Data sources and supported services - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide

AIDR uses multiple data sources to gain visibility into AI usage in the cloud and identify AI-specific threats. Cloud audit logs are used for infra-level detections, such as model theft, denial of ML service, and training data poisoning. Cloud audit logs can be collected using existing data collectors. At this time, prompt logs are used to detect which models are being used.

See Collect prompt logs for instructions on configuring prompt log collection.

The following AI/ML managed services are supported:

  • AWS: Amazon Bedrock, SageMaker

  • Azure: Open AI

  • GCP: VertexAI