> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr.md).

# Onboard Cortex XDR

- [Deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps.md): Plan, deploy, and onboard Cortex XDR using the required deployment steps.
- [Plan and prepare](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/plan-and-prepare.md): Learn more about deployment considerations and onboarding steps.
- [Cortex XDR onboarding checklist](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/cortex-xdr-onboarding-checklist.md): Review the steps to deploy and onboard Cortex XDR.
- [Activate Cortex XDR](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr.md): Learn how to activate your tenant.
- [Cortex XDR supported regions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/cortex-xdr-supported-regions.md): Review available Cortex XDR hosting regions and their data residency details.
- [Enable access to required PANW resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources.md): Configure firewall access for Cortex XDR resources.
- [Regional egress resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources/regional-egress-resources.md): Allow required regional endpoints for Cortex XDR agent and tenant communication.
- [Engines IP addresses (outbound)](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources/engines-ip-addresses-outbound.md): Allow outbound engine IP addresses to access your network resources.
- [Inbound source resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources/inbound-source-resources.md): Allow Cortex XDR source IP addresses to access your resources.
- [FedRamp and the US Federal Government required resources](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/activate-cortex-xdr/enable-access-to-required-panw-resources/fedramp-and-the-us-federal-government-required-resources.md): Configure required resources for FedRAMP and US federal deployments.
- [Set up users, groups, and roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles.md): Learn how to set up users, groups, and roles in Cortex XDR.
- [User group management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles/user-group-management.md): Create and manage user groups, group mappings, and group-based access in Cortex XDR.
- [Assign user roles and groups](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-users-and-roles/assign-user-roles-and-groups.md): Assign roles and groups to control each user's Cortex XDR access.
- [Set up authentication](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication.md): Authenticate Cortex XDR users using SAML 2.0 or Customer Support Portal (CSP).
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-through-the-customer-support-portal.md): Add Customer Support Portal users and grant them access to Cortex Gateway and Cortex XDR.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-using-sso.md): Configure single sign-on authentication for Cortex XDR users.
- [Set up okta as the Identity provider using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Configure Okta as a SAML 2.0 identity provider for Cortex XDR.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Configure Microsoft Entra ID as a SAML 2.0 identity provider.
- [Authenticate users through the Customer Support Portal](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-through-the-customer-support-portal-1.md): Add Customer Support Portal users and grant tenant access.
- [Authenticate users using SSO](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-using-sso-1.md): Configure SAML 2.0 single sign-on for Cortex XDR users.
- [Set up Okta as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-using-sso-1/set-up-okta-as-the-identity-provider-using-saml-2.0.md): Configure Okta SAML single sign-on for Cortex XDR.
- [Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-authentication/authenticate-users-using-sso-1/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md): Configure Microsoft Entra ID SAML single sign-on for Cortex XDR.
- [Pre-installation steps for Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/pre-installation-steps-for-cortex-xdr-agents.md): Complete system and network prerequisites before installing Cortex XDR agents.
- [Install Cortex XDR agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents.md): Learn about the initial steps required to deploy Cortex XDR agent software to endpoints.
- [Plan your agent deployment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents/plan-your-agent-deployment.md): Plan a Cortex XDR agent rollout for your endpoints and environment.
- [Guidelines for keeping Cortex XDR agents and content updated/](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents/guidelines-for-keeping-cortex-xdr-agents-and-content-updated.md): Keep Cortex XDR agents and security content current and supported.
- [Create an installation package](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents/create-an-installation-package.md): Create an installation package for deploying Cortex XDR agents.
- [Deploy agent installation packages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/install-cortex-xdr-agents/deploy-agent-installation-packages.md): Deploy Cortex XDR agent installation packages across your endpoints.
- [Configure XDR Analytics](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/configure-xdr-analytics.md): Configure XDR Analytics to analyze data and detect threats.
- [Set up Cloud Identity Engine](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/set-up-cloud-identity-engine.md): Set up Cloud Identity Engine to enrich Cortex XDR identity data.
- [Manage API keys](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/deployment-steps/manage-api-keys.md): Create, manage, and revoke API keys for Cortex XDR integrations.
- [Post-deployment steps](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps.md): Configure and manage Cortex XDR after completing the initial deployment.
- [Set up your environment](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment.md): Learn more about setting up the Cortex XDR environment based on your preferences.
- [Configure server settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/configure-server-settings.md): Configure tenant-wide and user-specific Cortex XDR server settings.
- [Configure security settings](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/configure-security-settings.md): Configure login sessions, access restrictions, and user expiration settings.
- [Data and log forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding.md): Configure forwarding of Cortex XDR data, logs, and notifications.
- [Forward logs and data from Cortex XDR to external services](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services.md): Send Cortex XDR logs, cases, and issues to external services.
- [Configure external applications for forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding.md): Configure external applications before forwarding Cortex XDR notifications.
- [Forward notifications to Amazon SQS](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-sqs.md): Configure Amazon SQS to receive Cortex XDR issue and case notifications.
- [Forward notifications to Amazon S3](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-amazon-s3.md): Configure Amazon S3 to receive Cortex XDR issue and case notifications.
- [Forward notifications to Splunk](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-splunk.md): Configure Splunk to receive Cortex XDR issue and case notifications.
- [Forward notifications to webhook](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/forward-notifications-to-webhook.md): Configure a webhook to receive Cortex XDR issue and case notifications.
