> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/use-the-interface.md).

# Use the interface

Cortex XDR provides an easy-to-use interface. Here you can learn more about the user interface, shortcuts and useful tips. For a more detailed product tour, [see here](https://www.paloaltonetworks.com/resources/infographics/xsiam-product-tour).

{% hint style="info" %}

### Note

Each SAML login session is valid for 8 hours.
{% endhint %}

<details>

<summary>Navigation cheat sheet</summary>

| Interface                | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Dashboard & Reports      | <p>From the <strong>Dashboard & Reports</strong> menu, you can view and manage your dashboards and reports from the dashboard and incidents table, and view alert exclusions.</p><ul><li><strong>Dashboard</strong>—Provides dashboards that you can use to view high-level statistics about your agents and incidents.</li><li><strong>Reports</strong>—View all the reports that Cortex XDR administrators have run.</li><li><p><strong>Customize</strong>—Create and manage a new dashboard and reports.</p><ul><li><strong>Dashboards Manager</strong>—Add new dashboards with customized widgets to surface the statistics that matter to you most.</li><li><strong>Reports Templates</strong>—Build reports using pre-defined templates, or customize a report. Reports can be generated on-demand scheduled.</li><li><strong>Widget Library</strong>—Search, view, edit, and create widgets based on predefined widgets and user-created custom widgets.</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Incident Response        | <p>From the <strong>Incident Response</strong> menu, you can view, manage, investigate and take action on all incidents.</p><ul><li><strong>Incidents</strong>—Investigate and manage your incidents.</li><li><p><strong>Investigation</strong></p><ul><li><strong>Query Builder</strong>—Build complex queries to investigate, identify connections, and expose the root cause of alerts from your data sources.</li><li><strong>Query Center</strong>—View and manage the results of all simple and complex queries created from the Query Builder.</li><li><strong>Scheduled Queries</strong>—View and manage all scheduled and reoccurring queries created from the Query Builder.</li><li><strong>Forensics</strong>—Streamline your incident response, data collection, threat hunting, and analyses of your endpoint data to find the source and scope of an attack.</li><li><strong>Host Inventory</strong>— Access comprehensive insights into your system's components, including applications, services, users, and vulnerability assessments, to maintain visibility and security across your environment.</li></ul></li><li><p><strong>Response</strong></p><ul><li><strong>Action Center</strong>—Provides a central location from which you can track the progress of all investigation, response, and maintenance actions performed on your endpoints.</li><li><strong>Live Terminal</strong>—Initiate a remote connection to an endpoint enabling you to remotely manage, investigate, and perform response actions on the endpoint.</li><li><strong>EDL</strong>—Add malicious domains and IP addresses to an external dynamic list enforceable on your Palo Alto Networks firewall.</li></ul></li><li><strong>Incident Configuration</strong>—Create a starring configuration that automatically categorizes and starts incidents when a related alert contains specific attributes that you define as important.</li></ul> |
| Detection & Threat Intel | <p>From the <strong>Detection</strong> menu, you can define specific rules for which you want Cortex XDR to raise alerts.</p><ul><li><p><strong>Detection Rules</strong></p><ul><li><strong>IOC</strong>—Identify specific hashes, IP addresses, domains, file names, and paths that indicate a threat.</li><li><strong>BIOC</strong>—Identify a specific network, process, file, or registry activity that indicates a threat.</li><li><strong>Correlations</strong>—Analyze correlations of multi-events from multiple sources.</li><li><strong>Exceptions</strong>—Define exception criteria for an IOC or BIOC rule.</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Assets                   | <p>From the <strong>Assets</strong> menu, you can define your network parameters and view a list of all the assets in your network.</p><ul><li><strong>Asset Inventory</strong>—Provides a central location from which you can view and investigate information relating to assets in your network.</li><li><strong>Network Configuration</strong>—Define your internal IP address ranges and domain names to identify and track your network assets.</li><li><strong>Vulnerability Assessment</strong>—Identify and quantify the security vulnerabilities on an endpoint.</li><li><strong>Asset Scores</strong>—Investigate user and host activities, and detect compromised accounts and malicious devices using the Cortex XDR calculated User and Host Scores.</li><li><strong>Cloud Inventory</strong>—Provides a unified, normalized asset inventory for cloud assets in Google Cloud Platform, Microsoft Azure, and Amazon Web Services.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Endpoints                | <p>From the <strong>Endpoints</strong> menu, you can manage your registered endpoints and configure the policy.</p><ul><li><strong>All Endpoints</strong>—View and manage endpoints that have registered with your Cortex XDR instance.</li><li><strong>Endpoint Groups</strong>—Create endpoint groups to which you can perform actions and assign the policy.</li><li><strong>Agent Installations</strong>—Create packages of the Cortex XDR agent software for deployment to your endpoints.</li><li><strong>Policy Management</strong>—Configure your endpoint security profiles and assign them to your endpoints.</li><li><strong>Host Firewall</strong>—Control communications on your endpoints by applying sets of rules that allow or block internal and external traffic.</li><li><strong>Device Control Violations</strong>—Monitor all instances where end users attempted to connect restricted USB-connected devices and Cortex XDR blocked them on the endpoint.</li><li><strong>Disk Encryption Visibility</strong>—View and manage endpoints that were encrypted using BitLocker.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Managed Services         | The Managed Threat Hunting service augments your security by providing 24/7, year-round monitoring by Palo Alto Networks threat researchers and Unit 42 experts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Quick Launcher           | Open an in-context shortcut that you can use to search for information, perform common investigation tasks, or initiate response actions from any place in the Cortex XDR console.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Settings                 | From the **Settings** menu, you can view information about your Cortex XDR license, review logs of actions initiated by Cortex XDR analysts, and configure Cortex XDR settings, integrations with other apps and services, and access management.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Tenant Navigator         | View and switch to tenants to which you have access divided per CSP account. You can also navigate directly to the Cortex Gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Notifications            | View Cortex XDR notifications.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Help                     | <p>Cortex XDR offers in-product help providing you with guidance directly from within the Cortex XDR Management Console.</p><p>From the <strong>Help</strong>, you can choose:</p><ul><li><strong>Documentation Portal</strong> to open the Cortex Help Center.</li><li>Toggle on/off the <strong>In-App Help Center</strong>. If on, the <img src="/files/RWWpQtliRxkHAfjjWA4C" alt="in-app-help-center-icon.png"> appears at the bottom right side of the page.</li><li><strong>Submit a Support Case</strong></li></ul><p>Click <img src="/files/RWWpQtliRxkHAfjjWA4C" alt="in-app-help-center-icon.png"> to open the Help Center. The topics listed in the panel reflect the current page opened in the Cortex XDR Management Console. You also have the option of entering a topic or keyword in the search bar for any information you are looking for.</p><p>Click the star at the top right hand side of the topic to add to the list of favorites. The list of favorites is saved to the home page of the Cortex Help Center panel.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| User                     | <p>From the User, see who is logged into Cortex XDR . Right-click and select:</p><ul><li><strong>About</strong> to view additional version and tenant ID information.</li><li><strong>What’s New in this Release</strong> to view selected new features available for your license type.</li><li><strong>What's New in XSIAM</strong></li><li><strong>Log Out</strong> to terminate the connection with your Cortex XDR Management Console.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

