Engine requirements
Hardware, OS, and required URLs for engines.
Last updated
Was this helpful?
Hardware, OS, and required URLs for engines.
You can install engines on all Linux environments. Docker/Podman needs to be installed before installing an engine. If you are using the shell installer for an engine, Docker/Podman is installed automatically.
If your hard drive is partitioned, we recommend a minimum of 50 GB for the /var partition.
CPU
8 CPU cores
16 CPU cores
CPU architecture
x86_64 only
x86_64 only
Memory
16 GB RAM
32 GB RAM
Storage
100 GB
100 GB
If using Podman, we recommend reserving 150 GB for container storage, either in the /home partition or a different storage directory that you have set using the rootless_storage_path key. For more information, see Change container storage directory.
You can deploy an engine on the following operating systems:
Ubuntu
18.04, 20.04, 22.04, 24.04
RHEL
8.x, 9.x, 10.x
Includes all minor versions.
Oracle Linux
7.x, 8.9, 9.3, 9.4, 9.5, 10.1
Amazon Linux
2, Amazon Linux 2023
Rocky Linux
9.5, 9.6
CentOS 8.x reached End of Life (EOL) on December 31, 2021, and is no longer supported as an operating system.
CentOS 7.x reached End of Life (EOL) on June 30, 2024, and is no longer supported as an operating system.
You need to allow the following in the URLs for the engines to operate properly. The URLs are needed to pull container images from public Docker registries.
The endpoint URL is: wss://api-<tenant domain>.crtx.<region>.paloaltonetworks.com/xsoar/d1ws. For example, wss://api-my-tenant.crtx.us.paloaltonetworks.com/xsoar/d1ws
If you have configured a range of Approved IP Ranges under Allowed Sessions on the Security Settings page, the engine must communicate through one of the approved IPs.
Integrations
Integration-specific ports
Outbound
Engine connectivity
HTTPS
443 (configurable)
Outbound
Docker/Podman
https://registry-1.docker.io
https://registry.fedoraproject.org
https://registry.access.redhat.com
https://docker.io
https://registry.docker.io
https://docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.com
https://auth.docker.io
This URL may change according to Docker’s discretion.
https://production.cloudflare.docker.com
This URL may change according to Docker’s discretion.
Note
Docker URLs may change. For the current list, see https://docs.docker.com/desktop/setup/allow-list/. Note that some URLs in the allow list are for Docker Desktop and are not required for Cortex XSOAR.
443
Outbound
Last updated
Was this helpful?
Was this helpful?
