> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/readme.md).

# Navigate the Cortex XSIAM docs

Cortex XSIAM unifies detection, investigation, response, endpoint security, and cloud security in one platform.

Use this page to jump into the right docs area fast.

{% hint style="info" %}
Use the table of contents when you know the exact page. Use this page when you want a fast overview of the full Cortex XSIAM docs set.
{% endhint %}

### Learn about Cortex XSIAM

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-wand-magic-sparkles">:wand-magic-sparkles:</i> Agentic AI in Cortex XSIAM</p><p>Explore AI-powered investigation, response, and workflows.</p></td><td><a href="/pages/L5l2iP8vB531AlFRaYlt">/pages/L5l2iP8vB531AlFRaYlt</a></td></tr><tr><td><p><i class="fa-id-card">:id-card:</i> Cortex XSIAM product licenses</p><p>Understand licensing options and feature entitlements.</p></td><td><a href="/pages/09Lsz9hb2ROrwvU7HEDl">/pages/09Lsz9hb2ROrwvU7HEDl</a></td></tr><tr><td><p><i class="fa-key">:key:</i> Manage API keys</p><p>Create and manage keys for API access.</p></td><td><a href="/pages/paEXvbXD7zkFwTSb8pEA">/pages/paEXvbXD7zkFwTSb8pEA</a></td></tr></tbody></table>

### Set up Cortex XSIAM

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-list-check">:list-check:</i> Plan and prepare</p><p>Consider storage, region, XDR agent, and data sources requirements.</p></td><td><a href="/pages/7EYRv7CkoY58Vkrrcl1N">/pages/7EYRv7CkoY58Vkrrcl1N</a></td></tr><tr><td><p><i class="fa-gears">:gears:</i> Deployment steps</p><p>Set up your tenant, XDR Agent, users, and analytics. </p></td><td><a href="/pages/oWaVrR20WgqCo0PIhShc">/pages/oWaVrR20WgqCo0PIhShc</a></td></tr><tr><td><p><i class="fa-check-double">:check-double:</i> Post-deployment</p><p>Validate your deployment and complete initial tasks.</p></td><td><a href="/pages/CBf0MtGNdI7qEo2cMRnG">/pages/CBf0MtGNdI7qEo2cMRnG</a></td></tr><tr><td><p><i class="fa-plug">:plug:</i> Cortex XSIAM Data Sources</p><p>Connect supported data sources to Cortex XSIAM.</p></td><td><a href="/pages/NBMrv1PDvEdAgMKJCHjn">/pages/NBMrv1PDvEdAgMKJCHjn</a></td></tr></tbody></table>

### Configure Cortex XSIAM

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-database">:database:</i> Data management</p><p>Manage ingestion, retention, and data access.</p></td><td><a href="/pages/iaBwpJApcWEO67dPHvw0">/pages/iaBwpJApcWEO67dPHvw0</a></td></tr><tr><td><p><i class="fa-store">:store:</i> Marketplace</p><p>Discover and install integrations and content packs.</p></td><td><a href="/pages/PS0PuF9DgWOMselvkksm">/pages/PS0PuF9DgWOMselvkksm</a></td></tr><tr><td><p><i class="fa-robot">:robot:</i> Configure the Cortex Agentic Assistant</p><p>Set up assistant access and capabilities.</p></td><td><a href="/pages/Tb73Nh9wtxjkxcL6ckTL">/pages/Tb73Nh9wtxjkxcL6ckTL</a></td></tr><tr><td><p><i class="fa-server">:server:</i> Cortex MCP server</p><p>Connect external AI clients through the MCP server.</p></td><td><a href="/pages/DBtz1UNVuXnjkz9GmJ5L">/pages/DBtz1UNVuXnjkz9GmJ5L</a></td></tr><tr><td><p><i class="fa-bolt">:bolt:</i> Automations</p><p>Automate recurring security tasks and responses.</p></td><td><a href="/pages/46rSJqw1xLlMwd6f1qrY">/pages/46rSJqw1xLlMwd6f1qrY</a></td></tr><tr><td><p><i class="fa-gear">:gear:</i> Engines</p><p>Configure detection and automation processing engines.</p></td><td><a href="/pages/wDuZkQVZvS1wd8oWFdvw">/pages/wDuZkQVZvS1wd8oWFdvw</a></td></tr><tr><td><p><i class="fa-code-branch">:code-branch:</i> Remote repository management</p><p>Connect repositories for version-controlled content.</p></td><td><a href="/pages/oy8yyKKzrGyWD41zNnIX">/pages/oy8yyKKzrGyWD41zNnIX</a></td></tr><tr><td><p><i class="fa-folder-tree">:folder-tree:</i> Customize cases and issues</p><p>Tailor case and issue workflows to your needs.</p></td><td><a href="/pages/COoDq1FrqLOlABz0Vjvv">/pages/COoDq1FrqLOlABz0Vjvv</a></td></tr><tr><td><p><i class="fa-building">:building:</i> Multi-Tenant</p><p>Manage tenants and their security operations.</p></td><td><a href="/pages/5J5DsTI4Ma9wsBlqrrTo">/pages/5J5DsTI4Ma9wsBlqrrTo</a></td></tr><tr><td><p><i class="fa-handshake">:handshake:</i> Managed Services configuration in Cortex</p><p>Configure services for managed security operations.</p></td><td><a href="/pages/VhczeZzjRABhXbN9NHr2">/pages/VhczeZzjRABhXbN9NHr2</a></td></tr></tbody></table>

