<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Device control violation alert\bioc in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/device-control-violation-alert-bioc/m-p/501312#M2131</link>
    <description>&lt;P&gt;Im looking for a way to alert when a device control violation occurs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently ive not found a xql query that works&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jun 2022 15:07:50 GMT</pubDate>
    <dc:creator>NathanBradley</dc:creator>
    <dc:date>2022-06-07T15:07:50Z</dc:date>
    <item>
      <title>Device control violation alert\bioc</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/device-control-violation-alert-bioc/m-p/501312#M2131</link>
      <description>&lt;P&gt;Im looking for a way to alert when a device control violation occurs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently ive not found a xql query that works&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 15:07:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/device-control-violation-alert-bioc/m-p/501312#M2131</guid>
      <dc:creator>NathanBradley</dc:creator>
      <dc:date>2022-06-07T15:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Device control violation alert\bioc</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/device-control-violation-alert-bioc/m-p/501544#M2141</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24508"&gt;@NathanBradley&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know I think the case still exists as outlined in the below community link:&lt;BR /&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/device-control-violations-amp-xql/td-p/426157" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/device-control-violations-amp-xql/td-p/426157&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The link also provides &lt;STRONG&gt;a hint&lt;/STRONG&gt; on how you can built your own custom notification using the &lt;STRONG&gt;"Get Violation API"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/endpoint-management/get-violations" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/endpoint-management/get-violations&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you can do here is, create a csv file of the violation being pulled from XDR API and then ingest in SIEM for notifications or other stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 00:57:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/device-control-violation-alert-bioc/m-p/501544#M2141</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-06-08T00:57:51Z</dc:date>
    </item>
  </channel>
</rss>

