For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Enable the Analytics Engine and Identity Analytics

Cortex XDR - Analytics includes the following:

  • Cortex XDR Analytics Engine: Analyzes your endpoint data to develop a baseline and raise Analytics and Analytics BIOC alerts when anomalies and malicious behaviors are detected.

  • Identity Analytics: Allows the Cortex XDR - Analytics engine to aggregate and display user profile details, activities, and alerts related to a user-based Analytics type alert and Analytics BIOC rule during an investigation.

Prerequisite

How to enable analytics

  1. Select SettingsConfigurationsCortex XDR - Analytics.

  2. Click Enable. Creating a baseline can take up to three hours.

    Adding Windows DHCP logs can enhance the Analytics Engine. For more information, see Ingest Windows DHCP Logs with an XDR Collector Profile.

  3. Activate Identity Analytics by turning on the toggle.

Last updated

Was this helpful?