> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-onboarding-checklist.md).

# Cortex XSIAM onboarding checklist

Review the plan and prepare considerations, and then use the onboarding checklist to successfully deploy and onboard Cortex XSIAM.

![fast-track-onboard.png](/files/XxI02D7ItsD6bM6wbijn)

{% hint style="info" %}

### Note

This checklist does not include any specific Cloud Security requirements. If you have a Cortex XSIAM Premium license or another XSIAM license with Cloud Posture Security/Runtime, you should also onboard Cloud Posture Security and Runtime during or after completing this stage. For more information about Cloud Security onboarding, see [Cloud service provider (CSP) onboarding](/cortex-xsiam/configure-cortex-xsiam/cortex-xsiam-data-sources/cloud-service-provider-csp-onboarding.md).
{% endhint %}

**Deployment checklist**

This phase sets up the infrastructure and data pipelines.

| Step                                       | Details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | See More                                                                                                                                                                                                                                                                                                                                                           |
| ------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| 1. Activation and initial setup            | <p>✓ In the Cortex Gateway, activate Cortex XSIAM and confirm license status.</p><p>✓ Enable access to required PANW resources and set up encryption keys (BYOK), if required.</p><p>✓ Assign initial administrator and analyst-type user roles (Responder/Investigator), create user groups, and assign roles to those groups (recommended) to a limited number of users initially. You can update this later.</p><p>✓ Set up access through the Customer Support Portal or SAML single sign-on.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | <p><a href="/pages/3glP3BWsMMQUXeWWPuqt">Activate Cortex XSIAM</a><br><br><a href="/pages/IWVdemmwfxhhDy9hY7cd">Enable access to required PANW resources</a><br><br><a href="/pages/zs5ATGWKEcNy0QQ1vh8I">Set up users and roles</a><br><a href="/pages/4JSvzCJgecoQO0S422H6">Set up authentication</a></p>                                                        |
| 2. Configure content                       | <p>Use the Data Sources Onboarding wizard to configure the following:</p><p>✓ Priority content:</p><ul><li>Configure network security data, such as Palo Alto Networks Next-Generation Firewalls, and network devices.</li><li>Configure identity and user data. Install the Cloud Identity Engine (optional and highly recommended), which provides the necessary Active Directory or Microsoft Entra ID/Okta context (user names, group membership, computer names) to map a raw event (for example, an IP address) to a user or asset.</li></ul><p>✓ Highly recommended content:</p><ul><li>Connect cloud audit logs for the most critical providers, such as AWS CloudTrail, Azure Activity Logs, and Google Cloud Audit Logs, directly to Cortex XSIAM.</li><li>Configure/enable a key Threat Intelligence feed, such as the Unit 42 Intelligence feed, to enrich incoming issues. This ensures that as soon as a log/alert hits the Data Lake, it has the latest malicious context.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | <ul><li><a href="/pages/wKxvjGTqgug2RnTinmhs">What are Cortex XSIAM data sources?</a></li><li><a href="/pages/LVmFk0hZ8cBrM2hXpOO5">Set up Cloud Identity Engine</a></li></ul>                                                                                                                                                                                     |
| 3. Deploy the XDR agent                    | <p>✓ Install the XDR agent by creating XDR Agent installation packages for a small, diverse pilot group of endpoints and deploy the agent to a pilot group (phased rollout). Start with small, low-risk endpoints and extend, as required. Gradually expand agent distribution to larger groups that have similar attributes (hardware, software, and users). At the end of two weeks, you can have Cortex XSIAM deployed on up to 100 endpoints.</p><p>✓ After testing expected agent behavior and performance, review and select default endpoint security profiles (Exploit, Malware, Restrictions, Agent Settings, Exceptions) to begin protecting your endpoints from threats immediately. Once endpoints are deployed and start collecting data, you can make any necessary adjustments to these rules and policies.</p><p>✓ Verify endpoint data collection (logs, alerts, events) is flowing from deployed agents to the XSIAM Data Lake. After deploying the agents to the pilot group, set up data collection to analyze the data.</p><p>This provides granular event data (process execution, file activity, registry changes, network connections) necessary for EDR/XDR detection and Behavioral Indicators of Compromise (BIOCs).</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | <ul><li><a href="/pages/xTS384SLrHGb1Jfrj9Sg">Create an agent installation package</a></li><li><a href="/pages/jUxv47B36iNKzphB5SBc">Set up endpoint profiles and exception rules</a></li><li><a href="/pages/gOhRupbQvXe7ZkIIzx1g">Set up agent settings profiles</a></li><li><a href="/pages/AqiAOI5iTS4EotIXI0uG">Configure global agent settings</a></li></ul> |
| 4. Enable Analytics and Identity Analytics | <p>✓ Enable Cortex XSIAM Analytics engine (if not already enabled).</p><p>The analytics engine accesses your logs as they are streamed to Cortex XSIAM, including firewall data, and analyzes them as soon as they arrive.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>You need EDR or network logs from at least 30 endpoints over a minimum of 2 weeks, or Cloud audit logs over a minimum of 2 weeks.</p></div><p>✓ Enable Identity Analytics, which focuses on user behavior that is critical since attackers primarily target credentials. It has two main functions:</p><ul><li>User/Entity Behavior Analytics (UEBA): Profiles users, hosts, and groups based on identity data and flags anomalies like a user logging in from a new country (Impossible Traveler), accessing an unusual database, or transferring a massive file volume outside of their norm.</li><li><p>Investigation context: When an issue fires, Identity Analytics ensures that the relevant user profile details, recent activities, and group membership are automatically aggregated and displayed with a user-based Analytics type issue and Analytics BIOC rule</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The Cloud Identity Engine must be set up.</p></div></li></ul><p>✓ Enable the Identity Threat Detection and Response (ITDR) add-on (optional), which enhances the analytics baseline capabilities to include the Directory Infrastructure. This enables the detection of advanced attacks targeting Domain Controllers and other identity components.</p><p>In addition, the ITDR module integrates proactive capabilities by using attack surface management to identify and expose identity-related security flaws and vulnerabilities before they can be exploited.</p> | <ul><li><a href="/pages/ZfPu4iFKy1rZPOWW5Nuf">Enable the Analytics Engine and Identity Analytics</a></li><li><a href="/pages/9Xw7ZTTptUDOBt4byusb">Identity Analytics</a></li><li><a href="/pages/crlyXVF6hrT8Up8VQKBc">Identity Threat Module (ITDR)</a></li></ul>                                                                                                |

Your Cortex XSIAM is now operational and is collecting data.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/deployment-steps/cortex-xsiam-onboarding-checklist.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
