Accounts with the
None
role can open and view notebooks. To
create, edit, or delete a notebook, your account must be a member of a team with the
Editor, SysAdmin, or User Administrator role.- View the notebooks list to browse every notebook you can access.
- Open a notebook in a full-screen view from the notebooks list or from a collection home page.
- Use the notebook side panel on any page to add resources without leaving your current context.
View the notebooks list
To display the list of notebooks, in the navigation menu, select Notebooks. The list fills the main window. While you’re on this page, Cortex XCOR closes the notebook side panel and disables theN
shortcut until you leave.
By default, the table lists notebooks in your personal collection and in
collections you can access. Notebooks in another user’s
personal collection, such as one you opened from a shared link,
are hidden until you turn on Show other users’ notebooks.
Use the following controls on the notebooks list.
- Create notebook opens a new notebook in a full-screen view when your account can create notebooks (see the Note at the top of this page). See Create a notebook. The button doesn’t appear on the list when you only have view access.
- Search notebooks filters the list by notebook name, owner, or category.
- Show only my notebooks lists only notebooks in your personal collection. While this switch is on, Show other users’ notebooks is hidden.
- Show other users’ notebooks also lists notebooks in other users’ personal collections. This switch appears only when Show only my notebooks is off.
- Copy Link copies a shareable URL for the notebook.
- Delete removes the notebook.
Notebooks on a collection home page
Each collection home page includes a Notebooks section that lists notebooks owned by that collection. Use it for a quick view of notebooks tied to a team or feature. View all on the collection home page opens the same list as Notebooks in the navigation menu. Cortex XCOR doesn’t pre-filter the list to that collection. To find notebooks for one collection, use one of the following methods on the notebooks list.- Enter the collection name in Search notebooks. Search matches notebook names, owners, and categories.
- Locate the collection in the Owner column.
Open a notebook in a full-screen view
When you open a notebook from the notebooks list, it fills the page. A full-screen notebook includes the formatting toolbar, a time range selector, an Editing or Viewing mode control, Copy as Markdown, Snapshot all panels (in Editing mode when the notebook has panels to snapshot), Notebook settings, and Version history. The page shows the notebook Name, Owner, and Category (when set) under the toolbar. In Editing mode, click the name to rename it inline. In Viewing mode, the name is read-only. Notebooks in your personal collection open in Editing mode. Notebooks owned by another user or by a collection open in Viewing mode. Switch to Editing to change content, rename the notebook, or update Collection in Notebook settings. To delete a notebook, use Notebook settings. Use the Notebooks breadcrumb to return to the list. Opening a notebook in full screen closes the notebook side panel if it was open. Closing the full-screen notebook restores the side panel.Set a notebook category
To classify a notebook, open Notebook settings in a full-screen view while the notebook is in Editing mode. Select a Notebook category and click Save.- None removes the category.
- Documentation, Investigation, Postmortem, Report, and Runbook label the notebook for filtering and display.
Notebook side panel
The notebook side panel opens over any page in Cortex XCOR so you can gather resources without leaving your current context. Cortex XCOR displays the last notebook you accessed, and your open notebook stays visible as you move between pages.Open a notebook
Click the Notebook icon in the page header, between pinned scope and search, or pressN. The notebook side panel opens on the
right side of the page. The N shortcut is disabled on the notebooks list and full-screen
notebook pages.
After the notebook opens, see Notebook header for full-screen, create,
share, and version history controls. Side panel notebooks often use a
narrow header.
Switch notebooks
To switch notebooks or find a notebook you opened recently:- Click Select a notebook in the notebook header.
- If needed, enter a name in Search or use Show only my notebooks and Show other users’ notebooks. The menu uses the same visibility switches as the notebooks list.
- Click a Name in the table to open the selected notebook. The open notebook is labeled (current). Each row also displays Owner, Last viewed, and row actions to Share or Delete.
