How to build XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries.md): Learn more about how to build XQL queries in the Query Builder.
- [Get started with XQL queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/get-started-with-xql-queries.md): Learn more about some important information before getting started with XQL queries.
- [Useful XQL user interface features](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/useful-xql-user-interface-features.md): Learn about useful XQL query features in the user interface.
- [XQL Query best practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/xql-query-best-practices.md): Learn about best practices for streamlining XQL queries.
- [Expected results when querying fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/expected-results-when-querying-fields.md): Learn what to expect in the query results when querying fields.
- [Create XQL query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/create-xql-query.md): Learn how to create queries using the Cortex Query Language (XQL).
- [Review XQL query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/review-xql-query-results.md): Learn more about reviewing the results returned from an XQL query.
- [Translate to XQL](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/translate-to-xql.md): Learn how to translate your Splunk queries to XQL queries in Cortex XDR.
- [Graph query results](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/how-to-build-xql-queries/graph-query-results.md): Cortex XDR enables you to generate helpful visualizations of your XQL query results.
- [XQL query entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities.md): Learn more about the Cortex Query Language (XQL) entities available in the Query Builder.
- [Create authentication query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-authentication-query.md): Learn more about creating a query to investigate any authentication activity.
- [Create event log query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-event-log-query.md): Learn more about creating a query to investigate Windows and Linux event log attributes and investigate event logs across endpoints.
- [Create file query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-file-query.md): Learn more about creating a query to investigate the connections between file activity and endpoints.
- [Create image load query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-image-load-query.md): Learn more about create a query to investigate the connections between image load activity, acting processes, and endpoints.
- [Create network connections query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-network-connections-query.md): Learn more about creating a query to investigate the connections between firewall logs, endpoints, and network activity.
- [Create network query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-network-query.md): Learn more about creating a query to investigate the connections between network activity, acting processes, and endpoints.
- [Create process query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-process-query.md): Learn more about creating a query to investigate connections between processes, child processes, and endpoints.
- [Create registry query](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/create-registry-query.md): Learn more about creating a query to investigate connections between registry activity, processes, and endpoints.
- [Query across all entities](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/xql-query-entities/query-across-all-entities.md): From the Cortex XDR management console, you can search for endpoints and processes across all endpoint activity.
- [Overview of the Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center.md): View information about the In Progress and Completed queries that that were run on the tenant.
- [Edit and rerun queries in Query Center](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center/edit-and-rerun-queries-in-query-center.md): Learn more about viewing the results of a query, modifying a query, and rerunning queries from Query Center.
- [Query Center reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/overview-of-the-query-center/edit-and-rerun-queries-in-query-center/query-center-reference-information.md): Descriptions of the fields in the Query Center table.
- [Manage scheduled queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/manage-scheduled-queries.md): Learn how to manage your scheduled and recurring queries.
- [Scheduled Queries reference information](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/manage-scheduled-queries/scheduled-queries-reference-information.md): Descriptions of the fields in the Scheduled Queries table.
- [Manage your personal query library](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/build-xql-queries/manage-your-personal-query-library.md): Cortex XDR provides as part of the Query Library a personal library for saving and managing your own queries.
- [Stages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages.md): Learn more about the Cortex Query Language supported stages.
- [alter](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/alter.md): Learn more about the Cortex Query Language alter stage.
- [arrayexpand](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/arrayexpand.md): Learn more about the Cortex Query Language arrayexpand stage.
- [bin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/bin.md): Learn more about the Cortex Query Language bin stage to group events by quantity or time span.
- [call](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/call.md): Learn more about the Cortex Query Language call stage to reference a predefined query from the Query Library.
- [comp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/comp.md): Learn more about the Cortex Query Language comp stage that precedes functions calculating statistics.
- [config](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/config.md): Learn more about the Cortex Query Language config stage that configures the query behavior.
- [case\_sensitive](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/config/case_sensitive.md): Learn more about the Cortex Query Language case\_sensitive config stage.
- [timeframe](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/config/timeframe.md): Cortex Query Language timeframe configuration enables performing searches within a specific time frame from the query execution.
- [max\_runtime\_minutes](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/config/max_runtime_minutes.md): Learn more about the Cortex Query Language max\_runtime\_minutes config stage.
