> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/install-the-server-with-elasticsearch.md).

# Install the Server with Elasticsearch

Install Cortex XSOAR 6.15 with Elasticsearch. Review prerequisites and deployment steps for a new Elasticsearch-backed environment.

Elasticsearch is a distributed, open-source search and analytics engine for all types of data. It enables processing and storing large amounts of data. If you are using Elasticsearch as your database, all objects are stored in Elasticsearch.

{% hint style="info" %}
Working with Elasticsearch for only indicators or audit logs is not supported.
{% endhint %}

The following diagram depicts a Cortex XSOAR environment with Elasticsearch.

![Cortex XSOAR environment with Elasticsearch](https://content.gitbook.com/content/8xEMUKpU65o1wagTHaO3/blobs/4dHcx0yd13JpIAQ9O7ks/fde8f96c090a1cbdba6c9e36fae71be8215ecd2f91ea535eca523d6ecc6c7a1d.png)

{% hint style="info" %}
We recommend installing the **Elasticsearch Monitoring** content pack from Marketplace to monitor Elasticsearch. After installation, add the **Elasticsearch Monitoring** dashboard, which includes various widgets to monitor Elasticsearch cluster status and track statistics.
{% endhint %}

### Cortex XSOAR installation file structure

By default, the `.sh` file is in `/home/<user-name>`. The file installs `demistoserver_xxxxx.amd64.deb` in `/usr/local/demisto`. You can [change the default folder](/xsoar-6-administrator-guide/6.15/customize-cortex-xsoar/customize-and-configure-cortex-xsoar/manage-data/move-data-folders-to-another-location-on-the-server.md), if necessary.

For more information, see [Cortex XSOAR installation file structure](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/install-the-server-for-a-single-server-deployment.md#installation-file-structure).

### Prerequisites for installing Cortex XSOAR with Elasticsearch

Verify the following information and requirements before you install Cortex XSOAR with Elasticsearch.

* A Customer Support Portal account.

  Set up your account. For more information, see [How to Create Your CSP User Account](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClNVCA0).

  When you create an account, you can set up two-factor authentication using email, Okta Verify, or Google Authenticator for non-FedRAMP accounts. For more information, see [How to Enable a Third Party IdP](https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sZ8mCAE).
* Have the following roles assigned:

  | Role                         | Details                                                                                                                                                                            |
  | ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  | Customer Support Portal role | The Super User role is assigned to your account. The account creator is granted the Super User role.                                                                               |
  | Cortex role                  | If you are the first user to access Cortex Gateway with the Super User role, you are automatically granted Account Admin permissions. You can add Account Admin users as required. |

  After creating the account, log in to Cortex Gateway to download the image file and license. Downloading an image file from Cortex Gateway ensures you have the latest pre-configured software package for deployment and updates. If you have multiple or development tenants, repeat these tasks for each tenant.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>To download Cortex XSOAR images from Cortex Gateway, you must have a license, or an evaluation license through sales, assigned to your account.</p></div>
* Your deployment meets the [minimum system requirements](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/system-requirements.md).
* Your Elasticsearch deployment meets the [Elasticsearch System Requirements](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/elasticsearch/elasticsearch-setup/elasticsearch-system-requirements.md).
* You have root access.
* Elasticsearch 7.x is installed. Elasticsearch should not be installed on the same server as Cortex XSOAR.
* The production server has Python 2.7 or 3.x.

### Install Cortex XSOAR with Elasticsearch

{% stepper %}
{% step %}

### Download the installation package and license

1. Log in to [Cortex Gateway](https://cortex-gateway.paloaltonetworks.com/accounts).
2. In the **Available for Activation** section, use the serial number to locate the tenant to download. By default, the **Production-Standalone** license is selected. You can also select **Dev**.