</details>

#### Filter page results

To reduce the number of results, you can filter by any heading and value. When you apply a filter, Cortex XDR displays the filter criteria above the results table. You can also filter individual columns for specific values using the icon to the right of the column heading.

Some fields also support additional operators such as **=**, **!=**, **Contains**, **not Contains**, **\***, **!\***.

There are three ways you can filter results:

<details>

<summary>Show me more</summary>

![XSIAM\_Filters104.gif](/files/0UtDxhDOADXVnTGyVcVN)

</details>

Filters are persistent. When you navigate away from the page and return, any filter you added remains active.

To build a filter using one or more fields:

1. From a Cortex XDR page, select filter (![filter-icon.png](/files/xzjRfnHIaDzd5xgibt5Y)).

   Cortex XDR adds the filter criteria above the top of the table.
2. For each field you would like to filter by:
   1. Select or search the field.
   2. Select the operator that matches the criteria.

      Use **=** to include results that match the value you specify, or **!=** to exclude results that match the value.
   3. Enter a value to complete the filter criteria.

      <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>CMD fields have a 128-character limit. Shorten longer query strings to 127 characters and add an asterisk (*).</p></div>

      Alternatively, you can select **Include empty values** to create a filter that excludes or includes results when the field has empty values.
3. To add additional filters, click **+AND,** within the filter brackets, to display results that must match all specified criteria, or **+OR** to display results that match any of the criteria.
4. To see the results, click out of the filter area.

#### Export results to file

You can export the page results for most pages in Cortex XDR to a tab-separated values (TSV) file.

1. (**Optional**) Filter page results to reduce the number of results for export.
2. Select export to file (![export-to-file-icon.png](/files/0KYpLk4ATaGyzurg8Okr)).

   Cortex XDR exports any results matching your applied filters in TSV format. The TSV format requires a tab separator, automatic detection does not work in the case of multi-event exports.

#### Save and share filters

You can save and share filters across your organization.

1. Save a filter:

   Saved filters are listed on the Filters tab for the table layout and filter manager menu.

   1. Save (![save-icon.png](/files/AxBoMrXSZXihpXLWYM17)) the active filter.
   2. Enter a name to identify the filter.

      You can create multiple filters with the same name. Saving a filter with an existing name does not override the existing filter.
   3. Choose to **Share this filter**, or keep it private for your use only.
2. Share a filter:

   You can share a filter across your organization.

   1. Select the table layout and filter menu indicated by the three vertical dots, then select **Filters**.
   2. Select the filter to share and click the share icon.
   3. You can later unshare (![filter-unshare-icon.png](/files/Nv3BDyUtq8oUUjxgfTr6)) or delete (![trash-icon.png](/files/uAcOS341izWL7p2qkh47)) a filter.

      Unsharing a filter turns a public filter private. Deleting a shared filter removes it for all users.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x/cortex-xdr-3.x-documentation/readme/use-the-interface.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
