What XenXDR is
XenXDR is a detection and response platform that combines four things a security team usually buys separately:
- a SIEM: one normalised store for every log source, with the original event preserved and a search interface built for investigation;
- an endpoint agent for Windows and Linux that collects telemetry and acts on the host: isolate, kill, collect, shell;
- a detection and automation layer: rules with a shipped content pack, correlation into incidents, playbooks that enrich, decide and respond, and advisory AI;
- case management and reporting: alerts that escalate into cases, reports from templates, and a portal the customer can log into.
Run it on your own infrastructure or as a tenant FluenceSecurity hosts for you. It is multi-tenant by design, so a provider can serve many organizations from one deployment.
Who this documentation is for
| Section | Read it if you |
|---|---|
| Getting started | Install and configure the platform for the first time. |
| Endpoint agent | Roll out, operate and troubleshoot the agent on your fleet. |
| Data sources | Connect syslog, Beats, HTTP, Splunk HEC and cloud identity sources. |
| Search | Work the Logs page: query syntax, fields, keyboard, AI Hunt. |
| Detections | Write, import and tune rules; understand the content pack. |
| Operations | Work alerts, correlations, cases, SLA, reports and notifications. |
| AI | Understand what the advisory layer does and how to point it at a model. |
| Automation | Build playbooks and understand modes, ceilings and response actions. |
| Fleet | Manage hosts and use the live response console. |
| Administration | Organizations, users and roles, audit, retention, backups, upgrades. |
| Customer portal | Give your customers a view of their standing and reports. |
| Reference | Glossary, support tiers, compatibility, catalogues. |
Editions
| Edition | What runs where |
|---|---|
| Self-hosted | You run the whole stack on your infrastructure. |
| Hosted tenant | FluenceSecurity runs a dedicated deployment for you in the EU. |
| Managed | FluenceSecurity's SOC operates the platform for you, on your tenant or theirs. |
The documentation describes the platform as a product. Where a step only applies to self-hosted deployments, the page says so.
Conventions
- Console labels are written as they appear: Settings › Organizations.
- Keyboard shortcuts are written as keys: Ctrl K.
- Field names use the canonical dotted form from the field dictionary:
host.name,process.executable. - Version notes state the release the behaviour was introduced in.
Help
For anything these pages leave open, contact support through the customer portal.