Skip to main content
Use notebooks to gather information from multiple pages in Palo Alto Networks Cortex XCOR. When you’re troubleshooting a problem, you might need graphs, charts, and other resources to review at the same time. Notebooks let you gather these resources in one place for ease of review.
Accounts with the None role can open and view notebooks. To create, edit, or delete a notebook, your account must be a member of a team with the Editor, SysAdmin, or User Administrator role.
Open and edit notebooks from the list, a full-screen view, or the side panel: The notebooks list and side panel edit the same notebooks, so changes you make in one place appear in the other.

View the notebooks list

To display the list of notebooks, in the navigation menu, select Notebooks. The list fills the main window. While you’re on this page, Cortex XCOR closes the notebook side panel and disables the N shortcut until you leave. By default, the table lists notebooks in your personal collection and in collections you can access. Notebooks in another user’s personal collection, such as one you opened from a shared link, are hidden until you turn on Show other users’ notebooks. Use the following controls on the notebooks list.
  • Create notebook opens a new notebook in a full-screen view when your account can create notebooks (see the Note at the top of this page). See Create a notebook. The button doesn’t appear on the list when you only have view access.
  • Search notebooks filters the list by notebook name, owner, or category.
  • Show only my notebooks lists only notebooks in your personal collection. While this switch is on, Show other users’ notebooks is hidden.
  • Show other users’ notebooks also lists notebooks in other users’ personal collections. This switch appears only when Show only my notebooks is off.
Each row displays the notebook Name, its Owner, Category (when set), the Date modified, and when you Last viewed it. The list is sorted by Last viewed by default. The Owner column identifies the collection that owns the notebook. For a personal collection, Cortex XCOR shows the owner’s email address and avatar. Your own personal collection is labeled (me). Owner also links to the collection or personal collection home page. Click a notebook’s Name to open it in a full-screen view. To manage a notebook from the list, click the three vertical dots icon in its row and select an action.

Notebooks on a collection home page

Each collection home page includes a Notebooks section that lists notebooks owned by that collection. Use it for a quick view of notebooks tied to a team or feature. View all on the collection home page opens the same list as Notebooks in the navigation menu. Cortex XCOR doesn’t pre-filter the list to that collection. To find notebooks for one collection, use one of the following methods on the notebooks list.
  1. Enter the collection name in Search notebooks. Search matches notebook names, owners, and categories.
  2. Locate the collection in the Owner column.
Click an Owner link on the notebooks list to open that collection’s home page.

Open a notebook in a full-screen view

When you open a notebook from the notebooks list, it fills the page. A full-screen notebook includes the formatting toolbar, a time range selector, an Editing or Viewing mode control, Copy as Markdown, Snapshot all panels (in Editing mode when the notebook has panels to snapshot), Notebook settings, and Version history. The page shows the notebook Name, Owner, and Category (when set) under the toolbar. In Editing mode, click the name to rename it inline. In Viewing mode, the name is read-only. Notebooks in your personal collection open in Editing mode. Notebooks owned by another user or by a collection open in Viewing mode. Switch to Editing to change content, rename the notebook, or update Collection in Notebook settings. To delete a notebook, use Notebook settings. Use the Notebooks breadcrumb to return to the list. Opening a notebook in full screen closes the notebook side panel if it was open. Closing the full-screen notebook restores the side panel.

Set a notebook category

To classify a notebook, open Notebook settings in a full-screen view while the notebook is in Editing mode. Select a Notebook category and click Save.
  • None removes the category.
  • Documentation, Investigation, Postmortem, Report, and Runbook label the notebook for filtering and display.
On the notebooks list, categorized notebooks show a Category chip in their row. In a full-screen notebook, the same chip appears next to Owner when a category is set.

Notebook side panel

The notebook side panel opens over any page in Cortex XCOR so you can gather resources without leaving your current context. Cortex XCOR displays the last notebook you accessed, and your open notebook stays visible as you move between pages.

Open a notebook

Click the Notebook icon in the page header, between pinned scope and search, or press N. The notebook side panel opens on the right side of the page. The N shortcut is disabled on the notebooks list and full-screen notebook pages. After the notebook opens, see Notebook header for full-screen, create, share, and version history controls. Side panel notebooks often use a narrow header.

