> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Ingest telemetry data

> Use control mechanisms to manage the telemetry data you ingest into Palo Alto Networks Cortex XCOR.

Before you can use Palo Alto Networks Cortex XCOR to view and manage your
telemetry data (of whatever type), you need to get that data into Cortex XCOR.

```mermaid actions={false} theme={null}
flowchart LR
  accTitle: Palo Alto Networks Cortex XCOR architecture diagram
  accDescr: Architecture diagram that shows the flow of data from a customer's environment into the Control Plane in Palo Alto Networks Cortex XCOR, and then out to third party incident management and alerting software.
  subgraph "Cortex XCOR"
    cp((Palo Alto<br>Cortex XCOR))
  end
  subgraph "Your environment"
    inf(Infrastructure<br>applications) -- Metrics and<br>traces --> coll(Chronosphere<br>Collector)
    inf -- Logs and<br>change events --> cp
    inf -- Logs --> pipe(Palo Alto Networks<br>Palo Alto Networks Telemetry Pipeline<br>or existing pipeline)
    inf -- Logs, metrics,<br>and traces --> otel(OpenTelemetry<br>Collector)
    pipe --> cp
    coll --> cp
    otel --> cp
  end

  click coll "/ingest/metrics-traces/collector"
  click pipe "/ingest/pipeline/v2"
  click otel "/ingest/otel-ingestion"

  classDef platform fill:#2fbf71,stroke-width:2px,stroke:#2fbf71,color:#FFFFFF;
  class cp,coll,pipe,otel platform
```

## Supported ingestion methods

Cortex XCOR supports multiple methods to ingest telemetry data, which
depend on which type of data you want to ingest:

| Ingestion method | Change events | Logs | Metrics | Traces |
| - | :-: | :-: | :-: | :-: |
| [Chronosphere Collector](/ingest/metrics-traces/collector) | <Icon icon="ban" color="red" /> | <Icon icon="ban" color="red" /> | <Icon icon="circle-check" color="green" /> | <Icon icon="circle-check" color="green" /> |
| [OpenTelemetry](/ingest/otel-ingestion) | <Icon icon="ban" color="red" /> | <Icon icon="circle-check" color="green" /> | <Icon icon="circle-check" color="green" /> | <Icon icon="circle-check" color="green" /> |
| [Palo Alto Networks Telemetry Pipeline](/ingest/pipeline/v2) | <Icon icon="ban" color="red" /> | <Icon icon="circle-check" color="green" /> | <Icon icon="ban" color="red" /> | <Icon icon="ban" color="red" /> |
| [Existing pipeline](/ingest/logs) | <Icon icon="ban" color="red" /> | <Icon icon="circle-check" color="green" /> | <Icon icon="ban" color="red" /> | <Icon icon="ban" color="red" /> |
| [Direct to Cortex XCOR](/ingest/third-party) | <Icon icon="circle-check" color="green" /> | <Icon icon="circle-check" color="green" /> | <Icon icon="ban" color="red" /> | <Icon icon="ban" color="red" /> |

After ingesting telemetry data, you can use the control mechanisms that Cortex XCOR
provides to [control costs](/control) and ensure you're ingesting only the
data you care about.

### OpenTelemetry support

For more information about using OpenTelemetry to ingest logs, metrics, and traces,
see [OpenTelemetry support in Cortex XCOR](/ingest/otel-ingestion).

## Ingestion models

Cortex XCOR utilizes *push* and *pull* models of ingestion, depending on the data
collected and the method of ingestion.

| Telemetry type | Push | Pull |
| - | :-: | :-: |
| Metrics | <Icon icon="circle-check" color="green" /> | <Icon icon="circle-check" color="green" /> |
| Traces | <Icon icon="circle-check" color="green" /> | <Icon icon="ban" color="red" /> |
| Logs | <Icon icon="circle-check" color="green" /> | <Icon icon="circle-check" color="green" /> |

*Pull* models, like the Chronosphere Collector, scrape telemetry data from external
sources and pull it in. These metrics have consistent reporting intervals.

*Push* models, like tracing, send telemetry data to Cortex XCOR, which is then
processed. These metrics can have a broad spectrum of reporting frequency, from large
bursts of data to long periods with no data reporting.

The ingestion model depends on the telemetry data source. Metrics pushed to
Cortex XCOR can have [latency delays](/ingest/metrics-traces/gcp#metrics-availability)
or [sparse time series](/investigate/querying/metrics/troubleshooting#sparse-time-series),
which can result in unexpected query results.


## Related topics

- [Get started with Cortex XCOR](/overview/get-started.md)
- [Ingest telemetry data with source plugins](/ingest/pipeline/plugins/source-plugins.md)
- [Administer your tools and users](/administer.md)
- [Ingest log data](/ingest/logs.md)
- [Ingest metric and trace data](/ingest/metrics-traces.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.