For the complete documentation index, see llms.txt. This page is also available as Markdown.

Plan and prepare

Before you get started with Cortex Data Security, consider the following deployment and data ingestion requirements to ensure a successful onboarding process.

Deployment considerations

  • Log Storage: Determine the amount of log storage you need for your Cortex Data Security deployment. Talk to your partner or sales representative to determine whether you must purchase additional storage within the Cortex Data Security tenant.

  • Region Selection: Determine the region in which you want to host Cortex Data Security and any associated services, such as Directory Sync Service. If you plan to stream data from a Strata Logging Service instance, it must be in the same region as Cortex Data Security. For more information, see Supported regions.

Data ingestion planning

Cortex Data Security enables you to ingest data from a wide range of third-party vendors and security services. During the onboarding process, you should identify the data sources and connectors you plan to use to ensure comprehensive visibility and protection.

Data sources and connectors typically fall into the following categories:

  • Cloud Service Provider (CSP) onboarding: Mandatory for initial onboarding to discover cloud assets and manage security posture. You must select and configure at least one CSP (AWS, Azure, GCP, or OCI) during the onboarding wizard.

  • Database as a Service (DBaaS): Ingest data from managed database services such as Databricks, MongoDB Atlas, or Snowflake.

  • Identity sources: Connect to identity providers like Okta, OneLogin, or Ping Identity to correlate user activities with data access.

  • On-Premise data collection: Collect data from on-premise log sources that are not necessarily tied to a specific vendor, typically using the Broker VM and its data collector applets, such as DSPM Fileshare and DSPM Database.

  • Data Security Threat Detection: Ingest logs and events from various security vendors to enable advanced threat detection and response, such as Google Workspace, Box, Dropbox, or Slack.

Configuring data sources

Detailed configuration steps, vendor-specific requirements, and supported ingestion methods, such as connectors or standard data sources, are maintained in a centralized vendor catalog.

Except for CSP Onboarding (which is integrated into the mandatory onboarding workflow), you should refer to the Cortex Data Security Data Sources and Connectors chapter for technical instructions on how to ingest data from specific third-party products. For a list of the entire vendor catalog, see the topics under Vendor-specific data sources and connectors.

Cloud scan planning

If you plan to onboard cloud accounts, decide on a scan mode before you start:

  • Cloud Scan (Recommended): Runs scanning in the Palo Alto Networks-managed environment with no additional setup or compute cost.

  • Outpost Scan: Runs scanning on infrastructure you host for data-residency or compliance requirements and requires additional cloud provider permissions and resources.

For a comparison of the two modes and guidance on when to choose Outpost Scan, see Outpost fundamentals and planning.

Last updated

Was this helpful?