> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline.md).

# Install the Server Offline

Install Cortex XSOAR 6.15 in an offline or air-gapped environment without internet access.

You need to download the required Cortex XSOAR dependencies, the Cortex XSOAR installer, license files, and Docker images from an internet-connected machine. Then transfer these files to the offline server and install the dependencies, Cortex XSOAR, and Docker images.

If you are deploying a signed installer:

* You need to import the public key into the operating system. Open a [ticket](https://support.paloaltonetworks.com/Support/Index) with Palo Alto Networks support to get the public key. It is valid for six months.
* If you are using engines or hosts in a multi-tenant environment, you need to install `makeself`.

{% hint style="info" %}

* Download the latest dependencies for your Cortex XSOAR release before installation. Dependencies can change between releases./
* Steps vary by operating system.
* Docker or Podman runs Python scripts in an isolated container.
* After installation, [add a license](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/add-a-license.md).
  {% endhint %}

### Prerequisites for installing Cortex XSOAR

Verify the following requirements before you install Cortex XSOAR:

* You have a Customer Support Portal account.

  Set up your account. For more information, see [How to Create Your CSP User Account](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNVCA0).

  You can configure two-factor authentication using email, Okta Verify, or Google Authenticator. For more information, see [How to Enable a Third Party IdP](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZ8mCAE).
* You have the following roles:

  | Role                         | Details                                                                                                                                                     |
  | ---------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | Customer Support Portal role | The Super User role is assigned to your Customer Support Portal account. The account creator receives this role.                                            |
  | Cortex role                  | You must have the Account Admin role. The first user who accesses Cortex Gateway with the Super User role receives Account Admin permissions automatically. |

  Log in to Cortex Gateway to download the image file and license.

  If you have multiple or development tenants, repeat these tasks for each tenant.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>You need a license, or an evaluation license through sales, assigned to your Customer Support Portal account to download the Cortex XSOAR images.</p></div>
* Your deployment meets the [System Requirements](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/system-requirements.md).
* You have root access.

### Install Cortex XSOAR offline

{% stepper %}
{% step %}

### Download the required dependencies

1. On a machine with internet access, download the [required dependencies](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline/dependencies-for-offline-installation.md) for your deployment type.

* **Ubuntu/Debian**: Run `sudo apt-get install --download-only <package>` , which saves the package and its dependencies in `/var/cache/apt/archives`.\
  If the latest package version is already installed, run `sudo apt-get download <package>`.\
  The command saves the package in your current directory.\
  If you need to download dependencies on Ubuntu, you can also use the command `sudo apt-get download`.
* **RHEL/Rocky/Oracle/Amazon**: Run `sudo yumdownloader --resolve <package>` or `sudo yum install --downloadonly <package>`.

2. Copy all `.deb` files over to the offline machine into a folder.
   {% endstep %}

{% step %}

### Download the installation files

On a machine with internet access, do the following:

1. Log in to [Cortex Gateway](https://cortex-gateway.paloaltonetworks.com/accounts).
2. Locate the activation card for your license.

   By default, the **Production-Standalone** license is selected. You can also select **Dev**. To use production and development tenants with a private remote repository, select **Dev**. You can install a development tenant later.
3. Select **Download On Prem**.
4. Select **Next**.
5. Under **Choose Download Option**, select **Installer**.
6. Select the checkbox to agree to the license terms and conditions. Then select **Download**.

{% hint style="info" %}
In Google Chrome, configure **Settings** → **Privacy and security** → **Site settings** → **Additional permissions** → **Automatic downloads**. Select **Sites can ask to automatically download multiple files**.
{% endhint %}

The installer file, `demistoserver-xxxxx.sh`, and a zipped JSON license file download.

{% hint style="info" %}
Copy the download link from your browser's **Downloads** section. The link contains the token needed for downloading Docker images.
{% endhint %}

7. If you use a signed installer, import the provided GPG public key. Open a [support ticket](https://support.paloaltonetworks.com/Support/Index) to get the public key.

