Learn

What you're actually paying for, in plain English.

Short explainers for Cortex XSIAM, written from your side of the table and grounded in the current Palo Alto Networks public docs and the Cortex marketplace. The vocabulary your partner assumes you know, the patterns the engine flags, and the negotiation language that fits each one. Each lesson cites its source and is dated.

Analytics versus rules4 min read

Correlation rules and Analytics rules are not the same product.

Buyers often pay for both because reps blur the line. Correlation rules are deterministic XQL queries you write or import. Analytics rules are platform-shipped detections built on machine learning. They solve different problems.

Read the lesson
Dashboards and widgets3 min read

Widgets and dashboards: almost always DIY-with-patience.

Cortex XSIAM ships predefined widgets, a Widget Library, and a dashboard builder with role-based access. Custom widgets use XQL queries or scripts. Most of the value can be built by your team in a workshop, not by a multi-week PS engagement.

Read the lesson
Data sources3 min read

If your log source is in the marketplace, you're not paying for parser work.

Palo Alto Networks runs a marketplace of pre-built integrations. If your source is in there, the parser is one click. Don't pay engineering hours for it.

Read the lesson
Data sources3 min read

Parsing rules: real engineering, but only sometimes.

Cortex XSIAM ships default parsing rules and an editor for writing custom ones in XQL. Most ingestion does not need bespoke parser work. The cases where it does are specific and worth full rate.

Read the lesson
Data sources7 min read

How parsing actually works in XSIAM: INGEST, XDM, raw datasets, and the data flow.

Every log byte that lands in your XSIAM tenant takes a specific path: collected by Broker VM or marketplace integration, transformed by parsing rules, normalized into XDM, and stored in the Cortex Extended Data Lake. Knowing the path makes it obvious which work is configuration and which is engineering.

Read the lesson
Detection content3 min read

OOTB rules enablement is a switch flip, not a project.

Cortex XSIAM ships hundreds of detection rules already mapped to MITRE ATT&CK. Most of the value of week one is enabling them, not authoring them.

Read the lesson
Detection content5 min read

How XSIAM detection actually fires: XQL triggers, real-time vs scheduled, and the alert pipeline.

Every detection in Cortex XSIAM is triggered by an XQL query, either continuously against the live data stream (real-time) or on a schedule. Understanding which one your rules use changes how you scope, tune, and pay for detection work.

Read the lesson
Detection content8 min read

What can fire in XSIAM: BIOCs, ABIOCs, Analytics, IOCs, and how they compare to a traditional SIEM.

In a traditional SIEM, every alert is a correlation rule you wrote. In XSIAM, alerts come from at least five distinct detection mechanisms running in parallel. Knowing which one fired (and why) is the difference between tuning the platform and fighting it.

Read the lesson
Licensing and SKUs5 min read

What Cortex XSIAM is, in plain language.

Cortex XSIAM is the AI-driven SOC platform Palo Alto Networks built to consolidate SIEM, EDR, XDR, SOAR, ASM, UEBA, and Threat Intel Management into one converged tenant. Knowing what's actually inside it is the foundation for reading any quote on this product.

Read the lesson
Licensing and SKUs6 min read

Cortex XSIAM tiers, ingestion economics, and what's bundled at each level.

Cortex XSIAM is sold in three tiers (NG-SIEM, Enterprise, Premium) with a shared ingestion baseline and add-on bundles. Knowing what's included at each tier lets you spot quotes that have you paying for things twice.

Read the lesson
Platform configuration3 min read

Broker VM standup and tenant config: documented, not bespoke.

The day-one work of a Cortex XSIAM rollout, deploying a Broker VM, registering it to your tenant, configuring NTP, network, and SSH, is published step-by-step in Palo Alto Networks docs. It is a runbook task with hard requirements, not custom engineering.

Read the lesson
Playbooks4 min read

Cortex AgentiX ships 1,300+ playbooks. You're paying to author the gaps, not the catalog.

Cortex AgentiX (the next generation of XSOAR, embedded in XSIAM) ships more than 1,300 playbooks and 1,000+ integrations. Most incident response workflows already have a working template. The work is tailoring the gaps, not authoring from scratch.

Read the lesson
Playbooks6 min read

How AgentiX playbooks are actually triggered: automation rules, jobs, and the WHEN/IF/THEN model.

In Cortex XSIAM, a playbook does not run by itself. Three things trigger it: automation rules (issue-driven), jobs (time or feed-driven), or a manual run. Understanding the trigger layer is the difference between automation that ships and automation that sits in a folder.

Read the lesson
Services scoping5 min read

Reading an XSIAM services SOW: what's runbook, what's engineering, what's Premium Success.

A typical XSIAM deployment SOW combines documented runbook work, real engineering, and Palo Alto Networks Premium Success services. Knowing which is which lets you negotiate each line on its own merits.

Read the lesson
Services scoping6 min read

When to bring a partner in: a decision matrix for Cortex XSIAM work.

Most XSIAM work splits cleanly into three buckets: do it yourself with the runbook, workshop with a partner and run it yourself, or pay a partner for full delivery. Here is the decision matrix.

Read the lesson

See it in your own quote.

Run a check and the engine will cite the lessons relevant to every line it flags. The pattern, the dollar consequence, and the script.

Have Clarify read your SOW