> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/readme.md).

# Navigate the Cortex XSIAM docs

Start here for a visual overview of the main Cortex XSIAM documentation areas.

Cortex XSIAM unifies detection, investigation, response, endpoint security, and cloud security in one platform.

Use this page to jump into the right docs area fast.

{% hint style="info" %}
Use the table of contents when you know the exact page.

Use this page when you need a quick overview of the main Cortex XSIAM areas.
{% endhint %}

### Learn the product

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-circle-info">:circle-info:</i> Product overview</p><p>Learn about the basics and architecture.</p></td><td><a href="/cortex-xsiam/learn-about-cortex-xsiam/get-started-cortex-xsiam.md">Get started with Cortex XSIAM</a></td></tr><tr><td><p><i class="fa-wand-magic-sparkles">:wand-magic-sparkles:</i> Agentic AI</p><p>Explore AI-powered investigation, response, and workflows.</p></td><td><a href="/cortex-xsiam/learn-about-cortex-xsiam/agentic-ai-in-cortex-xsiam.md">Agentic AI in Cortex XSIAM</a></td></tr><tr><td><p><i class="fa-id-card">:id-card:</i> Licensing</p><p>Review plans, add-ons, and retention.</p></td><td><a href="/cortex-xsiam/learn-about-cortex-xsiam/cortex-xsiam-product-licenses.md">Cortex XSIAM license tiers and product licenses</a></td></tr><tr><td><p><i class="fa-desktop">:desktop:</i> Interface</p><p>Navigate pages, filters, views, and exports.</p></td><td><a href="/cortex-xsiam/learn-about-cortex-xsiam/use-the-interface.md">Use the Cortex XSIAM interface</a></td></tr></tbody></table>

### Onboard Cortex XSIAM

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-list-check">:list-check:</i> Plan and prepare</p><p>Consider storage, region, XDR agent, and data sources requirements.</p></td><td><a href="/cortex-xsiam/onboard-cortex-xsiam/plan-and-prepare.md">Plan and prepare</a></td></tr><tr><td><p><i class="fa-clipboard-list">:clipboard-list:</i> Deployment checklist</p><p>Follow the key steps to deploy and onboard.</p></td><td><a href="/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-onboarding-checklist.md">Cortex XSIAM onboarding checklist</a></td></tr><tr><td><p><i class="fa-check-double">:check-double:</i> Post-deployment</p><p>Validate your deployment and complete initial tasks.</p></td><td><a href="/cortex-xsiam/onboard-cortex-xsiam/post-deployment.md">Post-deployment</a></td></tr><tr><td><p><i class="fa-plug">:plug:</i> Cortex XSIAM Data Sources</p><p>Connect data sources, including CSP, and Cloud Posture and Runtime Security data sources.</p></td><td><a href="/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources.md">Cortex XSIAM Data Sources and Connectors</a></td></tr><tr><td><p><i class="fa-chart-line">:chart-line:</i> Analytics</p><p>Set up analytics and enable the analytics engine.</p></td><td><a href="/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-analytics.md">Cortex XSIAM - Analytics</a></td></tr><tr><td></td><td></td></tr></tbody></table>

### Configure Cortex XSIAM

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-database">:database:</i> Data management</p><p>Manage ingestion, retention, and data access.</p></td><td><a href="/cortex-xsiam/configure-cortex-xsiam/data-management.md">Data management</a></td></tr><tr><td><p><i class="fa-robot">:robot:</i> Configure the Cortex Agentic Assistant</p><p>Set up assistant access and capabilities.</p></td><td><a href="/cortex-xsiam/configure-cortex-xsiam/configure-the-cortex-agentic-assistant-1.md">Configure the Cortex Agentic Assistant</a></td></tr><tr><td><p><i class="fa-server">:server:</i> Cortex MCP server</p><p>Connect external AI clients through the MCP server.</p></td><td><a href="/cortex-xsiam/configure-cortex-xsiam/cortex-mcp-server.md">Cortex MCP server</a></td></tr><tr><td><p><i class="fa-bolt">:bolt:</i> Automations</p><p>Automate recurring security tasks and responses.</p></td><td><a href="/cortex-xsiam/configure-cortex-xsiam/automations.md">Automations</a></td></tr><tr><td><p><i class="fa-folder-tree">:folder-tree:</i> Customize cases and issues</p><p>Tailor case and issue workflows to your needs.</p></td><td><a href="/cortex-xsiam/configure-cortex-xsiam/customize-cases-and-issues.md">Customize cases and issues</a></td></tr><tr><td><p><i class="fa-building">:building:</i> Multi-Tenant</p><p>Manage tenants and their security operations.</p></td><td><a href="/cortex-xsiam/configure-cortex-xsiam/multi-tenant.md">Multi-Tenant</a></td></tr><tr><td><p><i class="fa-handshake">:handshake:</i> Managed Services configuration in Cortex</p><p>Configure services for managed security operations.</p></td><td><a href="/cortex-xsiam/configure-cortex-xsiam/managed-services-configuration-in-cortex.md">Managed Services configuration in Cortex</a></td></tr></tbody></table>