- [dedup](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/dedup.md): Learn more about the Cortex Query Language dedup stage that removes duplicate occurrences of field values.
- [fields](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/fields.md): Learn more about the Cortex Query Language fields stage that defines the fields returned in the result set.
- [filter](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/filter.md): Learn more about the Cortex Query Language filter stage that narrows down the displayed results.
- [getrole](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/getrole.md): Learn more about the Cortex Query Language getrole stage that enriches events with specific roles associated with usernames or endpoints.
- [iploc](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/iploc.md): Learn more about the Cortex Query Language iploc stage that associates IPv4 addresses of fields to a list of predefined attributes related to the geolocation.
- [join](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/join.md): Learn more about the Cortex Query Language join stage that combines the results of two queries into a single result set.
- [limit](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/limit.md): Learn more about the Cortex Query Language limit stage that sets the maximum number of records that can be returned in the result set.
- [replacenull](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/replacenull.md): Learn more about the Cortex Query Language replacenull stage that replaces null field values with a text string.
- [sort](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/sort.md): Learn more about the Cortex Query Language sort stage that identifies the sort order for records returned in the result set.
- [Tag](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/tag.md): Learn more about the Cortex Query Language tag stage that adds a single tag or list of tags to the \\\_tag system ﬁeld.
- [target](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/target.md): Learn more about the Cortex Query Language target stage that saves query results to a dataset or lookup dataset.
- [top](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/top.md): Learn more about the Cortex Query Language top stage that returns the approximate count of top elements for a field and percentage of the count results.
- [transaction](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/transaction.md): Learn more about the Cortex Query Language transaction stage used to find transactions based on events that meet certain constraints.
- [union](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/union.md): Learn more about the Cortex Query Language union stage that combines two result sets into a single result set.
- [view](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/view.md): Learn more about the Cortex Query Language view stage that configures the display of the result set.
- [windowcomp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/stages/windowcomp.md): Learn more about the Cortex Query Language windowcomp stage that precedes functions calculating statistics.
- [Functions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions.md): Learn more the functions that can be used with Cortex Query Language (XQL) stages in Cortex XDR.
- [add](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/add.md): Learn more about the Cortex Query Language add() function that adds two integers.
- [approx\_count](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/approx_count.md): Learn more about the Cortex Query Language approx\_count approximate aggregate comp function.
- [approx\_quantiles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/approx_quantiles.md): Learn more about the Cortex Query Language approx\_quantiles approximate aggregate comp function.
- [approx\_top](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/approx_top.md): Learn more about the Cortex Query Language approx\_top approximate aggregate comp function.
- [array\_all](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/array_all.md): Learn more about the Cortex Query Language array\_all() function.
- [array\_any](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/array_any.md): Learn more about the Cortex Query Language array\_any() function.
- [arrayconcat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayconcat.md): Learn more about the Cortex Query Language arrayconcat() function that returns an array containing unique values found in the original array.
- [arraycreate](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraycreate.md): Learn more about the Cortex Query Language arraycreate() function that returns an array based on the given parameters defined for the array elements.
- [arraydistinct](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraydistinct.md): Learn more about the Cortex Query Language arraydistinct() function that returns an array containing unique values found in the original array.
- [arrayfilter](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayfilter.md): Learn more about the Cortex Query Language arrayfilter() function.
- [arrayindex](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayindex.md): Learn more about the Cortex Query Language arrayindex() function that returns the array element contained at the specified index.
- [arrayindexof](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayindexof.md): Learn more about the Cortex Query Language arrayindexof() function that returns the index value of an array.
- [array\_length](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/array_length.md): Learn more about the Cortex Query Language array\_length() function that returns the length of an array.
- [arraymap](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraymap.md): Learn more about the Cortex Query Language arraymap() function that applies a callable function to every element of an array.
- [arraymerge](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraymerge.md): Learn more about the Cortex Query Language arraymerge() function that returns an array created from a merge of the inner json-string arrays.
- [arrayrange](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arrayrange.md): Learn more about the Cortex Query Language arrayrange() function that returns a portion of an array based on specified array indices.
- [arraystring](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/arraystring.md): Learn more about the Cortex Query Language arraystring() function that returns a string from an array, where each array element is joined by a defined delimiter.
