For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSIAMAnalytics & Detetion

Enable the Analytics Engine and Identity Analytics

Enable Cortex XSIAM Analytics Engine and Identity Analytics to baseline activity and detect anomalous endpoint and user behavior.

Cortex XSIAM - Analytics includes the following:

  • Cortex XSIAM Analytics Engine: Analyzes your endpoint data to develop a baseline and raise Analytics and Analytics BIOC alerts when anomalies and malicious behaviors are detected.

  • Identity Analytics: Allows the Cortex XSIAM Analytics engine to aggregate and display user profile details, activities, and alerts related to a user-based Analytics type alert and Analytics BIOC rule during an investigation.

Prerequisite

How to enable analytics

  1. Select SettingsConfigurationsCortex XSIAM - Analytics.

  2. Click Enable. Creating a baseline can take up to three hours.

    Adding Windows DHCP logs can enhance the Analytics Engine. For more information, see Ingest Windows DHCP Logs with an XDR Collector Profile.

  3. Activate Identity Analytics by turning on the toggle.

Last updated

Was this helpful?