Switch notebooks

To switch notebooks or find a notebook you opened recently:
  1. Click Select a notebook in the notebook header.
  2. If needed, enter a name in Search or use Show only my notebooks and Show other users’ notebooks. The menu uses the same visibility switches as the notebooks list.
  3. Click a Name in the table to open the selected notebook. The open notebook is labeled (current). Each row also displays Owner, Last viewed, and row actions to Share or Delete.

Notebook header

The top of the notebook side panel provides controls to view the notebook in a full-screen view, open its version history, copy the notebook as Markdown, copy its URL, and create a notebook. The next row includes the formatting toolbar and an Editing or Viewing mode control. Cortex XCOR shows these controls as separate icon buttons or groups them in a menu, depending on the width of the notebook header row. The layout switches at 360 pixels. When the header row is narrower than 360 pixels, Cortex XCOR uses a narrow header. When the row is 360 pixels or wider, it uses a wide header. Resizing the notebook panel or using a long notebook name can change the header width and switch between layouts. Use the tab that matches what you see:
In a narrow header, these actions are grouped in one menu.
  1. Click the three vertical dots icon in the notebook header.
  2. Select an action.

Notebook ownership and sharing

Every notebook belongs to a collection. Notebooks you create are stored in your personal collection by default. To store a notebook with a team or feature instead, open the notebook in a full-screen view, switch to Editing mode if needed, open Notebook settings, and select a different Collection. You can also set a Notebook category there. See Set a notebook category. You can’t move a notebook from a shared collection back into a personal collection from the UI. Notebooks can’t be owned by services. Other users don’t see notebooks in your personal collection unless you share a link. When someone opens a link you share, the notebook opens in their notebook panel and appears in their notebooks list after they turn on Show other users’ notebooks when the notebook stays in your personal collection. Collection-owned notebooks appear on the collection’s home page and in the notebooks list by default.

Share a notebook

To share a notebook, copy its URL using one of the following controls.
  • In the notebooks list, open the row’s three vertical dots menu and click Copy Link.
  • In the side panel, click Copy URL in the notebook header. If Copy URL isn’t visible, click the three vertical dots icon, and then click Copy URL. See Notebook header for both header layouts.
  • In Select a notebook, open the row menu and click Share. Share copies the same URL as Copy Link on the notebooks list.

Use Markdown with notebooks

Copy a notebook’s contents to the clipboard as Markdown, or paste Markdown into an editable notebook. Cortex XCOR doesn’t support importing or uploading Markdown files.

Copy a notebook as Markdown

Use the control for the notebook view:
  • In a full-screen notebook, click Copy as Markdown in the toolbar.
  • In a wide side panel header, click Copy as Markdown.
  • In a narrow side panel header, click the three vertical dots icon, and then click Copy as Markdown.
The action copies the notebook body to the clipboard. Paste the contents into a text editor and save the file with an .md extension if you need a Markdown file. The copied Markdown doesn’t include the notebook name, collection, owner, version history, or notebook-wide default time range. A panel-specific time range remains part of that panel’s definition.

Create a notebook from Markdown

  1. Create a notebook, or open an existing notebook that you can edit.
  2. Copy the Markdown source from your .md file or text editor.
  3. Click where you want to add the content in the notebook body. Select existing content first if the pasted Markdown should replace it.
  4. Paste with Control+V (Command+V on macOS).
Cortex XCOR converts Markdown that contains a block element, such as a heading, list, block quote, fenced code block, table, horizontal rule, or details block. Markdown that contains only inline syntax might paste as literal text.