### Protect your environment

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-shield-halved">:shield-halved:</i> Endpoint security</p><p>Prevent, detect, and respond to endpoint threats.</p></td><td><a href="/cortex-xsiam/protect-your-endpoints/endpoint-security.md">Endpoint security</a></td></tr><tr><td><p><i class="fa-lock">:lock:</i> Endpoint DLP</p><p>Protect sensitive data on managed endpoints.</p></td><td><a href="/cortex-xsiam/protect-your-endpoints/endpoint-dlp-1.md">Endpoint DLP</a></td></tr></tbody></table>

### Detect, investigate, and respond

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-chart-line">:chart-line:</i> Monitor dashboards and reports</p><p>Track security operations, trends, and outcomes.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/monitor-dashboards-and-reports.md">Monitor dashboards and reports</a></td></tr><tr><td><p><i class="fa-magnifying-glass">:magnifying-glass:</i> Investigation and response</p><p>Investigate cases/issues and respond to threats.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/investigation-and-response.md">Investigation and response</a></td></tr><tr><td><p><i class="fa-comments">:comments:</i> Agentic Assistant chat</p><p>Use natural language to investigate security data.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/agentic-assistant-chat.md">Agentic Assistant chat</a></td></tr><tr><td><p><i class="fa-boxes-stacked">:boxes-stacked:</i> Asset management</p><p>Inventory and monitor assets across your environment.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/asset-management.md">Asset management</a></td></tr><tr><td><p><i class="fa-crosshairs">:crosshairs:</i> Threats</p><p>Prioritize and manage threats affecting your organization.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/threat-management.md">Threat management</a></td></tr><tr><td><p><i class="fa-globe">:globe:</i> Attack Surface Management</p><p>Discover and assess internet-facing attack surface risks.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/attack-surface-management.md">Attack surface management</a></td></tr><tr><td><p><i class="fa-bug">:bug:</i> Vulnerability management</p><p>Identify, prioritize, and remediate vulnerabilities.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/vulnerability-management.md">Vulnerability management</a></td></tr><tr><td><p><i class="fa-radar">:radar:</i> Exposure management</p><p>Understand and reduce your overall cyber exposure.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/exposure-management.md">Exposure management</a></td></tr></tbody></table>

