> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Cortex XCOR system limits

> Learn about system limits in Palo Alto Networks Cortex XCOR.

Palo Alto Networks Cortex XCOR applies system limits to protect itself from
failures caused by abnormal traffic patterns, such as sudden, unexpected spikes in
data ingestion.

For organizations that use consumption pricing, consumption system
limits restrict rapid increases in metrics, logs, and traces volume. The
[Consumption System Limits dashboard](/observe/dashboards/managed-dashboards#consumption-system-limits)
is the source of truth for the limits enforced in your tenant. Use it to view
thresholds, utilization, and data dropped by system limit enforcement.

Consumption system limits apply separately from contract credit consumption and
user-configured budgets. Contact [Cortex XCOR Support](/support) to request an
adjustment to these limits.

Cortex XCOR also applies data validation, ingestion, and query
protections. Learn more about the protections for the following data types:

* [Events](/administer/limits-licensing/limits/event-limits): Ingest rate caps and
  field-level validation for change events.
* [Logs](/administer/limits-licensing/limits/log-limits): Maximum individual log size
  and label length constraints.
* [Metrics](/administer/limits-licensing/limits/metric-limits): Label size, label
  count, total series byte limits, and late- or future-arriving data windows.
* [Queries](/administer/limits-licensing/limits/query-limits): Per-query scale
  protections, browser truncation limits, resource balancing, and automated source
  rate limits.
* [Traces](/administer/limits-licensing/limits/trace-limits): Tag size, span timing
  validity, trace span count, and per-pod ingest caps.

## Monitor capacity limits

For organizations that use capacity pricing, Cortex XCOR enforces
[license capacity limits](/administer/limits-licensing/concepts/capacity-licensing#capacity-limits)
for telemetry data. Exceeding these limits can put your organization at risk of
dropping data. The type of data that's dropped depends on the limit exceeded.

Exceeding your organization's license capacity limits can cause you to hit the defined
system limits, which shouldn't occur under normal operating circumstances. To prevent
your system from reaching system limits, use the following tools and information to
ensure that your Cortex XCOR tenant remains under your license capacity
limit at all times:

* Use the [License Overview](/administer/limits-licensing/licensing) to track your
  telemetry usage against your licensing.
* Review the
  [cardinality dashboards](/observe/dashboards/managed-dashboards#cardinality-dashboards)
  to identify information you can use to help reduce cardinality.
* Query
  [key metrics](/administer/limits-licensing/concepts/capacity-licensing#capacity-limits)
  to understand
  if Cortex XCOR is actively dropping data.
* Use the provided tools and techniques to
  [avoid hitting persisted cardinality limits](/administer/limits-licensing/concepts/capacity-licensing#avoid-persisted-cardinality-limits).


## Related topics

- [Licensing and system limits](/administer/limits-licensing.md)
- [Query limits](/administer/limits-licensing/limits/query-limits.md)
- [Tracing ingest limits](/administer/limits-licensing/limits/trace-limits.md)
- [Cortex XCOR-managed dashboards](/observe/dashboards/managed-dashboards.md)
- [Okta System Logs Collector source plugin](/ingest/pipeline/plugins/source-plugins/okta.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.