- [avg](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/avg.md): Learn more about the Cortex Query Language avg used with both comp and windowcomp stages.
- [coalesce](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/coalesce.md): Learn more about the Cortex Query Language coalesce() function that returns the first value that is not null from a defined list of fields.
- [concat](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/concat.md): Learn more about the Cortex Query Language concat() function joins multiple strings into a single string.
- [convert\_from\_base\_64](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/convert_from_base_64.md): Learn more about the Cortex Query Language convert\_from\_base\_64 function.
- [count](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/count.md): Learn more about the Cortex Query Language count function used with both comp and windowcomp stages.
- [count\_distinct](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/count_distinct.md): Learn more about the Cortex Query Language count\_distinct aggregate comp function that counts the number of unique values found for a field in the result set.
- [current\_time](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/current_time.md): Learn more about the Cortex Query Language current\_time() function that returns the current time as a timestamp.
- [date\_floor](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/date_floor.md): Learn more about the Cortex Query Language date\_floor() function.
- [divide](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/divide.md): Learn more about the Cortex Query Language divide() function that divides two integers.
- [earliest](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/earliest.md): Learn more about the Cortex Query Language earliest aggregate comp function that returns the earliest field value found with the matching criteria.
- [extract\_time](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/extract_time.md): Learn more about the Cortex Query Language extract\_time() function that returns a specified portion of a timestamp.
- [extract\_url\_host](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/extract_url_host.md): Learn more about the Cortex Query Language extract\_url\_host() function.
- [extract\_url\_pub\_suffix](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/extract_url_pub_suffix.md): Learn more about the Cortex Query Language extract\_url\_pub\_suffix() function.
- [extract\_url\_registered\_domain](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/extract_url_registered_domain.md): Learn more about the Cortex Query Language extract\_url\_registered\_domain() function.
- [first](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/first.md): Learn more about the Cortex Query Language first aggregate comp function that returns the first field value found in the dataset with the matching criteria.
- [first\_value](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/first_value.md): Learn more about the Cortex Query Language first\_value() navigation function that is used with a windowcomp stage.
- [floor](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/floor.md): Learn more about the Cortex Query Language floor() function that rounds a field that contains a number down to the nearest whole integer.
- [format\_string](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/format_string.md): Learn more about the Cortex Query Language format\_string() function.
- [format\_timestamp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/format_timestamp.md): Learn more about the Cortex Query Language format\_timestamp() function that returns a string after formatting a timestamp according to a specified string format.
- [if](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/if.md): Learn more about the Cortex Query Language if() function that returns a result after evaluating a condition.
- [incidr](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/incidr.md): Learn more about the Cortex Query Language incidr() function.
- [incidr6](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/incidr6.md): Learn more about the Cortex Query Language incidr6() function.
- [incidrlist](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/incidrlist.md): Learn more about the Cortex Query Language incidrlist() function.
- [int\_to\_ip](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/int_to_ip.md): Learn more about the Cortex Query Language int\_to\_ip() function that safely converts a signed integer representation of an IPv4 address to a string equivalent.
- [ip\_to\_int](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/ip_to_int.md): Learn more about the Cortex Query Language ip\_to\_int() function that safely converts a string representation of an IPv4 address to an integer equivalent.
- [is\_ipv4](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/is_ipv4.md): Learn more about the Cortex Query Language is\_ipv4() function.
- [is\_known\_private\_ipv4](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/is_known_private_ipv4.md): Learn more about the Cortex Query Language is\_known\_private\_ipv4() function.
- [is\_ipv6](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/is_ipv6.md): Learn more about the Cortex Query Language is\_ipv6() function.
- [is\_known\_private\_ipv6](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/is_known_private_ipv6.md): Learn more about the Cortex Query Language is\_known\_private\_ipv6() function.
- [json\_extract](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/json_extract.md): Learn more about the Cortex Query Language json\_extract() function that accepts a string representing a JSON object, and returns a field value from that object.
- [json\_extract\_array](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/json_extract_array.md): Learn more about the Cortex Query Language json\_extract\_array() function that accepts a string representing a JSON array, and returns an XQL-native array.
- [json\_extract\_scalar](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/json_extract_scalar.md): Learn more about the Cortex Query Language json\_extract\_scalar() function.
