For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 5.x

Use the interface

Learn more about how to use the Cortex XDR interface.

The Cortex XDR interface provides a centralized workspace for viewing and managing security data across your environment.

Use the navigation menu on the left to move between product areas in the tenant. For a quick overview of each area, see the Navigation cheat sheet below.

From the interface, you can:

  • Navigate between product areas.

  • Chat with an Agentic Assistant agent

  • Filter table results to find relevant information.

  • Create saved views with commonly used filter configurations.

  • Export table data.

  • Access in-product help and documentation.

Note

  • Each SAML login session is valid for 8 hours.

  • Some menu items only appear if you have the relevant license.

Filter page results

To reduce the number of results, you can filter by any heading and value. When you apply a filter, Cortex XDR displays the filter criteria above the results table. You can also filter individual columns for specific values using the icon to the right of the column heading.

Some fields also support additional operators such as =, !=, Contains, not Contains, *, !*.Filters are persistent. When you navigate away from the page and return, any filter you added remains active.

To build a filter using one or more fields:

  1. From a Cortex XDR page, select filter (filter-icon.png).

    Cortex XDR adds the filter criteria above the top of the table.

  2. For each field, you would like to filter by:

    1. Select or search the field.

    2. Select the operator that matches the criteria.

      Use = to include results that match the value you specify, or != to exclude results that match the value.

    3. Enter a value to complete the filter criteria.

      Note

      CMD fields have a 128-character limit. Shorten longer query strings to 127 characters and add an asterisk (*).

      Alternatively, you can select Include empty values to create a filter that excludes or includes results when the field has empty values.

  3. To add additional filters, click +AND, within the filter brackets, to display results that must match all specified criteria, or +OR to display results that match any of the criteria.

  4. To see the results, click out of the filter area.

Save views and filters

Cortex XDR allows you to save filter configurations so you can quickly return to commonly used data selections. Depending on the page you are working on, you can save either views or filters:

  • Saved views store table configurations, including filters, so you can quickly switch between commonly used table perspectives.

  • Saved filters store only the filter criteria, allowing you to quickly apply the same filtering logic again.

These options help you quickly focus on the data most relevant to your workflow.

Saved views

Saved views store filter configurations for table data, allowing you to quickly return to frequently used filters. You can filter table data by fields such as domain, context, or work queue, configure the columns you want to see, and save the configuration as a reusable view.

Saved views are available on most table-based pages, such as the Cases and Issues pages. The default view is All (for example, All Cases).

Select the arrow next to the view name to see all available views. If you modify filters in an existing view, you can update the view or save the configuration as a new view.

Save a view

  1. Apply one or more filters.

  2. Select Save.

  3. Enter a name for the view.

  4. Choose whether to share the view.

Manage views

  • Use the three-dot Actions menu next to the view name to take the following actions:

    • Set the view as the default.

    • Share or unshare the view.

    • Update the view after modifying filters.

    • Delete the view.

Note

  • Deleting a shared view removes it for all users.

  • You can delete your own saved views.

  • To delete views created by other users, you must have the Account administrator or Instance administrator role.

Saved filters

Some pages allow you to save filters instead of views, such as the IOC and BIOC pages.

Saved filters store filter criteria, allowing you to quickly apply the same filters again. Saved filters help standardize filtering and allow users to quickly apply commonly used search conditions.

Apply a saved filter

  1. Open the three-dot Actions menu in the table filter row.

  2. Select Saved filters and choose a filter to apply.

  3. Click Apply.

Create a filter

  1. Remove all filters from the table.

  2. Click Add filter and define the filter values.

  3. Click Save and define a filter name.

Share or delete a saved filter

  1. Open the three-dot Actions menu in the table filter row.

  2. Select Saved filters.

  3. Click the Actions menu next to a filter name and select the relevant action.

Note

  • Deleting a shared filter removes it for all users.

  • You can delete your own saved filters.

  • To delete filters created by other users, you must have the Account administrator or Instance administrator role.

Export results

You can export the page results for most pages in Cortex XDR to a tab-separated values (TSV) file.

  1. (Optional) Filter page results to reduce the number of results for export.

  2. Select export to file (export-to-file-icon.png).

    Cortex XDR exports any results matching your applied filters in TSV format. The TSV format requires a tab separator, automatic detection does not work in the case of multi-event exports.

System tools and services

The following controls appear in the navigation bar and provide access to system tools, help resources, and tenant settings.

Cortex Agentic Assistant

Click agentic-assistant.png in the top-right corner to open the assistant.

The Cortex Agentic Assistant is the autonomous AI capability of Cortex XSIAM. It uses AI agents that plan, reason, and investigate complex threats, such as cloud identity theft or container breaches.

Notifications

The Notifications panel displays system alerts and updates generated by Cortex XDR.

Tenant Navigator

Use Tenant Navigator to view and switch between tenants you have access to. Tenants are organized by CSP account.You can also navigate directly to the Cortex Gateway.

Settings

From the Settings menu, you can:

  • View license information

  • Manage audit logs

  • Manage exceptions configuration

  • Configure data sources and system settings

Managed Services

The Managed Threat Hunting service provides 24/7 monitoring by Palo Alto Networks threat researchers and Unit 42 experts.

Help

Cortex XDR provides in-product help directly within the interface.

Click in-app-help-center-icon.png to open the Help. There are two options:

  • Documentation Portal

  • Initiate Support Request

If you have the Cortex Agentic Assistant enabled, when you select Initiate Support Request, the Help Center agent opens to provides assistance with finding relevant documentation, troubleshooting, and creating a support ticket. After your first prompt to the Help Center agent, you can click Submit support ticket from above the chat. If you click Submit Support Ticket, you are brought directly to the Submit Support Ticket wizard. If you do not have Cortex Agentic Assistant enabled, selecting Initiate Support Request brings you directly to the Submit Support Ticket wizard.

User menu

Click your username to access user and tenant options.

From the user menu, you can:

  • View tenant information

  • See What's New

  • Switch between light and dark mode

  • Log out

Last updated

Was this helpful?