Notebook header
The top of the notebook side panel provides controls to view the notebook in a full-screen view, open its version history, copy the notebook as Markdown, copy its URL, and create a notebook. The next row includes the formatting toolbar and an Editing or Viewing mode control. Cortex XCOR shows these controls as separate icon buttons or groups them in a menu, depending on the width of the notebook header row. The layout switches at 360 pixels. When the header row is narrower than 360 pixels, Cortex XCOR uses a narrow header. When the row is 360 pixels or wider, it uses a wide header. Resizing the notebook panel or using a long notebook name can change the header width and switch between layouts. Use the tab that matches what you see:- Narrow header
- Wide header
In a narrow header, these actions are grouped in one menu.
- Click the three vertical dots icon in the notebook header.
- Select an action.
- View full screen
- Version history
- Copy as Markdown
- Snapshot all panels (in Editing mode)
- Copy URL
- Create notebook
Notebook ownership and sharing
Every notebook belongs to a collection. Notebooks you create are stored in your personal collection by default. To store a notebook with a team or feature instead, open the notebook in a full-screen view, switch to Editing mode if needed, open Notebook settings, and select a different Collection. You can also set a Notebook category there. See Set a notebook category. You can’t move a notebook from a shared collection back into a personal collection from the UI. Notebooks can’t be owned by services. Other users don’t see notebooks in your personal collection unless you share a link. When someone opens a link you share, the notebook opens in their notebook panel and appears in their notebooks list after they turn on Show other users’ notebooks when the notebook stays in your personal collection. Collection-owned notebooks appear on the collection’s home page and in the notebooks list by default.Share a notebook
To share a notebook, copy its URL using one of the following controls.- In the notebooks list, open the row’s three vertical dots menu and click Copy Link.
- In the side panel, click Copy URL in the notebook header. If Copy URL isn’t visible, click the three vertical dots icon, and then click Copy URL. See Notebook header for both header layouts.
- In Select a notebook, open the row menu and click Share. Share copies the same URL as Copy Link on the notebooks list.
Use Markdown with notebooks
Copy a notebook’s contents to the clipboard as Markdown, or paste Markdown into an editable notebook. Cortex XCOR doesn’t support importing or uploading Markdown files.Copy a notebook as Markdown
Use the control for the notebook view:- In a full-screen notebook, click Copy as Markdown in the toolbar.
- In a wide side panel header, click Copy as Markdown.
- In a narrow side panel header, click the three vertical dots icon, and then click Copy as Markdown.
.md extension if you need a Markdown file.
The copied Markdown doesn’t include the notebook name, collection, owner, version
history, or notebook-wide default time range. A panel-specific time range remains part
of that panel’s definition.
Create a notebook from Markdown
- Create a notebook, or open an existing notebook that you can edit.
- Copy the Markdown source from your
.mdfile or text editor. - Click where you want to add the content in the notebook body. Select existing content first if the pasted Markdown should replace it.
- Paste with
Control+V(Command+Von macOS).
Markdown content and round trips
Notebook content maps to Markdown in the following ways:- Free-form content uses standard Markdown for paragraphs, headings, bold and italic
text, strike-through text, inline code, links, line breaks, lists, block quotes, code
blocks, horizontal rules, tables, and task lists. Mermaid diagrams use
mermaidcode fences. - Visualization panels use
chrono-VizPanelcode fences containing the panel definition as JSON. The definition includes the queries, display options, and any panel-specific time range. Pasting the fence restores an interactive panel that runs its queries, preserving the fence and its JSON without modification. - Entity link cards become standard Markdown links. Pasting a recognized Cortex XCOR entity URL restores the link card. An entity without a supported URL becomes plain text.
- A snapshot uses the same
chrono-VizPanelrepresentation and retains its snapshot identifier, but not the captured query data. The imported panel remains a snapshot only where that identifier is available.
- Merged table cells expand into individual cells, multi-paragraph cells flatten onto one line, and column alignment normalizes.
- Images become linked alt text because notebooks don’t have an image block.
- Underlined text loses its underline. Inline code retains its code formatting but loses overlapping bold, italic, or link formatting on the same text.
- Unknown notebook content becomes its fallback text, descendant text, or an
Unsupported notebook contentlabel. - Copying Markdown to another tenant doesn’t copy referenced entities, snapshots, or query data.