- [json\_extract\_scalar\_array](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/json_extract_scalar_array.md): Learn more about the Cortex Query Language json\_extract\_scalar\_array() function.
- [lag](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/lag.md): Learn more about the Cortex Query Language lag() navigation function that is used with a windowcomp stage.
- [last](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/last.md): Learn more about the Cortex Query Language last aggregate comp function that returns the last field value found in the dataset with the matching criteria.
- [last\_value](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/last_value.md): Learn more about the Cortex Query Language last\_value() navigation function that is used with a windowcomp stage.
- [latest](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/latest.md): Learn more about the Cortex Query Language latest aggregate comp function that returns the latest field value found with the matching criteria.
- [len](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/len.md): Learn more about the Cortex Query Language len function that returns the number of characters contained in a string.
- [list](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/list.md): Learn more about the Cortex Query Language list aggregate comp function that returns an array for up to 100 values for a field in the result set.
- [lowercase](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/lowercase.md): Learn more about the Cortex Query Language lowercase() function that converts a string field to all lowercase letters.
- [ltrim, rtrim, trim](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/ltrim-rtrim-trim.md): Learn more about the Cortex Query Language ltrim(), rtrim(), and trim() functions that remove trim\_characters from a string.
- [max](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/max.md): Learn more about the Cortex Query Language max function used with both comp and windowcomp stages.
- [median](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/median.md): Learn more about the Cortex Query Language median function used with both comp and windowcomp stages.
- [min](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/min.md): Learn more about the Cortex Query Language min function used with both comp and windowcomp stages.
- [multiply](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/multiply.md): Learn more about the Cortex Query Language multiply() function that multiplies two integers.
- [object\_merge](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/object_merge.md): Learn more about the Cortex Query Language object\_merge() function.
- [object\_create](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/object_create.md): Learn more about the Cortex Query Language object\_create() function.
- [parse\_epoch](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/parse_epoch.md): Learn more about the Cortex Query Language parse\_epoch() function that returns a Unix epoch TIMESTAMP object.
- [parse\_timestamp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/parse_timestamp.md): Learn more about the Cortex Query Language parse\_timestamp() function that returns a TIMESTAMP object.
- [pow](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/pow.md): Learn more about the Cortex Query Language pow() function that returns the value of a number raised to the power of another number.
- [rank](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/rank.md): Learn more about the Cortex Query Language rank() numbering function that is used with a windowcomp stage.
- [regexcapture](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/regexcapture.md): Learn more about the Cortex Query Language regexcapture() function used in Parsing Rules to extract data from fields using regular expression named groups from a given string.
- [regextract](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/regextract.md): Learn more about the Cortex Query Language regextract() function that uses regular expressions to assemble an array of matching substrings from a string.
- [replace](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/replace.md): Learn more about the Cortex Query Language replace() function that performs a substring replacement.
- [replex](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/replex.md): Learn more about the Cortex Query Language replex() function that uses a regular expression to identify and replace substrings.
- [round](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/round.md): Learn more about the Cortex Query Language round() function that returns the input value rounded to the nearest integer.
- [row\_number](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/row_number.md): Learn more about the Cortex Query Language row\_number() numbering function that is used with a windowcomp stage.
- [split](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/split.md): Learn more about the Cortex Query Language split() function that splits a string and returns an array of string parts.
- [stddev\_population](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/stddev_population.md): Learn more about the Cortex Query Language stddev\_population() function used with both comp and windowcomp stages.
- [stddev\_sample](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/stddev_sample.md): Learn more about the Cortex Query Language stddev\_sample() function used with both comp and windowcomp stages.
- [string\_count](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/string_count.md): Learn more about the Cortex Query Language string\_count() function that returns the number of times a substring appears in a string.
- [subtract](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/subtract.md): Learn more about the Cortex Query Language subtract() function that subtracts two integers.
- [sum](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/sum.md): Cortex Query Language sum function used with both comp and windowcomp stages.
- [time\_frame\_end](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/time_frame_end.md): Learn more about the Cortex Query Language time\_frame\_end() function that returns the end time of the time range specified for the query.
