XenXDR documentation

Install the platform, connect your sources, enrol endpoints and work the queue. Written for the analysts and operators who run XenXDR.

What XenXDR is

XenXDR is a detection and response platform that combines four things a security team usually buys separately:

  • a SIEM: one normalised store for every log source, with the original event preserved and a search interface built for investigation;
  • an endpoint agent for Windows and Linux that collects telemetry and acts on the host: isolate, kill, collect, shell;
  • a detection and automation layer: rules with a shipped content pack, correlation into incidents, playbooks that enrich, decide and respond, and advisory AI;
  • case management and reporting: alerts that escalate into cases, reports from templates, and a portal the customer can log into.

Run it on your own infrastructure or as a tenant FluenceSecurity hosts for you. It is multi-tenant by design, so a provider can serve many organizations from one deployment.

Who this documentation is for

SectionRead it if you
Getting startedInstall and configure the platform for the first time.
Endpoint agentRoll out, operate and troubleshoot the agent on your fleet.
Data sourcesConnect syslog, Beats, HTTP, Splunk HEC and cloud identity sources.
SearchWork the Logs page: query syntax, fields, keyboard, AI Hunt.
DetectionsWrite, import and tune rules; understand the content pack.
OperationsWork alerts, correlations, cases, SLA, reports and notifications.
AIUnderstand what the advisory layer does and how to point it at a model.
AutomationBuild playbooks and understand modes, ceilings and response actions.
FleetManage hosts and use the live response console.
AdministrationOrganizations, users and roles, audit, retention, backups, upgrades.
Customer portalGive your customers a view of their standing and reports.
ReferenceGlossary, support tiers, compatibility, catalogues.

Editions

EditionWhat runs where
Self-hostedYou run the whole stack on your infrastructure.
Hosted tenantFluenceSecurity runs a dedicated deployment for you in the EU.
ManagedFluenceSecurity's SOC operates the platform for you, on your tenant or theirs.

The documentation describes the platform as a product. Where a step only applies to self-hosted deployments, the page says so.

Conventions

  • Console labels are written as they appear: Settings › Organizations.
  • Keyboard shortcuts are written as keys: Ctrl K.
  • Field names use the canonical dotted form from the field dictionary: host.name, process.executable.
  • Version notes state the release the behaviour was introduced in.

Help

For anything these pages leave open, contact support through the customer portal.