> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/create-data-model-rules.md).

# Create Data Model Rules

{% hint style="warning" %}

### Prerequisite

Data Model Rules requires **View/Edit** RBAC permissions for **Data Management** (under **Configurations** → **Data Management**), which are the same permissions required for Dataset Management, Parsing Rules, and Event Forwarding.
{% endhint %}

You can override rules or create your own rules using XQL and additional custom syntax that is specific to defining Data Model Rules. Once you edit a default data model mapping, you will no longer receive Marketplace updates.

Review the following:

* [Data Model Rules editor views](/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/data-model-rules-editor-views.md)
* [Data Model Rules file structure and syntax](/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/data-model-rules-file-structure-and-syntax.md)
* [How to map authentication story events?](/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/how-to-map-authentication-story-events.md)

How to create Data Model Rules

1. In Cortex XSIAM, select **Settings** → **Configurations** → **Data Management** → **Data Model Rules**.
2. Select the Data Model editor view for writing your Data Model Rules.

   You can select one of the following views:

   * **User Defined Rules**: Leave the default view open and write your Data Model Rules directly in the editor.
   * **Both**: Select this view to see the Data Model Rules editor as well as the default rules as you write your Data Model Rules.
3. Write your rules using XQL syntax and the syntax specific to Data Model Rules.
4. (Optional) Use XQL Search to test your Data Model Rules and review logs.

   You can create queries on the data model. For more information, see [Create XQL query](/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response/build-xql-queries/how-to-build-xql-queries/create-xql-query.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/configure-cortex-xsiam/data-management/data-model-rules/create-data-model-rules.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