- [timestamp\_diff](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/timestamp_diff.md): Learn more about the Cortex Query Language timestamp\_diff() function that returns the difference between two timestamp objects.
- [timestamp\_seconds](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/timestamp_seconds.md): Learn more about the Cortex Query Language timestamp\_seconds() function.
- [to\_boolean](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_boolean.md): Learn more about the Cortex Query Language to\_boolean() function that converts a string to a boolean.
- [to\_epoch](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_epoch.md): Learn more about the Cortex Query Language to\_epoch() function that converts a timestamp value for a field or function to the Unix epoch timestamp format.
- [to\_float](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_float.md): Learn more about the Cortex Query Language to\_float() function that converts a string to a floating point number.
- [to\_integer](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_integer.md): Learn more about the Cortex Query Language to\_integer() function that converts a string field to an integer.
- [to\_json\_string](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_json_string.md): Learn more about the Cortex Query Language to\_json\_string() function that accepts all data types and returns its contents as a JSON formatted string.
- [to\_number](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_number.md): Learn more about the Cortex Query Language to\_number() function that converts a string to a number.
- [to\_string](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_string.md): Learn more about the Cortex Query Language to\_string function that converts a number value to a string.
- [to\_timestamp](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/to_timestamp.md): Learn more about the Cortex Query Language to\_timestamp() function that converts an integer to a timestamp.
- [uppercase](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/uppercase.md): Learn more about the Cortex Query Language uppercase() function that converts a string field to all uppercase letters.
- [values](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/values.md): Cortex Query Language comp values aggregate returns an array for all the values seen for the field in the result set.
- [var](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/cortex-xdr-xql/functions/var.md): Learn more about the Cortex Query Language var aggregate comp function that returns the variance value of a field in the result set.
- [Multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant.md)
- [What is Cortex XDR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/what-is-cortex-xdr-multi-tenant.md): Learn about Cortex multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a single console.
- [MSSP multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/what-is-cortex-xdr-multi-tenant/mssp-multi-tenant.md): MSSP multi-tenancy allows managed security service providers to ensure strict data segregation along with the flexibility to monitor alerts across tenants and dynamically allocate licenses.
- [Enterprise multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/what-is-cortex-xdr-multi-tenant/enterprise-multi-tenant.md)
- [Multi-tenant central licensing management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/multi-tenant-central-licensing-management.md)
- [Onboard Cortex multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant.md): Learn how to activate and manage tenants.
- [Onboarding checklist for multi-tenant central licensing deployments](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments.md): Onboard MSSP/Enterprise multi-tenant central licensing deployments.
- [Step 1. Activate Cortex XDR (main account)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments/step-1.-activate-cortex-xdr-main-account.md): Learn how to activate Cortex XDR in Cortex Gateway.
- [Step 2. Create a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-central-licensing-deployments/step-2.-create-a-child-tenant.md): Create child tenants in the Cortex Gateway.
- [Onboarding checklist for multi-tenant customer-owned license deployments](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments.md): Onboard MSSP/Enterprise multi-tenant customer-owned license deployments.
- [Step 1. Activate Cortex Cortex XDR (parent and child tenants)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-1.-activate-cortex-cortex-xdr-parent-and-child-tenants.md): Learn how to activate Cortex XDR from Cortex Gateway.
- [Step 2. Define access configurations and role permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-2.-define-access-configurations-and-role-permissions.md): Define the correct access configuration and role permissions for multi-tenant customer-owned license deployment.
- [Step 3. Pair a parent tenant with child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/onboard-cortex-multi-tenant/onboarding-checklist-for-multi-tenant-customer-owned-license-deployments/step-3.-pair-a-parent-tenant-with-child-tenant.md): In multi-tenant customer-owned license deployments, you must manually pair the parent tenant with each child tenant.
- [Dynamic license allocation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/dynamic-license-allocation.md): In a multi-tenant central licensing management environment, you can dynamically edit child tenant allocations, add child tenants, and delete child tenants with the license pool automatically updated.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management.md): Track, manage, and investigate child tenant data from the parent tenant.
- [Manage a child tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/manage-a-child-tenant.md): From the Cortex XDR management console you can view and investigate child tenant data and initiate security actions.
- [Track your tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/track-your-tenant-management.md): You can view the details of your tenants at any time.
