XSIAM Command Center - See a dynamic overview of the current status of your tenant and your security operations processes on the XSIAM Command Center. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-16
Category
Administrator Guide
Abstract

See a dynamic overview of the current status of your tenant and your security operations processes on the XSIAM Command Center.

The XSIAM Command Center dashboard provides a dynamic overview of your security operations processes, and supports drilldowns to additional dashboards and dedicated pages. The dashboard gives a visualization of the current status of your tenant and its activity during the selected time frame. Click on any element to drill down to dashboards or pages displaying data that is filtered by your selection.

In addition, click on Cortex Agentic Assistant to open a dashboard detailing how Cortex XSIAM uses AI Agentic technology in your environment. For more information, see Cortex Agentic Assistant.Cortex Agentic Assistant

XSIAM_Command_Center-Platform.png

The XSIAM Command Center includes incoming data, cases, and issues, and key performance indicators. The following table describes each of these sections:

Section

Details

Incoming data

  • Number of connected Cortex XDR agent endpoints providing EDR data.

  • Data source instances grouped by integration and ordered by ingestion volume. Integrations shown in red indicate there is currently an error.

Click on any of these items to explore your Data Inventory. Breakdowns of data ingestion by data source, including ingestion rates, trends, and prevented events, are displayed.

Cases and issues

  • The number of issues opened during the time frame.

  • The number of cases that were created in response to the issues.

    Cases are split into manual cases and automated cases, where automated cases contain at least one playbook. You can also see the number of resolved cases and open cases broken down by severity.

Click on any of the case metrics to open the Cases Overview , showing a breakdown of your cases. You can also click on the concentric circle to see a live feed of Cortex XSIAM activity on the Dynamic View.

Key performance indicators

  • The amount of data and events ingested during the time frame and the ingestion rate.

  • The number of currently open cases broken down by severity. This number represents all open cases on the system, and is not time frame specific.

  • The number of attacks prevented by Cortex XSIAM during the time frame.

Click on the key performance indicators to drill down to dedicated pages for further investigation. You can also click Start Investigation to open the Cortex Agentic Assistant with useful prompts to aid you in the investigation process.

The trend percentages for the key performance indicators are calculated by comparing the totals from the current time frame with the totals of the previous time frame. An arrow indicates whether the rates are rising or falling in comparison to the previous time frame's total.

From the XSIAM Command Center, you can drill down to the following dashboards: