Configure Cortex Data Lake tier - Learn more about the Cortex Data Lake tier. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Learn more about the Cortex Data Lake tier.

Notice

The Cortex Data Lake tier is an optional add-on available only with an active Cortex XSIAM NG SIEM, Cortex XSIAM Enterprise, or Cortex XSIAM Premium license.

Prerequisite

  • Permissions: Requires View/Edit RBAC permissions for Data Management (under ConfigurationsData Management), the same permissions used for Dataset Management, parsing rules, data model rules, and event forwarding.

  • Minimum Ingestion: Requires a minimum of 50 GB/day for the Data Lake tier, provided the mandatory 100 GB/day Analytics tier minimum is met.

The Cortex Data Lake tier provides a cost-effective alternative for ingesting high-volume data that isn't required for real time security detection. While the Analytics tier is intended for real-time security and detection, the Cortex Data Lake tier allows you to maintain full visibility and searchability using Cortex Query Language (XQL) at a significantly lower cost.