Markdown content and round trips

Notebook content maps to Markdown in the following ways:
  • Free-form content uses standard Markdown for paragraphs, headings, bold and italic text, strike-through text, inline code, links, line breaks, lists, block quotes, code blocks, horizontal rules, tables, and task lists. Mermaid diagrams use mermaid code fences.
  • Visualization panels use chrono-VizPanel code fences containing the panel definition as JSON. The definition includes the queries, display options, and any panel-specific time range. Pasting the fence restores an interactive panel that runs its queries, preserving the fence and its JSON without modification.
  • Entity link cards become standard Markdown links. Pasting a recognized Cortex XCOR entity URL restores the link card. An entity without a supported URL becomes plain text.
  • A snapshot uses the same chrono-VizPanel representation and retains its snapshot identifier, but not the captured query data. The imported panel remains a snapshot only where that identifier is available.
Most supported content survives copying and pasting through Markdown. These structures change during conversion:
  • Merged table cells expand into individual cells, multi-paragraph cells flatten onto one line, and column alignment normalizes.
  • Images become linked alt text because notebooks don’t have an image block.
  • Underlined text loses its underline. Inline code retains its code formatting but loses overlapping bold, italic, or link formatting on the same text.
  • Unknown notebook content becomes its fallback text, descendant text, or an Unsupported notebook content label.
  • Copying Markdown to another tenant doesn’t copy referenced entities, snapshots, or query data.

View version history

To view the history of changes for a notebook, click Version history. In the side panel, if Version history isn’t visible, click the three vertical dots icon in the notebook header, and then click Version history. See Notebook header for both header layouts. Click Version history to display a panel with two tabs:
  • Code config: Displays a code representation of the selected entity as of the time of the selected revision.
  • Code diff: Displays a Git-style diff of the most-recent change made to the entity, in Cortex XCOR API format. To compare the selected revision to another revision in the history, click the Compare With dropdown and select the timestamp of the revision that you want to compare.
    • Click Unified to see the diff stacked horizontally.
    • Click Split to see changes side by side.
You can see the user, service account, or actor which made and the method used for the last change at the top of the list of changes. To view a revision in the history, click any entry in the list of timestamped revisions. The timestamps default to your local time zone. You can view unchanged lines within the diff by clicking the Expand X lines links. For a natural language description of the differences between versions, click Explain what has changed. An information box appears with a summary of the changes. This summary can help users who are less familiar with code updates understand changes. Use the thumbs up or thumbs down icon to indicate whether the explanation was helpful or not.
The Version History view retains up to 500 revisions, or up to 15 months of revisions if there are fewer than 500 revisions.

Restore a previous version

To restore a prior version of a notebook while reviewing its version history:
  1. Select the version to revert to.
  2. Click Restore to DATE, where DATE is the selected version.
  3. Click Restore.
The notebook refreshes and displays the restored version.

Reload an updated notebook

If Cortex XCOR detects a newer saved version of the notebook than the one displayed while the notebook is in Editing mode, it displays an alert. The alert header is A new version of this notebook is available. This can happen when another user saves changes to a shared notebook you’re viewing. It can also happen when you edit the same notebook in another browser tab. Click Reload to load the latest saved version.

Recover from a save error

If Cortex XCOR can’t save your latest notebook changes, an error alert displays with the header Your latest changes could not be saved. The notebook switches to Viewing mode so unsaved edits stop accumulating. The alert body explains that the notebook was switched to viewing mode and includes Try again. Click Try again to retry the save and return to Editing mode when the save succeeds. The alert appears in the side panel and in a full-screen notebook.

Create a notebook

If your personal collection has no notebooks when you open the notebook panel, Cortex XCOR creates one automatically. To create another notebook, use one of the following controls.
  • Click Create notebook in the notebooks list. The new notebook opens in a full-screen view.
  • In the side panel, click Create notebook in the notebook header. If Create notebook isn’t visible, click the three vertical dots icon, and then click Create notebook. See Notebook header for both header layouts.
  • In the side panel, click Select a notebook, and then click Create notebook.
A new notebook opens with a default name like Untitled notebook <date and time>. To rename it in the side panel while the notebook is in Editing mode, click the name. On the full-screen page, rename inline in Editing mode or use Notebook settings.

Add items to your notebook

Notebooks combine dashboard-style panels, entity link cards, and free-form text. This section describes how to add a panel, insert blocks with the command menu, format text, add a Mermaid diagram, link to an entity, Save an investigation report, and edit a notebook with Operator. To delete an item from your notebook, click the item and then press Delete.

Add a panel

Add a dashboard panel to a notebook in one of the following ways.

From another page

From any page that shows Add to notebook in its panel menu, such as dashboards and service pages:
  1. Hold the pointer over the panel, and then click the three vertical dots icon.
  2. Select Add to notebook.
  3. Select a notebook, or click Add to new notebook.
The panel appears at the bottom of your notebook.

Drag a panel from a dashboard

  1. Open a notebook.
  2. Open a dashboard.
  3. Drag a panel by its header into the notebook. Drop panel to add to notebook appears when the pointer is over the notebook.

Copy and paste a panel

  1. Open a notebook.
  2. On a dashboard, click a panel and press Control+C (Command+C on macOS).
  3. Click in the notebook text area and press Control+V (Command+V on macOS).

Create a panel in the notebook

  1. Open a notebook.
  2. In an empty notebook, click Add panel, or in any notebook open the command menu by typing / and select Panel.
  3. Configure the panel in the Add panel dialog, and then click Apply. See Edit a panel.

From Logs Explorer

  1. Open a notebook, or leave it closed to pick a notebook when you add content.
  2. Open Logs Explorer and enter a query. Add to notebook is disabled until the query field contains text.
  3. To match a specific chart type, select a visualization for the query results.
  4. Click Add to notebook in the page actions.
  5. If no notebook is open, select one in the Add panel to notebook dialog, or click Add to new notebook.
Cortex XCOR adds two panels: a log volume histogram, and a panel matching the selected visualization (such as list, table, or time series). Both use the Logs Explorer time range.

Save an investigation report

This feature isn’t available to all Palo Alto Networks Cortex XCOR users and might not be visible in your app. For information about enabling this feature in your environment, contact Cortex XCOR Support.
When a deep investigation finishes, save its report as a new notebook to share context with other responders or keep an evidence file after the incident.
  1. Open the completed investigation report from the Investigation card on alert details and click Show investigation.
  2. Open the report from an investigation card in the Assistant and click View full investigation.
  3. Click Save as notebook.
Cortex XCOR creates a notebook named for the alert when that name is available and opens it in the notebook side panel. The notebook includes context, findings, decisive evidence charts as panels, open questions, and suggested mitigation actions. Its default time range is about 30 minutes before and after the alert incident time when that time is known.
Generative AI features can produce incorrect results, hallucinate data, and deliver inaccurate analysis. Use generative AI features with care, and independently verify all information produced by generative AI tools before applying it.Certain prompts, data, or other inputs might produce irrelevant content. Don’t rely on generative AI features or responses for any uses that exceed their designed scope.

Use the command menu

To insert content blocks from the keyboard, type / anywhere in the notebook text area to open the command menu. Continue typing to filter the list by name, description, or keyword. Use the arrow keys to move through the results, press Enter to insert the selected block, and press Esc to close the menu. The command menu groups the available blocks.
  • Notebook
  • Basic blocks
    • Text inserts a plain paragraph.
    • Heading 1, Heading 2, and Heading 3 insert section headings.
    • Bulleted list, Numbered list, and Task list insert lists.
    • Quote inserts a block quotation.
    • Code block inserts a block of code.
    • Table inserts a table.
    • Toggle block inserts a collapsible section.

Format text

Click anywhere in the notebook that isn’t an added resource to add notes. Format notes using the toolbar under the notebook title bar:
  • Bold, Italic, and Code for inline formatting.
  • Link to add or edit a hyperlink. In the Add link dialog, enter Text and Link, and then click Apply.
  • Numbered list, Bulleted list, and Task list for lists.
When you select text, the same formatting controls appear in a floating menu over the selection. To insert block-level content such as headings, lists, quotes, code blocks, and tables, use the command menu.

Add a Mermaid diagram

Add a Mermaid diagram to illustrate a workflow or relationship inline in a notebook. Cortex XCOR renders the diagram from its source and matches your light or dark theme. To add a diagram:
  1. Open a notebook.
  2. Click in the notebook text area, open the command menu by typing /, and select Diagram. You can also filter the menu by typing mermaid, flowchart, or graph.
  3. Cortex XCOR inserts a sample diagram. Click Edit source and replace the sample with your own Mermaid syntax.
  4. Click Preview diagram to render it.
The diagram block provides the following controls:
  • Edit source and Preview diagram switch between the Mermaid source and the rendered diagram.
  • Remove Mermaid diagram deletes the block.
If the source contains invalid syntax, the block displays a Failed to render Mermaid diagram message with the error and your source so you can correct it. Embed a link card for a resource in one of the following ways. Click a link card to open the resource.

Mention an entity

Type @ in the notebook text area to open the Notebook entities search. The menu lists your recent entities until you type. Continue typing to search by name, then select a result to insert a link card. You can mention collections, services, dashboards, monitors, teams, and SLOs. Paste a URL copied from a resource page in Cortex XCOR to embed a link card labeled with the resource type and name. Use this method for pages that don’t offer Add to notebook, such as collections or teams pages.
  1. Click in the notebook text area.
  2. Paste the URL with Control+V (Command+V on macOS).
Paste each URL on its own line to add multiple resource cards.

Edit a notebook with Operator

This feature is in Early Access (EA), and might not be visible in your app. To learn more about this program and the features it contains, see the Early access page.
Operator reads the notebook you have open and edits its text, panels, and tables when you ask. Use it to summarize what you’ve gathered, add a chart, or reorganize your notes while you troubleshoot. To edit a notebook with Operator:
  1. Open a notebook.
  2. Click Ask Operator in the page header, or press A.
  3. Describe the change you want. For example:

    Summarize the panels in this notebook and add the summary at the top.

Operator saves notebook edits automatically. Review each change after Operator reports it. To revert a change, use the notebook’s version history. Operator can also find notebooks in your personal collection when you ask it to. For more information, see Operator capabilities.
Generative AI features can produce incorrect results, hallucinate data, and deliver inaccurate analysis. Use generative AI features with care, and independently verify all information produced by generative AI tools before applying it.Certain prompts, data, or other inputs might produce irrelevant content. Don’t rely on generative AI features or responses for any uses that exceed their designed scope.

Delete a notebook

To delete a notebook:
  • On the full-screen notebook page, click Notebook settings, and then click Delete notebook.
  • In the notebooks list, click the three vertical dots icon in the notebook’s row, and then click Delete. The list always shows Delete. The server rejects the action if your account doesn’t have permission to edit notebooks.
  • In the side panel:
    1. Open a notebook.
    2. Click Select a notebook in the notebook header.
    3. Next to the notebook you want to delete, click the three vertical dots icon and then click Delete.

Customize panels in a notebook

Change panel time ranges, open the panel editor to update queries and display options, or capture snapshots.

Change the time range

Change the time range for the entire notebook to shift all panels together, or override the time range on individual panels. For example, if there’s an anomaly in a graph in your notebook, add a second copy of the panel and change its time range to the same time last week to compare patterns. To change the time range for the entire notebook:
  1. In the notebook, click the time range selector under the format toolbar.
  2. Select a time range. See Select time ranges for preset, custom, and calendar options.
Panels without a per-panel override use the notebook time range. Panels with an override keep their own time until you reset them. To override the notebook time range for one panel:
  1. Hold the pointer over the panel.
  2. Click the clock icon.
  3. Select an available time range, or Custom time range to set your own.
The customized time range appears in the panel as a chip under the panel name. To reset the time range, click the x in the time range chip, or click the clock icon and select Use notebook time.

Edit panel contents

To update a panel in a notebook:
  1. Click the Edit icon.
  2. Edit the panel.
Not all panel editing operations are available in notebooks. For example, you can’t change the panel type.

Take a snapshot

Take a snapshot of a panel to capture specific data on a longer-term, static basis.
  1. Add a panel to your notebook.
  2. In the selected panel, click the three vertical dots icon.
  3. Select Capture snapshot.
The panel updates to indicate its snapshot status by adding Snapshot under the panel title. The snapshot time range displays next to the snapshot indicator. Zooming in on a time range updates the time range chip, and adds an x to the chip. Click the x to return to the original snapshot.

Snapshot all panels

While a notebook is in Editing mode, capture snapshots for every panel at once. In a full-screen notebook, click Snapshot all panels in the toolbar. The control is disabled when the notebook has no panels to snapshot. In the side panel, use Snapshot all panels in the notebook header. In a narrow header, it appears in the three vertical dots menu. Cortex XCOR prompts Snapshot all panels? and explains that it snapshots current data for every panel for each panel’s current time range. Click Snapshot all panels to confirm or Cancel to close the dialog without changes.