For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XSOAR 8 (SaaS)

Sync content to child tenants

Synchronize Cortex XSOAR 8 SaaS content from the main tenant to child tenants in a multi-tenant deployment.

The content that you sync from the main tenant to the child tenants might add, override, or remove content from the child tenants. New content items, that do not currently exist on the child tenants, are added. When you sync content to child tenants, there can potentially be content items added.

Option
Description

Add

New content items that do not currently exist on the child tenants will be added.

Override

For content items that are being pushed in the sync operation and that already exist on the child tenants, the sync operation overrides the existing content on the child tenants

Remove

For content items that were removed from the main tenant and which already exist on the child tenants, the sync operation removes the existing content from the child tenants.

You should review each content item and its dependencies before syncing the content. You have the option to remove items before executing the sync operation for a single tenant.

Before you begin

  • Ensure that your user roles have view or view/edit permission to sync to child tenants. For more information, see Configurations.

  • Add propagation labels to child tenants.

  • Add propagation labels to content.

How to sync content

  1. On the main tenant, go to Settings & InfoSettingsTenant Management.

  2. Select the tenant you want to sync.

    If you select one tenant, you can review which content sync. If you select two or more tenants, you can't review the content before syncing.

  3. Select one of the following options to sync content.

    • To review the content before syncing to a child tenant, select a child tenant, and click Sync.

      1. Review all content affected by the sync operation in the ADD, OVERRIDE, and REMOVE tabs.

      2. If there are playbooks listed in the OVERRIDE tab, select or clear the checkbox to Override playbook inputs in the child tenant.

      3. If the Run on field has changed in the script, select or clear the Overwrite script run-on to override this field in the child tenant.

    • To sync content to child tenants without manual review, select two or more child tenants and then click Sync.

      This option automatically updates new, and existing content to the child tenant, and removes outdated content. If there are playbooks and scripts, select or clear the checkbox to Override playbook inputs and script run-on-settings in the child tenant.

  4. Click Sync.

If you sync a content item from the main tenant to a child tenant, and a content item with that same name already exists on the child tenant, the content on the child tenant is overwritten. This applies to integrations, fields, incident types, and Threat Intel report types.

Last updated

Was this helpful?