View version history
To view the history of changes for a notebook, click Version history. In the side panel, if Version history isn’t visible, click the three vertical dots icon in the notebook header, and then click Version history. See Notebook header for both header layouts. Click Version history to display a panel with two tabs:- Code config: Displays a code representation of the selected entity as of the time of the selected revision.
- Code diff: Displays a Git-style diff of the most-recent change made to the
entity, in Cortex XCOR API format. To compare the selected revision to another
revision in the history, click the Compare With dropdown and select the
timestamp of the revision that you want to compare.
- Click Unified to see the diff stacked horizontally.
- Click Split to see changes side by side.
The Version History view retains up to 500 revisions, or up to 15 months of revisions
if there are fewer than 500 revisions.
Restore a previous version
To restore a prior version of a notebook while reviewing its version history:- Select the version to revert to.
- Click Restore to
DATE, whereDATEis the selected version. - Click Restore.
Reload an updated notebook
If Cortex XCOR detects a newer saved version of the notebook than the one displayed while the notebook is in Editing mode, it displays an alert. The alert header is A new version of this notebook is available. This can happen when another user saves changes to a shared notebook you’re viewing. It can also happen when you edit the same notebook in another browser tab. Click Reload to load the latest saved version.Recover from a save error
If Cortex XCOR can’t save your latest notebook changes, an error alert displays with the header Your latest changes could not be saved. The notebook switches to Viewing mode so unsaved edits stop accumulating. The alert body explains that the notebook was switched to viewing mode and includes Try again. Click Try again to retry the save and return to Editing mode when the save succeeds. The alert appears in the side panel and in a full-screen notebook.Create a notebook
If your personal collection has no notebooks when you open the notebook panel, Cortex XCOR creates one automatically. To create another notebook, use one of the following controls.- Click Create notebook in the notebooks list. The new notebook opens in a full-screen view.
- In the side panel, click Create notebook in the notebook header. If Create notebook isn’t visible, click the three vertical dots icon, and then click Create notebook. See Notebook header for both header layouts.
- In the side panel, click Select a notebook, and then click Create notebook.
<date and time>. To
rename it in the side panel while the notebook is in Editing mode, click the name.
On the full-screen page, rename inline in Editing mode or use
Notebook settings.
Add items to your notebook
Notebooks combine dashboard-style panels, entity link cards, and free-form text. This section describes how to add a panel, insert blocks with the command menu, format text, add a Mermaid diagram, link to an entity, Save an investigation report, and edit a notebook with Operator. To delete an item from your notebook, click the item and then pressDelete.
Add a panel
Add a dashboard panel to a notebook in one of the following ways.From another page
From any page that shows Add to notebook in its panel menu, such as dashboards and service pages:- Hold the pointer over the panel, and then click the three vertical dots icon.
- Select Add to notebook.
- Select a notebook, or click Add to new notebook.
Drag a panel from a dashboard
- Open a notebook.
- Open a dashboard.
- Drag a panel by its header into the notebook. Drop panel to add to notebook appears when the pointer is over the notebook.
Copy and paste a panel
- Open a notebook.
- On a dashboard, click a panel and press
Control+C(Command+Con macOS). - Click in the notebook text area and press
Control+V(Command+Von macOS).
Create a panel in the notebook
- Open a notebook.
- In an empty notebook, click Add panel, or in any notebook open the
command menu by typing
/and select Panel. - Configure the panel in the Add panel dialog, and then click Apply. See Edit a panel.
From Logs Explorer
- Open a notebook, or leave it closed to pick a notebook when you add content.
- Open Logs Explorer and enter a query. Add to notebook is disabled until the query field contains text.
- To match a specific chart type, select a visualization for the query results.
- Click Add to notebook in the page actions.
- If no notebook is open, select one in the Add panel to notebook dialog, or click Add to new notebook.
Save an investigation report
This feature isn’t available to all Palo Alto Networks Cortex XCOR users and
might not be visible in your app. For information about enabling this feature in your
environment, contact Cortex XCOR Support.
- Open the completed investigation report from the Investigation card on alert details and click Show investigation.
- Open the report from an investigation card in the Assistant and click View full investigation.
