Skip to main content

Understanding the unified connector framework and automatic updates

note

This framework applies to the following Cortex products: Cortex XSIAM, Cortex XDR, Cortex Cloud, Cortex AgentiX, and Cortex Data Security. It does not apply to standalone Cortex XSOAR deployments.

For applicable Cortex products, Palo Alto Networks is evolving the integration infrastructure with the Unified Connector framework. This framework transitions the products from fragmented, manual version management to a streamlined, unified onboarding experience with automatic background updates.


Content categories#

To help you manage your security ecosystem, the applicable Cortex products now distinguish between two categories of content:

1. Connector-Ready capabilities#

Items labeled as Connector-Ready are part of the new framework. These core integration layers, now referred to as sub-capabilities, are built directly into the unified connector and are force-updated silently in the background. You no longer need to manually manage versions for these items.

  • Update method: Forced (Silent).
  • Included types: Sub-capability (integration) code, parsing rules, data model rules, fields, and mappings.
  • Visibility: These items are displayed within the connector's side-panel.

2. Marketplace Legacy content#

Items labeled as Marketplace Legacy are standalone integrations and high-level content that remain in the content pack. These must be managed and updated manually via Marketplace.

  • Update method: Manual (Marketplace).
  • Included types: Playbooks, scripts, dashboards, layouts, and jobs.

Transitioning to unified connectors#

For applicable Cortex products, the configuration workflow and update behavior depend on your onboarding date and the specific connector you are enabling.

New customers (onboarded after July 26, 2026)#

As a new customer, you will see the updated connector experience across the entire catalog.

  • Automatic force-updates: All connectors in your tenant will shift to the automatic force-update model automatically.
  • Background updates: Core sub-capabilities (integrations) are updated silently in the background without requiring user intervention.

Existing customers (onboarded before July 26, 2026)#

As an existing customer, you have immediate access to a subset of the unified catalog, specifically specialized SaaS remediation connectors (such as G-Suite, Salesforce, and Microsoft 365).

  • Manual update support: You will continue to manage updates manually for most integrations until those specific services are transitioned to the unified connector framework for your tenant.
  • Manual conversion: If you have existing standalone instances for services that are now available as connectors, you may need to perform a manual conversion process if your related content packs are not at the latest version.

Important considerations#

  • Integration visibility: Once you convert an integration to a connector, the legacy integration card will no longer appear in your catalog, and the service will appear as a sub-capability (integration) within the connector.
  • Dev-prod sync: For customers using a Dev/Prod setup, it is highly recommended to perform updates and conversions in your Test tenant first, push them to your repository, and then pull them into your Production tenant to ensure parity.

Related resources#

For product-specific configuration guides and comprehensive catalogs, refer to the documentation portal:

Last updated on