   For example, run `rpm --import public.key` to import the key into the local GPG keyring. Follow the requirements for your operating system.
8. If you use a signed installer, install `makeself` when required. For example, run `yum install makeself`.
   {% endstep %}

{% step %}

### Download Docker images

While the Cortex XSOAR installer sets up Docker automatically, it does no**t** include the images required to run integrations. You must obtain them manually. On a machine with internet access, do one of the following:

* **Targeted Download (Recommended)**: Use the `download_packs_and_docker_images.py` script to download the Docker image according to the content pack integration you want to use, such as AWS-ILM, Cybereason, and EWS.\
  The script is located in the `Utils` folder in the GIT Content repository. If you do not have access to the GIT Content repository, you can download the script from [here](https://raw.githubusercontent.com/demisto/content/master/Utils/download_packs_and_docker_images.py). For detailed information and how to download the Docker images, see [download packs offline](https://xsoar.pan.dev/docs/reference/articles/download-packs-offline). This is the preferred method as it allows you to download only the images for the specific content packs you plan to use.
* Full Library download: Download the Docker images by appending `downloadName=dockerimages` to the download URL you copied from the installer download. For example: `https://download.demisto.com/download-params?token=xxxxxxx email=user@paloaltonetworks.com downloadName=dockerimages eula=accept`\
  The Docker images file is approximately 75 GB.
  {% endstep %}

{% step %}

### Transfer and verify downloaded files

1. On a machine with internet access, transfer the files downloaded in steps 1 to 3.
2. Install all dependencies:
   * **Ubuntu/Debian**: `sudo dpkg -i *`
   * **RHEL/Rocky/Oracle/Amazon Linux**: `sudo yum localinstall *`
     {% endstep %}

{% step %}

### Install Cortex XSOAR

The Cortex XSOAR shell installer automatically installs and configures the container (Docker for most Ubuntu, RHEL 8+, Rocky Linux 9+, and Amazon Linux 2023 using the dependencies you installed in Step 4.

{% hint style="warning" %}
For Oracle Linux and Amazon Linux 2, install Docker before running the installer.
{% endhint %}

Run the following commands:

* `chmod +x demisto.sh`
* `sudo ./demisto.sh -- -tools=false -do-not-start-server=true`\
  Note: For multi-tenant, also include the `-multi-tenant` flag.
  {% endstep %}

{% step %}

### Load Docker images

* (Ubuntu, Oracle, and Amazon 2/2023 (Docker) Run the following command:

  `sudo docker load -i <YOUR_DOCKER_FILE>.tar`
* (Red Hat v8+ and Rocky Linux 9+ (Podman) Do the following:
  1. Ensure the file is owned by the `demisto` user: `sudo chown demisto:demisto <FILENAME>.tar`
  2. Ensure that you are in the root directory (`cd /`).
  3. Run the following command:

     `sudo -su demisto podman load -i <PATH TO FILE>/<FILENAME>.tar`
  4. (Optional) To verify that images can run, use the `podman images` command. You can also run the `podman images -q "demisto/python:1.3-alpine"` command to validate specific images and identify any issues.
     {% endstep %}

{% step %}

### Start Cortex XSOAR

Run the following command:

`sudo systemctl start demisto`
{% endstep %}

{% step %}

### Verify the installation

1. Confirm that the Cortex XSOAR server status is active by running:\
   `systemctl status demisto` command.
2. (Ubuntu, Oracle, and Amazon 2/2023) Confirm that the Docker service status is active by running the `systemctl status docker` command.
3. In a web browser, go to the `https://serverURL:port` to verify that Cortex XSOAR was successfully installed.

   When you open Cortex XSOAR for the first time, you need to add the license.
   {% endstep %}
   {% endstepper %}

### Troubleshoot offline installation

If you receive the following message, ensure you use a version of Podman that supports archives with multiple images.

`Error: error pulling "": unable to pull dir:./xsoar_docker_images.tar: error determining pull goal for image "dir:./xsoar_docker_images.tar": error parsing dest reference name "localhost/./xsoar_docker_images.tar": error parsing named reference "localhost/./xsoar_docker_images.tar": invalid reference format`

### Next steps

After you complete the installation, you might need to:

* Turn off Marketplace synchronization.

  See [Configure the Marketplace for Offline Installation](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/marketplace/install-a-content-pack-offline/configure-the-marketplace-for-offline-installation.md).
* Download content packs offline.

  See [Download Content Packs and Docker Images Offline](https://xsoar.pan.dev/docs/reference/articles/download-packs-offline) and [Install a Content Pack Offline](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/marketplace/install-a-content-pack-offline.md).

  Watch this video for information about installing content in an air-gapped environment. [Install XSOAR Content in Air-Gapped Environments](https://www.youtube.com/watch?v=sTvSUFeZI3I)
* (Optional) Install an engine offline.

  See [Install a Cortex XSOAR Engine Offline](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/engines/engine-installation/install-a-cortex-xsoar-engine-offline.md).
* (Informational) Set relevant server configurations.

  See [Reference](/xsoar-6-administrator-guide/6.15/reference-docs/reference.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/install-the-server-offline.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
