> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs/cortex-xsiam-documentation.md).

# Cortex XSIAM Documentation

## How can we help?

Find product documentation, compatibility details, and the latest release information.

<button type="button" class="button primary" data-action="ask" data-icon="gitbook-assistant">Ask a question</button>

{% hint style="info" %}
Use the tiles below to browse each documentation area.
{% endhint %}

***

### Cortex XSIAM

Explore Cortex XSIAM platform documentation and technical references.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td><i class="fa-bullhorn">:bullhorn:</i> <strong>Release Notes</strong></td><td>Review the latest Cortex XSIAM features and known issues.</td><td><a href="/spaces/URJI4U6i9UDwotNccb7R/pages/kZlvobjlgo6Prn8MFcoi">Guide</a></td><td></td></tr><tr><td><i class="fa-book-open">:book-open:</i> <strong>Cortex XSIAM Documentation</strong></td><td>Learn daily tasks, configuration, and product workflows.</td><td><a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/QODQbh65sM5UR93gfxSJ">Guide</a></td><td></td></tr><tr><td><i class="fa-code">:code:</i> <strong>XQL Query Language Reference</strong></td><td>Use XQL functions and stages to transform and analyze data.</td><td><a href="/spaces/fUtoMSNyY2P8jbK3cQsM">Guide</a></td><td></td></tr><tr><td><i class="fa-plug">:plug:</i> <strong>Cortex XSIAM API Reference</strong></td><td>Explore Cortex XSIAM APIs and integration endpoints.</td><td><a href="/spaces/1ZrobAtcwfCDWAJAWeuj">Guide</a></td><td></td></tr><tr><td><i class="fa-database">:database:</i> <strong>XQL Schema Reference</strong></td><td>Review available datasets, fields, and presets.</td><td><a href="/spaces/6UN9P7f8B5L9QmLYI9Te/pages/0tbMO07opuvWRaO0m8ev">Guide</a></td><td></td></tr><tr><td><i class="fa-chart-line">:chart-line:</i> <strong>Analytics Alerts Reference Guide</strong></td><td>Review Cortex XSIAM analytics alerts and detection details.</td><td><a href="/spaces/5O67gr80iLneA56jiuO2">Guide</a></td><td><a href="/spaces/hJnzmcGQsreNQBWx4YG9/pages/w6038x6UpXohSz9OcmQp">Release Notes</a></td></tr><tr><td><i class="fa-table-columns">:table-columns:</i> <strong>Data Model Schema Reference</strong></td><td>Browse the XSIAM data model and field definitions.</td><td><a href="/spaces/HVBaxKOW1b6qcIQ6iMBh">Guide</a></td><td></td></tr><tr><td><i class="fa-user-shield">:user-shield:</i> <strong>Cortex Gateway Guide</strong></td><td>Manage permissions, RBAC, and user groups.</td><td><a href="/spaces/SqEFcjERpi4JSgB9LjVw">Guide</a></td><td></td></tr><tr><td><i class="fa-code-branch">:code-branch:</i> <strong>Cortex XSIAM Developer Guide</strong></td><td>Develop integrations and custom content for Cortex XSIAM.</td><td><a href="/spaces/urXrv6qkJRLbdhMdvPIU">Guide</a></td><td></td></tr><tr><td><i class="fa-server">:server:</i> <strong>Broker VM Image Migration</strong></td><td>Migrate to the latest Broker VM image installed with Debian 13.</td><td><a href="/spaces/AEIjuYE3RXcIfmuQnBbm/pages/fhfTWtIP4TJKPWJ85FMh">Guide</a></td><td></td></tr></tbody></table>

***

### Cortex XDR Agent

Explore installation, configuration, and troubleshooting guidance for Cortex XDR agents.

<table data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><i class="fa-bullhorn">:bullhorn:</i> <strong>Agent Release Notes</strong></td><td>Review the newest features and known issues for Cortex XDR Agent.</td><td><a href="/spaces/RwAoI4lZv8Q7OzaOg2cK">Guide</a></td></tr><tr><td><i class="fa-book-open">:book-open:</i> <strong>Agent Administrator Guide</strong></td><td>Learn the requirements for installing and using Cortex XDR Agent.</td><td><a href="/spaces/5UJguKA09UlnsSwXqQSr">Guide</a></td></tr><tr><td><i class="fa-list">:list:</i> <strong>Cortex XDR Agent Releases</strong></td><td>Review supported Cortex XDR Agent releases.</td><td><a href="/spaces/RwAoI4lZv8Q7OzaOg2cK/pages/G1oOaedpqKSGfgg5sjZj">Guide</a></td></tr><tr><td><i class="fa-table-columns">:table-columns:</i> <strong>Compatibility Matrix</strong></td><td>Find Cortex XDR Agent compatibility information.</td><td><a href="/spaces/fZ8QSMnkjnXpuOeuRcam">Guide</a></td></tr><tr><td><i class="fa-apple">:apple:</i> <strong>Agent iOS Guide</strong></td><td>Learn how the iOS app detects and blocks malicious URLs.</td><td><a href="/spaces/8AQY2hSDDP8XenSfAtjj/pages/8MEMPMTozIxe6Kp08pdJ">Guide</a></td></tr><tr><td><i class="fa-android">:android:</i> <strong>Agent Android Guide</strong></td><td>Learn how the Android app prevents malware on endpoints.</td><td><a href="/spaces/QYFpeEghdkGqvW2PdVmn">Guide</a></td></tr><tr><td><i class="fa-scale-balanced">:scale-balanced:</i> <strong>Agent OSS Listings</strong></td><td>Review open-source software licenses for Cortex XDR Agent.</td><td><a href="/spaces/TBvbxZu9tJn714mkiz7P/pages/x6PxiO2Z89EBzWBucl6M">Guide</a></td></tr><tr><td><i class="fa-linux">:linux:</i> <strong>Linux Kernel Versions</strong></td><td>Latest kernel module version support</td><td><a href="/spaces/y29o8lwSBpbfPbvztsyt">Guide</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam-docs/cortex-xsiam-documentation.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
