> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/configure-server-settings.md).

# Configure server settings

You can configure server settings such as keyboard shortcuts, timezone, timestamp format, and custom logos for communications task emails to create a more personalized user experience in Cortex XSIAM. Go to **Settings** → **Configurations** → **General** → **Server Settings**.

{% hint style="info" %}

### Note

Keyboard shortcuts, timezone, and timestamp format are not set universally and only apply to the user who sets them.
{% endhint %}

| Server Setting                                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ----------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Keyboard Shortcuts                              | Enables you to change the default shortcut settings. The shortcut value must be a keyboard letter, A through Z, and cannot be the same for both shortcuts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Timezone                                        | Select a specific timezone. The timezone affects the timestamps displayed in Cortex XSIAM, auditing logs and when exporting files.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Timestamp Format                                | <p>The format in which to display Cortex XSIAM data. The format affects the timestamps displayed in Cortex XSIAM, auditing logs and when exporting files.<br><br>This setting is configured per user and not per tenant.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Email Contacts                                  | A list of email addresses Cortex XSIAM can be used as a distribution list. The defined email addresses are used to send product maintenance, updates, and new version notifications. These addresses are in addition to the email addresses registered with your Customer Support Portal account.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Custom Logo                                     | <p>By default, the Cortex XSIAM logo displays on communication task emails. You can replace the default logo with a custom logo to match your organization's branding.<br><br>Supported file formats are PNG, JPEG, SVG, and GIF.<br><br>The minimum recommended image dimensions are 50px height and 50px width. The recommended maximum file size is 100 KB.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| AI Configuration                                | <ul><li>Enable or disable the Cortex Agentic Assistant (<strong>Agents & LLM Experience</strong>).</li><li>Enable or disable AI case summarization capabilities.</li></ul><p><strong>Note:</strong></p><ul><li>The Cortex Agentic Assistant and AI case summarization are currently available for users in limited regions. For more information, see Agentic AI in Cortex XSIAM.</li><li>For multi-tenant/MSSP environments, the Cortex Agentic Assistant and AI case summarization are not available in the main tenant.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Password Protection (for downloaded files)      | <p>Enable password protection when downloading retrieved files from an endpoint. This prevents users from opening potentially malicious files.<br><br>Administrator permissions required.</p><p><strong>Note:</strong> If the <strong>Password Protection (for downloaded files)</strong> setting under <strong>Settings</strong> → <strong>Configuration</strong> → <strong>General</strong> → <strong>Server Settings</strong> is enabled, enter the password 'suspicious' to download the file.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Google Maps Key                                 | Enter the Google Maps API key to display the physical location of an entity on a Google map.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Scope-Based Access Control (SBAC)               | <p>Enforces granular scoping on users with a scoping configuration. A user can inherit scoping configurations from a user group, or have the scoping configuration applied directly on top of the role assigned from either a user group or a generated API Key.<br><br>By default, <strong>Enable Scope Based Access Control</strong> is disabled and granular scoping is not enforced. Before enabling SBAC, we recommend that an administrator or a user with <strong>Access Management</strong> permissions first ensure that the users, user groups, and API Keys defined in Cortex XSIAM are granted the required access by assigning the relevant scopes. For more information, see Manage user scope.<br><br>(Optional) If enabled, you can select the <strong>Endpoint Scoping Mode</strong>, which is defined per tenant:</p><ul><li><strong>Permissive:</strong> Enables users with at least one scope tag to access the relevant entity with that same tag.</li><li><strong>Restrictive:</strong> Users must have all the scoped tags that are tagged within the relevant entity of the system.</li></ul> |