- Click Save as notebook.
Use the command menu
To insert content blocks from the keyboard, type/ anywhere in the notebook text
area to open the command menu. Continue typing to filter the list by name,
description, or keyword. Use the arrow keys to move through the results, press
Enter to insert the selected block, and press Esc to close the menu.
The command menu groups the available blocks.
- Notebook
- Panel inserts a dashboard panel.
- Diagram inserts a Mermaid diagram.
- Basic blocks
- Text inserts a plain paragraph.
- Heading 1, Heading 2, and Heading 3 insert section headings.
- Bulleted list, Numbered list, and Task list insert lists.
- Quote inserts a block quotation.
- Code block inserts a block of code.
- Table inserts a table.
- Toggle block inserts a collapsible section.
Format text
Click anywhere in the notebook that isn’t an added resource to add notes. Format notes using the toolbar under the notebook title bar:- Bold, Italic, and Code for inline formatting.
- Link to add or edit a hyperlink. In the Add link dialog, enter Text and Link, and then click Apply.
- Numbered list, Bulleted list, and Task list for lists.
Add a Mermaid diagram
Add a Mermaid diagram to illustrate a workflow or relationship inline in a notebook. Cortex XCOR renders the diagram from its source and matches your light or dark theme. To add a diagram:- Open a notebook.
- Click in the notebook text area, open the command menu by
typing
/, and select Diagram. You can also filter the menu by typingmermaid,flowchart, orgraph. - Cortex XCOR inserts a sample diagram. Click Edit source and replace the sample with your own Mermaid syntax.
- Click Preview diagram to render it.
- Edit source and Preview diagram switch between the Mermaid source and the rendered diagram.
- Remove Mermaid diagram deletes the block.
Link to an entity
Embed a link card for a resource in one of the following ways. Click a link card to open the resource.Mention an entity
Type@ in the notebook text area to open the Notebook entities search. The menu
lists your recent entities until you type. Continue typing to search by name, then
select a result to insert a link card. You can mention collections, services,
dashboards, monitors, teams, and SLOs.
Paste an entity link
Paste a URL copied from a resource page in Cortex XCOR to embed a link card labeled with the resource type and name. Use this method for pages that don’t offer Add to notebook, such as collections or teams pages.- Click in the notebook text area.
- Paste the URL with
Control+V(Command+Von macOS).
Edit a notebook with Operator
This feature is in Early Access (EA), and might not be visible in your app. To learn
more about this program and the features it contains, see the
Early access page.
- Open a notebook.
- Click Ask Operator in the page header, or press A.
-
Describe the change you want. For example:
Summarize the panels in this notebook and add the summary at the top.
Delete a notebook
To delete a notebook:- On the full-screen notebook page, click Notebook settings, and then click Delete notebook.
- In the notebooks list, click the three vertical dots icon in the notebook’s row, and then click Delete. The list always shows Delete. The server rejects the action if your account doesn’t have permission to edit notebooks.
- In the side panel:
- Open a notebook.
- Click Select a notebook in the notebook header.
- Next to the notebook you want to delete, click the three vertical dots icon and then click Delete.
Customize panels in a notebook
Change panel time ranges, open the panel editor to update queries and display options, or capture snapshots.Change the time range
Change the time range for the entire notebook to shift all panels together, or override the time range on individual panels. For example, if there’s an anomaly in a graph in your notebook, add a second copy of the panel and change its time range to the same time last week to compare patterns. To change the time range for the entire notebook:- In the notebook, click the time range selector under the format toolbar.
- Select a time range. See Select time ranges for preset, custom, and calendar options.
- Hold the pointer over the panel.
- Click the clock icon.
- Select an available time range, or Custom time range to set your own.
x in the time range chip,
or click the clock icon and select Use notebook time.
Edit panel contents
To update a panel in a notebook:- Click the Edit icon.
- Edit the panel.
Take a snapshot
Take a snapshot of a panel to capture specific data on a longer-term, static basis.- Add a panel to your notebook.
- In the selected panel, click the three vertical dots icon.
- Select Capture snapshot.
x to the chip. Click the x to
return to the original snapshot.