- [Investigate child tenant data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/investigate-child-tenant-data.md): In multi-tenant environments, you can view, track, and investigate data across your Cortex XDR child tenants.
- [Create and allocate configurations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/create-and-allocate-configurations.md): From the Cortex XDR management console, you can create and allocate configurations for child tenants.
- [Create a security managed action](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/child-tenant-management/create-a-security-managed-action.md): Create a security type action to perform on behalf of your child tenants.
- [About managed threat hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/about-managed-threat-hunting.md): Understand how Managed Threat Hunting can help your organization.
- [Set up Managed Threat Hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/about-managed-threat-hunting/set-up-managed-threat-hunting.md): Get started with the Managed Threat Hunting service, an add-on security service provided with Cortex XDR.
- [Investigate Managed Threat Hunting reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/multi-tenant/about-managed-threat-hunting/investigate-managed-threat-hunting-reports.md): Investigate your Managed Threat Hunting reports.
- [Reference](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference.md)
- [RBAC permissions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions.md): Learn more about the RBAC permissions specifically about role permissions by component and the default Palo Alto Networks roles.
- [Role permissions by components](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/role-permissions-by-components.md): Learn how to manage role permissions in Cortex XDR.
- [Default PANW roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles.md): Learn more about the default Palo Alto Networks user roles included in Cortex XDR.
- [Account Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/account-admin.md): Learn more about the Cortex XDR predefined user role called Account Admin.
- [Deployment Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/deployment-admin.md): Learn more about the Cortex XDR predefined user role called Deployment Admin.
- [Instance Administrator](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/instance-administrator.md): Learn more about the Cortex XDR predefined user role called Instance Administrator.
- [Investigation Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/investigation-admin.md): Learn more about the Cortex XDR predefined user role called Investigation Admin.
- [Investigator](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/investigator.md): Learn more about the Cortex XDR predefined user role called Investigator.
- [IT Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/it-admin.md): Learn more about the Cortex XDR predefined user role called IT Admin.
- [Privileged Investigator](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/privileged-investigator.md): Learn more about the Cortex XDR predefined user role called Privileged Investigator.
- [Privileged IT Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/privileged-it-admin.md): Learn more about the Cortex XDR predefined user role called Privileged IT Admin.
- [Privileged Responder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/privileged-responder.md): Learn more about the Cortex XDR predefined user role called Privileged Responder.
- [Privileged Security Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/privileged-security-admin.md): Learn more about the predefined user role called Privileged Security Admin.
- [Responder](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/responder.md): Learn more about the Cortex XDR predefined user role called Responder.
- [Scoped Endpoint Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/scoped-endpoint-admin.md): Learn more about the Cortex XDR predefined user role called Scoped Endpoint Admin.
- [Security Admin](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/security-admin.md): Learn more about the Cortex XDR predefined user role called Security Admin.
- [Viewer](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/rbac-permissions/default-panw-roles/viewer.md): Learn more about the Cortex XDR predefined user role called Viewer.
- [Microsoft Windows security auditing setup](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup.md)
- [Enable security auditing event IDs](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids.md)
- [Enable security auditing event IDs with GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/enable-security-auditing-event-ids-with-gpo.md)
- [Set up local machine security auditing without GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/set-up-local-machine-security-auditing-without-gpo.md)
- [Additional setup for Active Directory Certificate Services (ADCS) events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/additional-setup-for-active-directory-certificate-services-adcs-events.md)
- [Enable auditing access to AD domain objects - 4662](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-security-auditing-event-ids/enable-auditing-access-to-ad-domain-objects-4662.md)
- [Enable additional event logs using Event Viewer](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-additional-event-logs-using-event-viewer.md)
- [Enable LDAP server events logging (1644)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644.md)
- [Enable LDAP server events logging using RegEdit](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/enable-ldap-server-events-logging-using-regedit.md)
- [Enable LDAP server events logging using GPO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/enable-ldap-server-events-logging-using-gpo.md)
- [Validate log collection for LDAP Server events](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/microsoft-windows-security-auditing-setup/enable-ldap-server-events-logging-1644/validate-log-collection-for-ldap-server-events.md)
- [Cortex secure deployment practices](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/reference/cortex-secure-deployment-practices.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