   If you want to use a production and a development tenant with a private remote repository, select **Dev**. If you don't select it now, you can install a development tenant later.
3. Select **Download On Prem**.
4. Under **Choose Download Option**, select **Installer**.
5. Select the checkbox to agree to the license terms and conditions. Select **Download**.

{% hint style="info" %}
In Google Chrome, you may need to allow automatic downloads. Select **Settings** → **Privacy and security** → **Site settings** → **Additional permissions** → **Automatic downloads**. Select **Sites can ask to automatically download multiple files**.
{% endhint %}

Two files download: the `demistoserver-xxxxx.sh` installer file and a zipped JSON license file.

{% hint style="info" %}
Copy the download link button from your browser downloads to get the token for an offline installation.
{% endhint %}

6. Select **Next**.
7. Optional: If you deploy Cortex XSOAR using a signed installer (GPG), import the provided GPG public key.

   For example, run `rpm --import public.key` to import the public key into the local GPG keyring. Each operating system has specific requirements.
8. Optional: If you deploy Cortex XSOAR using a signed installer (GPG), you might need to install `makeself`. Run `yum install makeself`.
   {% endstep %}

{% step %}

### Make the server package executable

Run `chmod +x demistoserver-xxxx.sh` to make the `.sh` file executable.
{% endstep %}

{% step %}

### Run the installer

1. Run one of the following commands to install the app server with Elasticsearch:

   * For username and password authentication, run `sudo ./demisto.sh -- -elasticsearch-url=<elastic search url address> -elasticsearch-username=<the elasticsearch user name> -elasticsearch-password=<the elasticsearch password>`.
   * For API key authentication, run `sudo ./demisto.sh -- -elasticsearch-url=<elastic search url address> -elasticsearch-api-key=<the elasticsearch API key>`.

   Use the following flags:

   | Flag                       | Type    | Description                                                                                                     |
   | -------------------------- | ------- | --------------------------------------------------------------------------------------------------------------- |
   | `-elasticsearch-url`       | String  | Elasticsearch URL addresses, separated by commas. For example, `http://test1:9200,http://test2:9200`            |
   | `-elasticsearch-api-key`   | String  | Elasticsearch API key. If you use this flag, do not use `-elasticsearch-username` or `-elasticsearch-password`. |
   | `-elasticsearch-username`  | String  | Elasticsearch username. Use this flag with `-elasticsearch-password`. Do not use `-elasticsearch-api-key`.      |
   | `-elasticsearch-password`  | String  | Elasticsearch password. Use this flag with `-elasticsearch-username`. Do not use `-elasticsearch-api-key`.      |
   | `-elasticsearch-proxy=`    | Boolean | Whether to use a proxy for Elasticsearch. Use `true` or `false`. The default is `false`.                        |
   | `-elasticsearch-insecure=` | Boolean | Whether to trust any certificate for Elasticsearch. Use `true` or `false`. The default is `false`.              |
   | `-elasticsearch-timeout`   | Integer | Elasticsearch timeout in seconds. The default is 20 seconds.                                                    |
   | `-elasticsearch-prefix`    | String  | Unique prefix for Elasticsearch index names created by a Cortex XSOAR server.                                   |
2. Accept the EULA and provide the required information.
   {% endstep %}

{% step %}

### Verify the installation

After the installation completes, verify the following:

1. Run `systemctl status demisto` to confirm that the Cortex XSOAR server is active.

   If the server is not active, run `systemctl start demisto`.
2. Run `systemctl status docker` to confirm that the Docker service is active.
3. Open `https://<serverURL>:<port>` in a web browser to verify the installation.
   {% endstep %}

{% step %}

### Add the license

After installation completes, activate the license.

1. Log in to the Cortex XSOAR server.
2. Upload the **license** file that you downloaded from Cortex Gateway.

For more information, see [Add a License](/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/add-a-license.md).
{% endstep %}
{% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/xsoar-6-administrator-guide/6.15/onboard-cortex-xsoar/single-server-deployment/install-the-server-with-elasticsearch.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