| Ingestion Evaluation Mode                       | Estimates your data sizing requirements for licensing purposes. When enabled, the system accepts, processes, and parses all your data to calculate ingestion metrics and populate the Ingestion and NGFW Ingestion Dashboards.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Data Ingestion Monitoring (Beta)                | <p>Data ingestion health monitors the availability and overall health of data collection. When enabled, Cortex XSIAM creates the following types of alerts:</p><ul><li><strong>Ingestion health alerts:</strong> Based on the data ingestion metrics and indicate disruptions in data collection</li><li><strong>Collection health alerts:</strong> Based on error statuses in collection integrations and indicate that a collector is not connected</li></ul><p>If you disable data ingestion monitoring, Cortex XSIAM continues to collect metrics, but alerts are not created.<br><br><strong>Related information</strong></p><ul><li>Use data ingestion health metrics in Cortex Query Language queries and to create correlation rules with your data ingestion logic. For more information, see Monitor data ingestion health.</li><li>View all health alerts on the Health Alerts page. For more information, see About health issues.</li></ul>                                                                                                                                                              |
| XQL Configuration                               | <p>Enables setting case sensitivity across Cortex XSIAM.<br><br>By default, this setting is set to <code>false</code> and field values are evaluated as case insensitive.<br><br>This setting overwrites any other default configuration except for BIOCs, which will remain case-insensitive no matter what this configuration is set to.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Define the cases target MTTR per issue severity | <p>Determines within how many days and hours you want issues resolved according to the issue severity <strong>Critical</strong>, <strong>High</strong>, <strong>Medium</strong>, and <strong>Low</strong>.<br><br>The defined MTTR is used to display the Resolved Issue MTTR dashboard widgets.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Impersonation Role                              | <p>The type of role permissions granted to the Palo Alto Networks Support team when opening support tickets. We recommend that role permissions be granted only for a specific time frame, and full administrative permissions be granted only when specifically requested by the Support team.<br><br>Role permissions include:</p><ul><li><strong>Read-only:</strong> Default setting; grants read-only access to your tenant.</li><li><strong>Support-related actions:</strong> Grants permissions to tech support file collection, dump file collection, investigation query, correlation rule, BIOC and IOC rule editing, alert starring, exclusion, and exception editing</li><li><strong>Full role permissions:</strong> No limitations are applied; grants full permissions to all actions and content on your tenant</li></ul><p><strong>Permission Reset Timeframe:</strong> Determines how long role permissions are valid.</p>                                                                                                                                                                            |
| Custom Content                                  | <ul><li><strong>Export all custom content:</strong> Exports custom content, such as playbooks and scripts as a content bundle, which you can import to another Cortex XSIAM tenant.</li><li><strong>Upload custom content:</strong> Imports custom content created from another Cortex XSIAM tenant.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Case display modes                              | Allow users the access the Cases page in legacy mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Caching                                         | <p>Improve performance on the Cases and Issues pages by enabling a temporary data cache.</p><p><strong>Note:</strong> In MSSP environments, this option is not available on the parent tenant.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Issues                                          | Create timer fields that display in the issues table and issue layouts. For more information, see Configure issue timer fields.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Indicators                                      | <p><strong>Note:</strong> Requires the TIM add-on.</p><p>By default, system-wide automatic indicator extraction and enrichment is disabled. However, if you migrated from Cortex XSIAM 2.x to Cortex XSIAM 3.x, system-wide automatic indicator extraction and enrichment is enabled.</p><p>If you have the TIM add-on, you can enable or disable system-wide automatic indicator extraction and enrichment from issues.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Unified Case View                               | <p><strong>Note:</strong> Requires an MSSP License and RBAC permissions to <strong>Cases & Issues</strong> and <strong>Investigation & Response</strong> → <strong>Automation</strong>. This setting is available for the parent tenant only.</p><p>Enable the <strong>Unified Case View</strong> to see a consolidated view of all cases across your distributed environment and perform actions on child tenants.</p><p>If this setting is disabled, the <strong>Cases</strong> page displays a single tenant at a time with a drop down list to move between tenants in read-only mode.</p><p>For more information, see Unified case view.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsiam/onboard-cortex-xsiam/post-deployment/configure-server-settings.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
