1) On-Premises
You can install Cortex XSOAR on a VM or bare-metal servers. In this installation model, the customer provisions, installs, configures, and maintains all aspects of the system while Palo Alto Networks provides support based on licensing. As of now, installation of Cortex XSOAR on CentOS, RedHat Enterprise Linux, Ubuntu, Oracle Linux, Amazon Linux 2, SUSE Linux Enterprise 12, openSUSE, and Fedora is supported.
2) Hosted Cloud
In this model, Palo Alto Networks provisions and maintains the customer’s instance of the Cortex XSOAR server, which includes maintaining the OS, performing upgrades, providing high availability. The customer only needs to configure and maintain the Cortex SOAR from an application-layer level. Palo Alto Networks provides application support based on the license purchased. Only the Palo Alto Networks DevOps team has access to the OS. The cloud-hosted option is not a full security-as-a-service offering. After the cloud instance is deployed, the customer is responsible for all configuration, integration, and automation work required using the product's web console.
As of now, Palo Alto Networks provides Cortex XSOAR hosted-cloud instances on AWS only.
3) Private Cloud
Another installation model is Private Cloud, in which you can deploy Cortex XSOAR within your private cloud. Palo Alto Networks treats a private cloud deployment the same as an on-premises deployment and therefore same kind of support is delivered from PaloAlto. In this option, the customer must manage patches and upgrades yourself. For AWS, Cortex XSOAR publishes an Amazon Machine Image (AMI) that uses Amazon Linux.
You can also deploy private-cloud instances of Cortex XSOAR server on GCP or Azure, given that the underlying virtual machine satisfies the supporting requirements.
4) Hybrid Cloud
The hybrid cloud model puts the Cortex XSOAR server in the cloud, either hosted or private, and couples it with a Cortex XSOAR Engine that resides at the central location which is, normally the on-premises server. The Cortex XSOAR Engine allows Cortex XSOAR integrations and automation to talk to on-premises security tools and report back to the Cortex XSOAR Server through the local perimeter.
In this model, the customer provisions the image, installs the software, and maintains upgrades and availability while Palo Alto Networks provides the same support as in the on-premises model. This solution requires to allow HTTPS outbound connections from the Engine to the cloud-based Cortex XSOAR Server.
Read more posts on Palo Alto Cortex XSOAR here. 👆