<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Query Network in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/479429#M1855</link>
    <description>&lt;P&gt;Hello XDR Community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when the network (see screenshot) will be depprecated, will it be possible to get all the informations under network connections?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't get the same results and not dst_host which would be very usefull.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my Query:&lt;/P&gt;&lt;P&gt;Network [ action type = all AND remote ip = XXX.XXX.XXX.X ] AND Time [ event timestamp in last 24H before Apr 9th 2022 01:03:51 ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anybody of you a future proof XQL version of my query above?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1649460837699.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40107iA9035B126674102E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1649460837699.png" alt="RFeyertag_0-1649460837699.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Fri, 08 Apr 2022 23:39:46 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2022-04-08T23:39:46Z</dc:date>
    <item>
      <title>Query Network</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/479429#M1855</link>
      <description>&lt;P&gt;Hello XDR Community!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when the network (see screenshot) will be depprecated, will it be possible to get all the informations under network connections?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't get the same results and not dst_host which would be very usefull.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my Query:&lt;/P&gt;&lt;P&gt;Network [ action type = all AND remote ip = XXX.XXX.XXX.X ] AND Time [ event timestamp in last 24H before Apr 9th 2022 01:03:51 ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anybody of you a future proof XQL version of my query above?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1649460837699.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40107iA9035B126674102E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1649460837699.png" alt="RFeyertag_0-1649460837699.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 23:39:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/479429#M1855</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-04-08T23:39:46Z</dc:date>
    </item>
    <item>
      <title>Betreff: Query Network</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/479484#M1856</link>
      <description>&lt;P&gt;The two data sources deliver completly other results:&lt;/P&gt;&lt;P&gt;preset = xdr_agent_network | filter action_remote_ip = "185.x.x.x"&amp;nbsp;&lt;/P&gt;&lt;P&gt;preset = network_story | filter action_remote_ip = "185.x.x.x"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will there be a possibility to move the informations from XDR_AGENT_NETWORK&amp;nbsp; to NETWORK_STORY?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Apr 2022 19:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/479484#M1856</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-04-09T19:19:43Z</dc:date>
    </item>
    <item>
      <title>Betreff: Query Network</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/479491#M1857</link>
      <description>&lt;P&gt;Am I right? PA will take this useful feautre away, because they wan't to sell us a firewall? We allready have a firewall and we just need this information, which is shown in the&amp;nbsp;xdr_agent_network preset.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/release-information/features-introduced/features-introduced-in-2021" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-release-notes/release-information/features-introduced/features-introduced-in-2021&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV&gt;Network Events Deprecation&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;(&lt;DIV&gt;Starting with the next Cortex XDR release&lt;/DIV&gt;)&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;DIV&gt;After Cortex XDR introduced network collection events, that are stitched across endpoints and the Palo Alto Networks next-generation firewalls logs, there is no longer need to support raw&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;DIV&gt;Network&lt;/DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;events. Starting with the next Cortex XDR release,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;DIV&gt;Network&lt;/DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;events will be deprecated. In light of the upcoming change, Palo Alto Networks encourages you to define BIOC rules and/or searches by using&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;DIV&gt;Network Connections&lt;/DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the Query Builder. When searching in XQL, you should avoid using the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;DIV&gt;xdr_agent_network&lt;/DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;preset and use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;DIV&gt;newtork_story&lt;/DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;preset instead.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Sat, 09 Apr 2022 21:29:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/479491#M1857</guid>
      <dc:creator>Cyber1985</dc:creator>
      <dc:date>2022-04-09T21:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: Query Network</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/480051#M1869</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see if the below XQL helps your case? Please replace the necessary fields as per your requirements.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;config case_sensitive = false
| preset = network_story
| filter agent_hostname = "you_end_point_name" and action_remote_ip != null and dst_action_external_hostname != null
| fields
_time as Time,
actor_process_os_pid as Pid,
actor_process_image_name as Process,
action_local_ip as Local_IP,
dst_action_external_hostname as External_Hostname,
action_remote_ip as Destination_IP,
action_remote_port as Destination_Port
| sort desc Time&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 05:18:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/480051#M1869</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-13T05:18:29Z</dc:date>
    </item>
    <item>
      <title>Re: Query Network</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/480494#M1875</link>
      <description>&lt;P&gt;Hello to ALL!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found the mistake.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was my fault. I didn't check the period in the top right corner when writing the query *shame on me*&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The network_story works like the agent_network_story!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks you very much for the help!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 15 Apr 2022 12:33:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-network/m-p/480494#M1875</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-04-15T12:33:31Z</dc:date>
    </item>
  </channel>
</rss>

