Manage Logging Storage for Cortex XDR
Cortex XDR licenses are based on Cortex Data Lake capacity. To view your licensed capacity, use the Customer Support Portal.
Cortex XDR licenses are purchased based on Cortex Data Lake capacity. Generally, this capacity is determined by factors such as the size of your network and number of endpoints in your deployment. To increase your capacity, contact your Palo Alto Network account representative.
When you activate your Cortex XDR apps, your log storage is unallocated. To allocate your log storage quota:
- Sign In to the Cortex hub at https://apps.paloaltonetworks.com/.
- Select your Cortex Data Lake instance.If you have multiple Cortex Data Lake instances, select the Cortex Data Lake tile and then select the Cortex Data Lake instance from the list of available instances associated with your account.Cortex Data Lake displays the service status and your total logging storage capacity.
- Select Configuration to define
logging storage settings.Cortex Data Lake displays the total storage allocated for the apps and services associated with the Cortex Data Lake instance. The Cortex Data Lake displays this information graphically and adjusts the graphic based on the storage policy you define below. The Cortex Data Lake storage policy specifies the distribution of your total storage allocated to each app or service and the minimum retention warning (not supported with Traps management service).
- Allocate quota for each app and service.Use the arrows to increment or decrement existing allocations or enter a new quota percentage.You cannot exceed 100% log storage allocation. If your total allocated quota is already at 100% for other non-Cortex XDR apps or services, reduce the quota for those apps or services to free up storage.
- If you purchased quota for firewall logs,
allocate quota to the Firewall log type.To use the same Cortex Data Lake instance for both firewall logs and Traps logs, you must first associate Panorama with the Cortex Data Lake instance before you can allocate quota for firewall logs.
- If you purchased quota for Traps logs, allocate quota
to the Traps log type.While the distribution of Traps logs depends on your storage needs, a good starting point is to allocate Traps logs as recommended for Traps management service. It’s recommended to review the status of your Cortex Data Lake instance after about two weeks of data collection and make adjustments as needed.
- Allocate quota to the Cortex XDR – Investigation
and Response log type.Because Cortex XDR – Investigation and Response alerts do not require a lot of storage, you typically need to allocate less than 1% of your total allocated storage.
- Allocate quota to the Cortex XDR – Analytics log
type.Cortex XDR – Analytics alerts also do not require a lot of storage, so you can similarly allocate less than 1% of your total allocated storage for analytics alert logs.
- If you purchased quota for firewall logs, allocate quota to the Firewall log type.
- Apply your changes.
Manage Logging Storage for Traps
Manage Logging Storage for Traps The Cortex Data Lake provides granular control over quota allocation for each type of log it receives. After you activate ...
Cortex XDR Configuration Overview With Cortex XDR you can use a variety of sensors to integrate all your network, endpoint, and cloud data. For the ...
Set Up Cortex XDR
Set Up Cortex XDR Cortex XDR Configuration Overview Everything You Need to Configure Cortex XDR Review the prerequisites for setting up Cortex XDR apps. Manage ...
Activate Cortex XDR Apps
Activate Cortex XDR Apps Use the Palo Alto Networks Cortex hub ( https://apps.paloaltonetworks.com ) to activate your Cortex XDR apps. This is a one-time task ...
View Cortex Data Lake Status
View Cortex Data Lake Status The Cortex Hub allows you to confirm that your service is provisioned in the region you chose when you activated ...
Configure Log Storage Quota on the Cortex Data Lake
Configure Log Storage Quota on the Cortex Data Lake You must set the log storage quota for each log type on the Cortex Hub. By ...
Activate Cortex Data Lake on the Cortex Hub
Activate Cortex Data Lake on the Cortex Hub If are using the Traps management service to secure your endpoints, all logs generated by the Traps components are ...
Cortex Data Lake License Activation
Determine whether to you need to activate your Cortex Data Lake (formerly called the Logging Service) license on the CSP or on the Cloud Services ...
Everything You Need to Configure Cortex XDR
Review the prerequisites for setting up Cortex XDR apps. ...