- [Integrate a syslog receiver](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/integrate-a-syslog-receiver.md): Configure a syslog receiver for Cortex XDR log and notification forwarding.
- [Integrate Slack for outbound notifications](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-external-applications-for-forwarding/integrate-slack-for-outbound-notifications.md): Connect Slack to receive Cortex XDR issue and report notifications.
- [Configure notification forwarding](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/configure-notification-forwarding.md): Select Cortex XDR notifications and configure where to forward them.
- [Set up email notifications for tenant updates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/set-up-email-notifications-for-tenant-updates.md): Receive email notifications when Cortex XDR tenant updates are scheduled or complete.
- [Monitor administrative activity](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/forward-logs-and-data-from-cortex-xdr-to-external-services/monitor-administrative-activity.md): Review and forward audit logs for Cortex XDR administrative activity.
- [Data and log notification formats](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats.md): Review formats for forwarded Cortex XDR cases, issues, and logs.
- [Management audit log messages](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-messages.md): Review management audit log types and messages generated by Cortex XDR.
- [Issue notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/issue-notification-format.md): Review issue notification formats for email and external forwarding destinations.
- [Agent Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/agent-audit-log-notification-format.md): Review the email and syslog formats for agent audit log notifications.
- [Management Audit log notification format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/management-audit-log-notification-format.md): Review the email and syslog formats for management audit log notifications.
- [Log format for IOC and BIOC issues](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/log-format-for-ioc-and-bioc-issues.md): Review legacy log formats for IOC and BIOC issues.
- [Analytics log format](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/set-up-your-environment/data-and-log-forwarding/data-and-log-notification-formats/analytics-log-format.md): Review legacy log formats and fields for Cortex XDR Analytics issues.
- [Manage user roles and access management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management.md): Learn how to manage access for users, user roles, user groups, and Single Sign-On (SSO) for users on a specific Cortex XDR tenant.
- [Manage user roles](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-roles.md): Create, edit, and assign roles that control Cortex XDR permissions.
- [Manage user acces](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-access.md): Manage users and their access to the Cortex XDR tenant.
- [Manage user scope](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope.md): Configure Scope-Based Access Control (SBAC) to limit access to Cortex XDR data and content.
- [Manage access to objects](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects.md): Control user access to Cortex XDR objects and saved content.
- [Manage access to custom dashboards](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-custom-dashboards.md): Control which users can view and manage custom dashboards.
- [Manage access to report templates](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-report-templates.md): Control which users can view and manage report templates.
- [Manage access to playbooks and scripts](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-playbooks-and-scripts.md): Control which users can view and manage playbooks and scripts.
- [Manage access to saved queries](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-saved-queries.md): Control which users can view and manage saved queries.
- [Configure the Cortex Agentic Assistant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant.md): Create and manage agents and actions in the Agents Hub and configure access to the Cortex Agentic Assistant.
- [Agents Hub](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub.md): Manage Cortex Agentic Assistant agents, actions, and integrations.
- [Manage actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-actions.md): Create and manage actions that agents can perform.
- [Register actions](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/register-actions.md): Register actions for use by Cortex Agentic Assistant agents.
- [Manage agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/manage-agents.md): View, configure, and manage Cortex Agentic Assistant agents.
- [Build agents](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/build-agents.md): Build Cortex Agentic Assistant agents for your security workflows.
- [Expand agent capabilities with MCP integrations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agents-hub/expand-agent-capabilities-with-mcp-integrations.md): Extend agent capabilities by configuring Model Context Protocol integrations.
- [Agentic Assistant role based access control](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/configure-the-cortex-agentic-assistant/agentic-assistant-role-based-access-control.md): Configure role-based access to the Cortex Agentic Assistant and Agents Hub.
- [Dashboards and reports](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/post-deployment-steps/dashboards-and-reports.md): Create dashboards and reports to monitor your Cortex XDR environment.
- [Multi-Tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant.md): Manage licensing, onboarding, and operations across Cortex XDR tenants.
- [What is Cortex XDR multi-tenant?](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/what-is-cortex-xdr-multi-tenant.md): Learn about Cortex multi-tenant deployments that provide data segregation while enabling you to manage multiple tenants from a single console.
- [Multi-tenant central licensing management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/multi-tenant-central-licensing-management.md)
- [Onboard Cortex multi-tenant](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/onboard-cortex-multi-tenant.md): Learn how to activate and manage tenants.
- [Dynamic license allocation](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/dynamic-license-allocation.md): In a multi-tenant central licensing management environment, you can dynamically edit child tenant allocations, add child tenants, and delete child tenants with the license pool automatically updated.
- [Child tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management.md): Track, manage, and investigate child tenant data from the parent tenant.
- [Track your tenant management](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management/track-your-tenant-management.md): Monitor tenant management activity across your multi-tenant environment.
- [Investigate child tenant data](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management/investigate-child-tenant-data.md): Investigate security data from child tenants in Cortex XDR.
- [Create and allocate configurations](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management/create-and-allocate-configurations.md): Create configurations and allocate them to child tenants.
- [Create a security managed action](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/child-tenant-management/create-a-security-managed-action.md): Create managed actions to apply security changes across child tenants.
- [About managed threat hunting](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr/multi-tenant/about-managed-threat-hunting.md): Understand how Managed Threat Hunting can help your organization.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/onboard-cortex-xdr.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
