> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/learn-about-cortex-xsoar/readme.md).

# Navigate the Cortex XSOAR 6.15 Administrator Guide

Start here for a visual overview of the main Cortex XSOAR 6.15 documentation areas.

Use this page to jump into the right docs area fast.

### Learn about Cortex XSOAR

<table data-view="cards"><thead><tr><th>Topic</th><th data-card-target data-type="content-ref">Link</th></tr></thead><tbody><tr><td><i class="fa-play">:play:</i> Get Started in Cortex XSOAR<br>Explore core concepts, licenses, and essential product features.</td><td><a href="/xsoar-6-administrator-guide/6.14/learn-about-cortex-xsoar/get-started-in-cortex-xsoar.md">Get Started in Cortex XSOAR</a></td></tr><tr><td><i class="fa-calendar-days">:calendar-days:</i> Product Support Lifecycle<br>Learn about updates and EOL dates.</td><td><a href="/xsoar-6-administrator-guide/6.15/learn-about-cortex-xsoar/get-started-in-cortex-xsoar/product-support-lifecycle.md">Product Support Lifecycle</a></td></tr></tbody></table>

### Onboard Cortex XSOAR

<table data-view="cards"><thead><tr><th>Topic</th><th data-card-target data-type="content-ref">Link</th></tr></thead><tbody><tr><td><i class="fa-list-check">:list-check:</i> Deployment Checklist - Best Practices<br>Overview of the deployment process, including best practices for Cortex XSOAR 6.15 installation and maintenance.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/deployment-checklist-best-practices.md">Deployment Checklist - Best Practices</a></td></tr><tr><td><i class="fa-server">:server:</i> Single Server Deployment<br>Install, configure, upgrade, and maintain a Cortex XSOAR 6.15 single-server deployment.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment.md">Single Server Deployment</a></td></tr><tr><td><i class="fa-database">:database:</i> Elasticsearch<br>Deploy and manage Cortex XSOAR 6.15 with Elasticsearch, including setup, security, migration, backups, and troubleshooting.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/elasticsearch.md">Elasticsearch</a></td></tr><tr><td><i class="fa-box">:box:</i> Docker<br>Install, configure, secure, and troubleshoot Docker for Cortex XSOAR 6.15.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/docker.md">Docker</a></td></tr><tr><td><i class="fa-cubes">:cubes:</i> Podman<br>Install, configure, migrate to, and troubleshoot Podman for Cortex XSOAR 6.14 on RHEL 8 and later.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/podman.md">Podman</a></td></tr><tr><td><i class="fa-shuffle">:shuffle:</i> Proxy<br>Configure proxy, proxy bypass, and NGINX reverse proxy settings for Cortex XSOAR 6.15.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/proxy.md">Proxy</a></td></tr><tr><td><i class="fa-shield-halved">:shield-halved:</i> High Availability<br>Configure Cortex XSOAR 6.15 high availability with Elasticsearch, including sizing, migration, app servers, engines, and certificates.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/high-availability.md">High Availability</a></td></tr><tr><td><i class="fa-hard-drive">:hard-drive:</i> Disaster Recovery and Live Backup<br>Configure Cortex XSOAR 6.15 disaster recovery and live backup, including failover, backups, restores, and troubleshooting.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/disaster-recovery-and-live-backup.md">Disaster Recovery and Live Backup</a></td></tr><tr><td><i class="fa-users">:users:</i> Users and Roles<br>Manage Cortex XSOAR 6.15 users, roles, permissions, settings, shifts, passwords, and authentication.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/users-and-roles.md">Users and Roles</a></td></tr><tr><td><i class="fa-store">:store:</i> Marketplace<br>Browse Cortex XSOAR 6.15 Marketplace content packs, manage installations, and contribute content.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/marketplace.md">Marketplace</a></td></tr><tr><td><i class="fa-code-branch">:code-branch:</i> Remote Repositories in Cortex XSOAR<br>Configure Cortex XSOAR 6.15 remote repositories for content development, synchronization, and deployment.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/remote-repositories-in-cortex-xsoar.md">Remote Repositories in Cortex XSOAR</a></td></tr><tr><td><i class="fa-gears">:gears:</i> Engines<br>Install, manage, configure, and troubleshoot Cortex XSOAR 6.15 engines.</td><td><a href="/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/engines.md">Engines</a></td></tr></tbody></table>