### Protect your endpoints

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-shield-halved">:shield-halved:</i> Endpoint security</p><p>Prevent, detect, and respond to endpoint threats.</p></td><td><a href="/pages/znCbuVUjgvwwOcRcMcw3">/pages/znCbuVUjgvwwOcRcMcw3</a></td></tr><tr><td><p><i class="fa-lock">:lock:</i> Endpoint DLP</p><p>Protect sensitive data on managed endpoints.</p></td><td><a href="/pages/8FXWITDKwKDjvd6o409P">/pages/8FXWITDKwKDjvd6o409P</a></td></tr></tbody></table>

### Detect, investigate, and respond to threats

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-chart-line">:chart-line:</i> Monitor dashboards and reports</p><p>Track security operations with dashboards and reports.</p></td><td><a href="/pages/hnrrkp8y47KkgCl6TCNm">/pages/hnrrkp8y47KkgCl6TCNm</a></td></tr><tr><td><p><i class="fa-magnifying-glass">:magnifying-glass:</i> Investigation and response</p><p>Investigate cases/issues and respond to threats.</p></td><td><a href="/pages/Wv3XAMO9mwSfUXRtiV1v">/pages/Wv3XAMO9mwSfUXRtiV1v</a></td></tr><tr><td><p><i class="fa-comments">:comments:</i> Agentic Assistant chat</p><p>Use natural language to investigate security data.</p></td><td><a href="/pages/3KyHoI6BE8Pn00oUWChB">/pages/3KyHoI6BE8Pn00oUWChB</a></td></tr><tr><td><p><i class="fa-boxes-stacked">:boxes-stacked:</i> Asset management</p><p>Inventory and monitor assets across your environment.</p></td><td><a href="/pages/hpGGwyI1isIL82kdzCjR">/pages/hpGGwyI1isIL82kdzCjR</a></td></tr><tr><td><p><i class="fa-crosshairs">:crosshairs:</i> Threat management</p><p>Prioritize and manage threats affecting your organization.</p></td><td><a href="/pages/l2WP2HmCoRgQ5HdfNIPQ">/pages/l2WP2HmCoRgQ5HdfNIPQ</a></td></tr><tr><td><p><i class="fa-globe">:globe:</i> Attack Surface Management</p><p>Discover and assess internet-facing attack surface risks.</p></td><td><a href="/pages/RsdIFXdmUQJF73vH9DBE">/pages/RsdIFXdmUQJF73vH9DBE</a></td></tr><tr><td><p><i class="fa-bug">:bug:</i> Vulnerability management</p><p>Identify, prioritize, and remediate vulnerabilities.</p></td><td><a href="/pages/FGWCkaYpBTaiacOLfcXb">/pages/FGWCkaYpBTaiacOLfcXb</a></td></tr><tr><td><p><i class="fa-radar">:radar:</i> Exposure management</p><p>Understand and reduce your overall cyber exposure.</p></td><td><a href="/pages/trAlReenEKZYI51TkKAT">/pages/trAlReenEKZYI51TkKAT</a></td></tr></tbody></table>

