<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XQL  incident query in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-incident-query/m-p/472952#M1676</link>
    <description>&lt;P&gt;Hello PAN community !!&lt;/P&gt;&lt;P&gt;I'm new in this platform and I am a little lost here. I'm trying to create a query to list all endpoints of a specific endpoint group with all its incidents (malware,etc).&lt;/P&gt;&lt;P&gt;To get the endpointgroup and its endpoints I'm using&lt;/P&gt;&lt;P&gt;dataset = endpoints | fields group_names , endpoint_name&lt;/P&gt;&lt;P&gt;But I have not idea where to find the alert category of an incident and the incident details for cases like malware of other kind of incident.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All support is always welcome&lt;/P&gt;</description>
    <pubDate>Mon, 14 Mar 2022 19:25:57 GMT</pubDate>
    <dc:creator>rcamposb</dc:creator>
    <dc:date>2022-03-14T19:25:57Z</dc:date>
    <item>
      <title>Cortex XQL  incident query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-incident-query/m-p/472952#M1676</link>
      <description>&lt;P&gt;Hello PAN community !!&lt;/P&gt;&lt;P&gt;I'm new in this platform and I am a little lost here. I'm trying to create a query to list all endpoints of a specific endpoint group with all its incidents (malware,etc).&lt;/P&gt;&lt;P&gt;To get the endpointgroup and its endpoints I'm using&lt;/P&gt;&lt;P&gt;dataset = endpoints | fields group_names , endpoint_name&lt;/P&gt;&lt;P&gt;But I have not idea where to find the alert category of an incident and the incident details for cases like malware of other kind of incident.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All support is always welcome&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 19:25:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-incident-query/m-p/472952#M1676</guid>
      <dc:creator>rcamposb</dc:creator>
      <dc:date>2022-03-14T19:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XQL  incident query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-incident-query/m-p/472958#M1677</link>
      <description>&lt;P&gt;Hi Rcamposb,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently XDR data sets with Incident or Alert data are not available through XQL. You may consider reaching out to your account team to inquire about any future plans to support this capability.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Mon, 14 Mar 2022 19:34:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-incident-query/m-p/472958#M1677</guid>
      <dc:creator>bbucao</dc:creator>
      <dc:date>2022-03-14T19:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XQL  incident query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-incident-query/m-p/520309#M3098</link>
      <description>&lt;P&gt;Hey Ben,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for this clarification. Do you know if there is a place to make a feature request, as we are also missing option in our team?&lt;BR /&gt;&lt;BR /&gt;Best/Elisabeth&lt;/P&gt;</description>
      <pubDate>Fri, 04 Nov 2022 12:12:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-incident-query/m-p/520309#M3098</guid>
      <dc:creator>ElisabethNordentoft</dc:creator>
      <dc:date>2022-11-04T12:12:50Z</dc:date>
    </item>
  </channel>
</rss>