### Customize Cortex XSOAR

<table data-view="cards"><thead><tr><th>Topic</th><th data-card-target data-type="content-ref">Link</th></tr></thead><tbody><tr><td><i class="fa-triangle-exclamation">:triangle-exclamation:</i> Incidents<br>Configure Cortex XSOAR 6.15 incident types, workflows, fields, layouts, and access controls.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/incidents.md">Incidents</a></td></tr><tr><td><i class="fa-diagram-project">:diagram-project:</i> Playbooks<br>Build and manage Cortex XSOAR 6.15 playbooks for security orchestration and response.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/playbooks.md">Playbooks</a></td></tr><tr><td><i class="fa-clock">:clock:</i> Jobs<br>Schedule Cortex XSOAR 6.15 playbooks with time-triggered and feed-triggered jobs.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/jobs.md">Jobs</a></td></tr><tr><td><i class="fa-stopwatch">:stopwatch:</i> Work with SLAs<br>Create and manage Cortex XSOAR 6.15 SLAs, timers, triggers, scripts, and risk thresholds.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/work-with-slas.md">Work with SLAs</a></td></tr><tr><td><i class="fa-brain">:brain:</i> Machine Learning<br>Use Cortex XSOAR 6.15 machine learning models for phishing classification and automation.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/machine-learning.md">Machine Learning</a></td></tr><tr><td><i class="fa-list">:list:</i> Lists<br>Create and manage Cortex XSOAR 6.15 lists for playbooks and automations.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/lists.md">Lists</a></td></tr><tr><td><i class="fa-crosshairs">:crosshairs:</i> Indicators<br>Manage Cortex XSOAR 6.15 threat indicators, including types, fields, extraction, enrichment, expiration, and feeds.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/indicators.md">Indicators</a></td></tr><tr><td><i class="fa-chart-line">:chart-line:</i> Dashboards<br>Create, customize, share, and manage Cortex XSOAR 6.15 dashboards and widgets for security operations data.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/dashboards.md">Dashboards</a></td></tr><tr><td><i class="fa-file-lines">:file-lines:</i> Reports<br>Create, customize, schedule, and troubleshoot Cortex XSOAR 6.15 reports for security operations data.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/reports.md">Reports</a></td></tr><tr><td><i class="fa-chart-pie">:chart-pie:</i> Widgets<br>Create, customize, and manage Cortex XSOAR 6.15 widgets for dashboards, reports, and security operations data.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/widgets.md">Widgets</a></td></tr><tr><td><i class="fa-database">:database:</i> Manage Data<br>Manage Cortex XSOAR 6.15 data with reindexing, archiving, migration, storage, and restoration procedures.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data.md">Manage Data</a></td></tr><tr><td><i class="fa-file-waveform">:file-waveform:</i> Logs<br>Configure Cortex XSOAR 6.15 server logs, access logs, audit trails, and diagnostic log bundles.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/logs.md">Logs</a></td></tr><tr><td><i class="fa-gear">:gear:</i> System Settings<br>Configure Cortex XSOAR 6.15 branding, login messages, system emails, and notification delivery settings.</td><td><a href="/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/system-settings.md">System Settings</a></td></tr></tbody></table>

### Investigate and Respond to Threats

<table data-view="cards"><thead><tr><th>Topic</th><th data-card-target data-type="content-ref">Link</th></tr></thead><tbody><tr><td><i class="fa-triangle-exclamation">:triangle-exclamation:</i> Incident Management<br>Open, investigate, manage, and resolve security incidents in Cortex XSOAR 6.15.</td><td><a href="/xsoar-6-administrator-guide/6.15/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/incident-management.md">Incident Management</a></td></tr><tr><td><i class="fa-crosshairs">:crosshairs:</i> Indicator Management<br>Create, search, edit, export, and manage threat indicators in Cortex XSOAR 6.15.</td><td><a href="/xsoar-6-administrator-guide/6.15/investigate-and-respond-to-threats/day-to-day-tasks-in-cortex-xsoar/indicator-management.md">Indicator Management</a></td></tr></tbody></table>

### Troubleshoot and Reference

<table data-view="cards"><thead><tr><th>Topic</th><th data-card-target data-type="content-ref">Link</th></tr></thead><tbody><tr><td><i class="fa-book">:book:</i> Reference Docs<br>Access configuration details, diagnostics, and technical reference material.</td><td><a href="/xsoar-6-administrator-guide/6.15/reference-docs/reference.md">Reference Docs</a></td></tr><tr><td><i class="fa-gears">:gears:</i> Server Configurations<br>Reference Cortex XSOAR 6.15 server configurations for customization, administration, and troubleshooting.</td><td><a href="/xsoar-6-administrator-guide/6.15/reference-docs/reference/server-configurations.md">Server Configurations</a></td></tr></tbody></table>

### Threat Intel Management

<table data-view="cards"><thead><tr><th>Topic</th><th data-card-target data-type="content-ref">Link</th></tr></thead><tbody><tr><td><i class="fa-crosshairs">:crosshairs:</i> Threat Intel Management<br>Manage indicators, threat intelligence feeds, and threat intel reports in Cortex XSOAR 6.15.</td><td><a href="https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/BpHpUTEMW1LJCAHPgrpq">Navigate the Threat Intel Management Guide</a></td></tr></tbody></table>

### Mult-Tenant

<table data-view="cards"><thead><tr><th>Topic</th><th data-card-target data-type="content-ref">Link</th></tr></thead><tbody><tr><td><i class="fa-users">:users:</i> Multi-Tenant<br>Configure and manage Cortex XSOAR multi-tenant deployments.</td><td><a href="/cortex-xsoar-8-on-prem/8.14/multi-tenant/what-is-cortex-xsoar-multi-tenant.md">What is Cortex XSOAR multi-tenant?</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/learn-about-cortex-xsoar/readme.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
