Cortex XSIAM
Resources for Cortex XSIAM, Palo Alto Networks’ autonomous security platform powering the Modern SOC.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Cortex XSIAM

Welcome to the Cortex XSIAM LIVEcommunity! Explore how-to guides, best practices, and on-demand videos to help you get the most out of Cortex XSIAM. Have questions or insights to share? Join the conversation in our Discussions forums and connect with our Product Experts.

Stay in the loop—subscribe now to get the latest product updates delivered to you.

Articles

Cortex XSIAM Use Case Definition Template

06-16-2023 — Use Case Definition (UCD) Template This template will help you understand and leverage the UCD to benefit implementation strategy, understand how your Incident Response (IR) process fits into XSIAM, and identify integrations for ingestion/enrichment needed. The XSIAM Use Case Definition Templa... — Read more

Labels: Cortex XSIAM
991 published by in Cortex XSIAM Customer Articles
06-16-2023 edited by

Blogs

Guide to Onboard and Ingest logs from Firewalls  to Strata Logging Service and Cortex XSIAM

07-08-2025 — Guide to Onboard and Ingest logs from Firewalls to Strata Logging Service and Cortex XSIAM — Read more

Labels: Cortex XSIAM Log Forwarding Log Ingestion SCM SCM Pro SLS Strata Cloud Manager Strata Logging Service XSIAM
6832 1 by in Community Blogs

SecOps Insider-April Edition

04-30-2025 — Discover key insights from Sam Rubin, SVP of Consulting and Threat Intelligence at Unit 42, on the critical importance of cyber resilience highlighted in the 2025 Global Incident Response Report. Get recommendations for enhancing incident response... — Read more

Labels: Cortex Cortex XDR Cortex Xpanse Cortex XSIAM Cortex XSOAR Cybersecurity Prisma Cloud SecOps Security Operations Unit 42 XDR Xpanse
1607 by in Community Blogs

Threat Brief: CVE-2024-6387 OpenSSH RegreSSHion Vulnerability

07-15-2024 — On July 1, 2024, a critical signal handler race condition vulnerability was disclosed in OpenSSH servers (sshd) on glibc-based Linux systems. This vulnerability, called RegreSSHion and tracked as CVE-2024-6387, can result in unauthenticated remote... — Read more

Labels: Cortex XDR Cortex Xpanse Cortex XSIAM Cortex XSOAR CVE-2024-6387 Incident Response OpenSSH OpenSSH. RegreSSHion RegreSSHion Remote Code Execution security intelligence SOC SSH threat brief Threat Detection Vulnerability
20327 by in Community Blogs

Harnessing the Power of Cortex XSIAM for Enhanced File Management and Data Privacy

07-15-2024 — In an era where cybersecurity threats are evolving at a breakneck pace, Extended Detection and Response (XDR) solutions have emerged as the vanguard of defense for organizations. But what if we could extend the capabilities of the Cortex XSIAM sol... — Read more

Labels: Cortex XSIAM Endpoint Security Incident Response security intelligence SOC Threat Detection
3191 4 by in Community Blogs

What’s Next in Cortex - New Wave of Innovations in Cortex (June 2024 Release)

07-03-2024 — ith the ever evolving threat landscape, security operations teams require a new level of efficiency to protect their organizations. The latest release across Cortex products aims to solve a diverse set of challenges in security operations, all whi... — Read more

Labels: Cortex Cortex XDR Cortex Xpanse Cortex XSIAM Cortex XSOAR Release Notes XDR Xpanse XSIAM XSOAR
6801 by in Community Blogs

Discussions

Author Topic Views Replies
R_BhlpMe
01-19-2026

Cortex XSIAM XQL: How to find incidents where playbook failed / errored?

I’m new to Cortex XSIAM and XQL, and I’m still learning how things work. I need some help with an XQL query. I’m trying to create an XQL query where I... — Read more

posted in Cortex XSIAM Discussions

259 0
H.Pachpande430929
01-19-2026

How to Configure XQL to detect logs not reporting rule

I am able to retrieve logs successfully using XQL in Cortex XSIAM.However, I need to configure an analytics rule that triggers when any single expecte... — Read more

posted in Cortex XSIAM Discussions

348 0
A.Velusamy
01-19-2026

XSIAM Dashboard

Hi, I'm working on creating a dashboard for the concept below. Has anyone already tried this or have any insights they can share? sudden spike for ... — Read more

posted in Cortex XSIAM Discussions

354 0
j.chen644219
01-18-2026

Why do the same Windows Server data collected using XDRC and WEC agents show different statuses in the following fields?

Why do the same Windows Server 2022 std (Traditional Chinese) data collected using XDRC and WEC agents show different statuses in the following fields... — Read more

posted in Cortex XSIAM Discussions

549 0
Vinay_AS
01-06-2026

Does lookup or snapshot type dataset contributes to Hot storage

Hello Everyone, We have lot of lookup file and some snapshot type dataset in our environment. Does it contributes to hot storage. If so how can i ve... — Read more

posted in Cortex XSIAM Discussions

169 0

Digital Learning Courses

Access Palo Alto Networks learning platform to gain technical insights and educational materials across our full suite of products.

Please note: SSO login is necessary to access the content.

Videos