### Cloud Security

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-database">:database:</i> Data Security</p><p>Discover and protect sensitive cloud data.</p></td><td><a href="/pages/vZWKJaw4TeaUtcclE2Yo">/pages/vZWKJaw4TeaUtcclE2Yo</a></td></tr><tr><td><p><i class="fa-scale-balanced">:scale-balanced:</i> Monitor and track compliance adherence</p><p>Measure cloud compliance against supported standards.</p></td><td><a href="/pages/sCqDAIcNXPOlmgeVnVow">/pages/sCqDAIcNXPOlmgeVnVow</a></td></tr><tr><td><p><i class="fa-shield">:shield:</i> Cloud Security Rules and Policies</p><p>Configure policies and rules for cloud protection.</p></td><td><a href="/pages/kcUCjWr2PJIYBNByZPWV">/pages/kcUCjWr2PJIYBNByZPWV</a></td></tr><tr><td><p><i class="fa-tags">:tags:</i> Cloud Data Classification</p><p>Classify cloud data using sensitive data profiles.</p></td><td><a href="/pages/lJdl9KZcgEaMkcOpIl8R">/pages/lJdl9KZcgEaMkcOpIl8R</a></td></tr><tr><td><p><i class="fa-user-shield">:user-shield:</i> Cloud Identity Security</p><p>Secure cloud identities and their permissions.</p></td><td><a href="/pages/gmCet7FGYsOZSOu9wtRJ">/pages/gmCet7FGYsOZSOu9wtRJ</a></td></tr><tr><td><p><i class="fa-network-wired">:network-wired:</i> Network exposure detection</p><p>Identify cloud network paths that create exposure.</p></td><td><a href="/pages/DufIulvT2W4tVLwxX94R">/pages/DufIulvT2W4tVLwxX94R</a></td></tr><tr><td><p><i class="fa-brain">:brain:</i> Cloud AI Security</p><p>Secure AI services and workloads in the cloud.</p></td><td><a href="/pages/kJv1e7lkqHaTBI1ijlQp">/pages/kJv1e7lkqHaTBI1ijlQp</a></td></tr><tr><td><p><i class="fa-bolt">:bolt:</i> Serverless function posture security</p><p>Assess configuration risks in serverless functions.</p></td><td><a href="/pages/w0QebtU613cOk1PQDmgr">/pages/w0QebtU613cOk1PQDmgr</a></td></tr><tr><td><p><i class="fa-code">:code:</i> Cloud Application Security</p><p>Protect cloud-native applications across their lifecycle.</p></td><td><a href="/pages/uqu0bRB2APNb0n2erwda">/pages/uqu0bRB2APNb0n2erwda</a></td></tr><tr><td><p><i class="fa-cloud">:cloud:</i> Cloud workload policies and rules</p><p>Define controls for cloud workloads and resources.</p></td><td><a href="/pages/No4hJO8AAoUtG7TlGIPt">/pages/No4hJO8AAoUtG7TlGIPt</a></td></tr><tr><td><p><i class="fa-globe">:globe:</i> Web and API Security (WAAS)</p><p>Protect web applications and APIs from attacks.</p></td><td><a href="/pages/IuK4TuAnTmTbYthA0vSm">/pages/IuK4TuAnTmTbYthA0vSm</a></td></tr><tr><td><p><i class="fa-play">:play:</i> Serverless function runtime security</p><p>Detect runtime threats in serverless functions.</p></td><td><a href="/pages/510YX2Fat3lQfFslXY1f">/pages/510YX2Fat3lQfFslXY1f</a></td></tr><tr><td><p><i class="fa-envelope-open-text">:envelope-open-text:</i> Cortex Advanced Email Security</p><p>Protect users from email-based threats.</p></td><td><a href="/pages/B4hYeBSN6B24RhOSL1IY">/pages/B4hYeBSN6B24RhOSL1IY</a></td></tr></tbody></table>

### Reference and developer docs

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-terminal">:terminal:</i> Cortex XSIAM XQL</p><p>Query and analyze security data with XQL.</p></td><td><a href="/pages/DHnT8u9JihSAJl52kXP2">/pages/DHnT8u9JihSAJl52kXP2</a></td></tr><tr><td><p><i class="fa-share-nodes">:share-nodes:</i> Graph Search</p><p>Explore relationships between entities and events.</p></td><td><a href="/pages/lczGlUsBBdHvlOYPMQPI">/pages/lczGlUsBBdHvlOYPMQPI</a></td></tr><tr><td><p><i class="fa-terminal">:terminal:</i> Cortex CLI</p><p>Manage Cortex XSIAM from the command line.</p></td><td><a href="/pages/FFv8IFn0Pbcf96XW3msX">/pages/FFv8IFn0Pbcf96XW3msX</a></td></tr><tr><td><p><i class="fa-user-lock">:user-lock:</i> Role-Based Access Control</p><p>Control access with roles and permissions.</p></td><td><a href="/pages/5M5phRLF6QbN1uYN7oBx">/pages/5M5phRLF6QbN1uYN7oBx</a></td></tr><tr><td><p><i class="fa-code">:code:</i> API documentation</p><p>Integrate Cortex XSIAM with its public APIs.</p></td><td><a href="/pages/2aM7vpjYlo8JkGb5eELw">/pages/2aM7vpjYlo8JkGb5eELw</a></td></tr><tr><td><p><i class="fa-book-open">:book-open:</i> Reference</p><p>Find detailed product and configuration reference material.</p></td><td><a href="/pages/gHGMudhe8RQyo9U9Lj6X">/pages/gHGMudhe8RQyo9U9Lj6X</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
