To create a baseline for enabling Analytics,
Cortex
XDR
requires a minimum
set of data; EDR or Network logs from at least 30 endpoints over
a minimum of 2 weeks or cloud audit logs over a minimum of 5 days.
Once this requirement is met,
Cortex
XDR
allows to enable analytics and begin
triggering alerts within a few hours.