### Cloud Security

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-database">:database:</i> Data Security</p><p>Discover and protect sensitive cloud data.</p></td><td><a href="/cortex-xsiam/data-security/cortex-data-security.md">Cortex Data Security</a></td></tr><tr><td><p><i class="fa-scale-balanced">:scale-balanced:</i> Monitor and track compliance adherence</p><p>Measure cloud compliance against supported standards.</p></td><td><a href="/cortex-xsiam/cloud-security/monitor-and-track-compliance-adherence.md">Monitor and track compliance adherence</a></td></tr><tr><td><p><i class="fa-shield">:shield:</i> Cloud Security Rules and Policies</p><p>Configure policies and rules for cloud protection.</p></td><td><a href="/cortex-xsiam/cloud-security/rules-and-policies/cloud-security-rules-and-policies.md">Cloud security rules and policies</a></td></tr><tr><td><p><i class="fa-tags">:tags:</i> Cloud Data Classification</p><p>Classify cloud data using sensitive data profiles.</p></td><td><a href="/cortex-xsiam/cloud-security/cortex-cloud-data-classification.md">Cloud Data Classification</a></td></tr><tr><td><p><i class="fa-user-shield">:user-shield:</i> Cloud Identity Security</p><p>Secure cloud identities and their permissions.</p></td><td><a href="/cortex-xsiam/cloud-security/cortex-cloud-identity-security.md">Cloud Identity Security</a></td></tr><tr><td><p><i class="fa-network-wired">:network-wired:</i> Network exposure detection</p><p>Identify cloud network paths that create exposure.</p></td><td><a href="/cortex-xsiam/cloud-security/network-exposure-detection.md">Network exposure detection</a></td></tr><tr><td><p><i class="fa-brain">:brain:</i> Cloud AI Security</p><p>Secure AI services and workloads in the cloud.</p></td><td><a href="/cortex-xsiam/cloud-security/cortex-cloud-ai-security.md">Cortex Cloud AI Security</a></td></tr><tr><td><p><i class="fa-bolt">:bolt:</i> Serverless function posture security</p><p>Assess configuration risks in serverless functions.</p></td><td><a href="/cortex-xsiam/cloud-security/serverless-function-posture-security.md">Serverless function posture security</a></td></tr><tr><td><p><i class="fa-code">:code:</i> Cloud Application Security</p><p>Protect cloud-native applications across their lifecycle.</p></td><td><a href="/cortex-xsiam/cloud-security/cortex-cloud-application-security.md">Cortex Cloud Application Security</a></td></tr><tr><td><p><i class="fa-cloud">:cloud:</i> Cloud workload policies and rules</p><p>Define controls for cloud workloads and resources.</p></td><td><a href="/cortex-xsiam/cloud-security/rules-and-policies/cloud-workload-policies-and-rules.md">Cloud workload policies and rules</a></td></tr><tr><td><p><i class="fa-globe">:globe:</i> Web and API Security (WAAS)</p><p>Protect web applications and APIs from attacks.</p></td><td><a href="/cortex-xsiam/cloud-security/overview.md">Web and API Security (WAAS)</a></td></tr><tr><td><p><i class="fa-play">:play:</i> Serverless function runtime security</p><p>Detect runtime threats in serverless functions.</p></td><td><a href="/cortex-xsiam/cloud-security/overview-1.md">Serverless function runtime security</a></td></tr><tr><td><p><i class="fa-envelope-open-text">:envelope-open-text:</i> Cortex Advanced Email Security</p><p>Protect users from email-based threats.</p></td><td><a href="/cortex-xsiam/detect-investigate-and-respond-to-threats/cortex-advanced-email-security.md">Cortex Advanced Email Security</a></td></tr></tbody></table>

### Reference and developer docs

<table data-view="cards"><thead><tr><th></th><th data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><p><i class="fa-terminal">:terminal:</i> XQL</p><p>Query and analyze security data with XQL.</p></td><td><a href="/cortex-xsiam/reference-and-developer-docs/cortex-agentix-xql.md">Cortex XSIAM XQL</a></td></tr><tr><td><p><i class="fa-share-nodes">:share-nodes:</i> Graph Search</p><p>Explore relationships between entities and events.</p></td><td><a href="/cortex-xsiam/reference-and-developer-docs/graph-search.md">Graph Search</a></td></tr><tr><td><p><i class="fa-terminal">:terminal:</i> Cortex CLI</p><p>Manage Cortex XSIAM from the command line.</p></td><td><a href="/cortex-xsiam/reference-and-developer-docs/about-cortex-cli.md">About Cortex CLI</a></td></tr><tr><td><p><i class="fa-user-lock">:user-lock:</i> Role-Based Access Control</p><p>Control access with roles and permissions.</p></td><td><a href="/cortex-xsiam/reference-and-developer-docs/role-based-access-control.md">Role-Based Access Control</a></td></tr><tr><td><p><i class="fa-code">:code:</i> API documentation</p><p>Integrate Cortex XSIAM with its public APIs.</p></td><td><a href="/cortex-xsiam/reference-and-developer-docs/api-documentation.md">API documentation</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/learn-about-cortex-xsiam/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
