> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Understanding generative AI features

> Learn how Palo Alto Networks Cortex XCOR provides generative AI features.

<Note>
  This feature isn't available to all Palo Alto Networks Cortex XCOR users and
  might not be visible in your app. For information about enabling this feature in your
  environment, contact [Cortex XCOR Support](/support).
</Note>

Palo Alto Networks Cortex XCOR provides content generated by
artificial intelligence (AI) tools, including large language models (LLMs). This
content can serve many purposes, such as context-aware query language completions
and high-level summaries of your data and visualizations.

<Warning>
  Generative AI features can produce incorrect results, hallucinate data, and deliver
  inaccurate analysis. Use generative AI features with care, and independently verify
  all information produced by generative AI tools before applying it.

  Certain prompts, data, or other inputs might produce irrelevant content. Don't rely on
  generative AI features or responses for any uses that exceed their designed scope.
</Warning>

## Discover generative AI features

Generative AI features aren't enabled on all Cortex XCOR tenants. For more information,
contact [Cortex XCOR Support](/support).

### Identify generative AI features

Generative AI features are accompanied by icons in the Cortex XCOR
interface:

* **AI Summary**: Produces a pop-up summary of an entity or subject. You can provide
  feedback for these summaries by clicking their
  **<Icon icon="thumbs-up" alt="Thumbs up icon" /> accept**
  or **<Icon icon="thumbs-down" alt="Thumbs down icon" /> reject** buttons.
* **AI content**: Appears alongside content created by generative AI tools.

### Generative AI features in Cortex XCOR

Cortex XCOR features that use generative AI include:

* **Dashboard descriptions** summarize [dashboards](/observe/dashboards) by their
  contents, panel groups, and variables.
* **Dashboard panel names and descriptions** create a name and summary description
  for a [panel](/observe/dashboards/panels) based on panel contents.

<Note>
  This feature is in Early Access (EA), and might not be visible in your app. To learn
  more about this program and the features it contains, see the
  [Early access](/early-access) page.
</Note>

* **[Operator](/navigate/operator)** answers questions about your telemetry and
  configuration, runs queries on your behalf, and edits the dashboard or notebook
  you have open. Click **Ask Operator** in the page header or press `A` to open
  it.
* **Natural language queries**: Generate queries using natural language prompts.
  * **PromQL**: Generate [PromQL queries](/investigate/querying/natural-language)
    in [Metrics Explorer](/investigate/querying/metrics/explorer) or in a
    [dashboard panel](/investigate/querying/natural-language#generate-a-promql-query-for-a-dashboard-panel)
    query editor.
    [Semantic search](/investigate/querying/natural-language#semantic-metric-search)
    automatically identifies the most relevant metrics for your prompt based on
    intent, rather than exact keyword matches.
  * **Logs**: Generate [queries of logs](/investigate/querying/query-logs) in Logs Explorer.
  * **Monitors**: Generate
    [PromQL queries for monitors](/investigate/alerts/monitors).
  * **SLOs**: Generate
    [PromQL queries for SLO indicators](/investigate/querying/natural-language#generate-queries-for-slo-indicators)
    when you define a [service level objective](/observe/slo).

## Write effective prompts

The quality of a generative AI response depends on the prompt that produced it.
The guidance in this section applies to any prompt field in Cortex XCOR, including
[Operator](/navigate/operator) and
[query generation](/investigate/querying/natural-language).

### Prompting guidelines

* **State a specific goal.** Name the service, metric, log field, or resource you
  care about, and what you want to know about it.
* **Bound the question in time.** Generative AI features default to the time range
  of the page you're on, which might not match your intent. State the window when
  it matters.
* **Provide the context you have.** Metric names, label values, service names, and
  dashboard slugs all narrow the search. You don't need exact names, because
  Cortex XCOR uses
  [semantic search](/investigate/querying/natural-language#semantic-metric-search)
  to find relevant metrics, but exact names produce better results faster.
* **Ask for the shape of the answer you want**, such as a count, a rate, a
  comparison against last week, or a table of the top contributors.
* **Ask one question at a time.** A prompt that combines several unrelated
  requests produces a diffuse answer. Send follow-up prompts instead, because both
  Operator and query generation retain the context of the conversation.
* **Refine instead of restarting.** When the first response is close but not
  correct, describe the correction rather than rewriting your original prompt.
* **Verify before you act.** Read the queries and evidence behind a response, and
  confirm them against your data before making a decision.

### Example prompts

An overly terse prompt lacks the context to produce an actionable answer:

> latency

A prompt that's vague and adds no constraints produces a diffuse answer:

> Tell me what's wrong with my services right now.

A specific prompt that names the subject, the time window, and the form of the
answer produces a focused result:

> Show the p99 latency of the checkout service over the last 6 hours, broken down
> by endpoint.

Effective prompts for Operator follow the same pattern across use cases:

* Explain a signal:

  > Why did the checkout-api error rate increase around 14:00 UTC today?

* Find a resource:

  > Which dashboards cover the payments service, and who owns them?

* Understand configuration:

  > What conditions trigger the checkout-latency monitor, and who does it notify?

* Correlate across telemetry types:

  > Were there any deploys or config changes to the payments service in the 30
  > minutes before this alert triggered?

* Investigate logs:

  > What are the most common error messages in the shopping-cart service logs over
  > the last hour, and how often does each occur?

* Change a dashboard:

  > Add a panel to this dashboard showing request rate by status code for the
  > checkout service.

When a response is close but incomplete, refine it with a follow-up rather than a
new prompt:

> Break that down by availability zone instead, and exclude the canary deployment.


## Related topics

- [Service level objectives](/observe/slo.md)
- [Ask Operator about your telemetry](/navigate/operator.md)
- [Operator capabilities reference](/navigate/operator/capabilities.md)
- [Use monitors to generate alerts and notifications](/investigate/alerts/monitors.md)
- [Generate queries using natural language](/investigate/querying/natural-language.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.