<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CIDR Lookup or Join for IP Enrichment in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cidr-lookup-or-join-for-ip-enrichment/m-p/501775#M2147</link>
    <description>&lt;P&gt;I would like to use some custom datasets to enrich some of our XQL searches.&amp;nbsp; It could be our subnets from our IPAM or in this example the ASN information.&amp;nbsp; I have used lookups and joins in the past to accomplish this in others tools and would like to do the same with Cortex XQL.&amp;nbsp; I did look at incidr and incidrlist but it seems to be the opposite of what I'm looking for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Results would look like below with the ASN org field&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="720"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="159"&gt;_time&lt;/TD&gt;&lt;TD width="197"&gt;actor_process_image_name&lt;/TD&gt;&lt;TD width="125"&gt;action_remote_ip&lt;/TD&gt;&lt;TD width="239"&gt;autonomous_system_organization&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jun 1st 2022&lt;/TD&gt;&lt;TD&gt;curl&lt;/TD&gt;&lt;TD&gt;100.20.0.15&lt;/TD&gt;&lt;TD&gt;AMAZON-02&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Base XQL Search&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;preset = network_story&lt;BR /&gt;| filter actor_process_image_name contains "curl" and action_total_upload &amp;gt; 1048576&lt;BR /&gt;| fields actor_process_image_name, action_remote_ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Custom Dataset&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;dataset = geo_asn_ip4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="649"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="141"&gt;network&lt;/TD&gt;&lt;TD width="227"&gt;autonomous_system_number&lt;/TD&gt;&lt;TD width="281"&gt;autonomous_system_organization&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;100.20.0.0/14&lt;/TD&gt;&lt;TD&gt;16509&lt;/TD&gt;&lt;TD&gt;AMAZON-02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;100.24.0.0/13&lt;/TD&gt;&lt;TD&gt;14618&lt;/TD&gt;&lt;TD&gt;AMAZON-AES&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;103.119.213.0/24&lt;/TD&gt;&lt;TD&gt;16509&lt;/TD&gt;&lt;TD&gt;AMAZON-02&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Bonus Question&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I know that XDR already has the ASN information as they have some alerts based off of it.&amp;nbsp; Is there a way a customer could leverage this data instead of building our own dataset?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jun 2022 14:11:46 GMT</pubDate>
    <dc:creator>GolfHacker</dc:creator>
    <dc:date>2022-06-08T14:11:46Z</dc:date>
    <item>
      <title>CIDR Lookup or Join for IP Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cidr-lookup-or-join-for-ip-enrichment/m-p/501775#M2147</link>
      <description>&lt;P&gt;I would like to use some custom datasets to enrich some of our XQL searches.&amp;nbsp; It could be our subnets from our IPAM or in this example the ASN information.&amp;nbsp; I have used lookups and joins in the past to accomplish this in others tools and would like to do the same with Cortex XQL.&amp;nbsp; I did look at incidr and incidrlist but it seems to be the opposite of what I'm looking for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Results would look like below with the ASN org field&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE width="720"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="159"&gt;_time&lt;/TD&gt;&lt;TD width="197"&gt;actor_process_image_name&lt;/TD&gt;&lt;TD width="125"&gt;action_remote_ip&lt;/TD&gt;&lt;TD width="239"&gt;autonomous_system_organization&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Jun 1st 2022&lt;/TD&gt;&lt;TD&gt;curl&lt;/TD&gt;&lt;TD&gt;100.20.0.15&lt;/TD&gt;&lt;TD&gt;AMAZON-02&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Base XQL Search&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;preset = network_story&lt;BR /&gt;| filter actor_process_image_name contains "curl" and action_total_upload &amp;gt; 1048576&lt;BR /&gt;| fields actor_process_image_name, action_remote_ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Custom Dataset&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;dataset = geo_asn_ip4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE width="649"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="141"&gt;network&lt;/TD&gt;&lt;TD width="227"&gt;autonomous_system_number&lt;/TD&gt;&lt;TD width="281"&gt;autonomous_system_organization&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;100.20.0.0/14&lt;/TD&gt;&lt;TD&gt;16509&lt;/TD&gt;&lt;TD&gt;AMAZON-02&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;100.24.0.0/13&lt;/TD&gt;&lt;TD&gt;14618&lt;/TD&gt;&lt;TD&gt;AMAZON-AES&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;103.119.213.0/24&lt;/TD&gt;&lt;TD&gt;16509&lt;/TD&gt;&lt;TD&gt;AMAZON-02&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Bonus Question&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I know that XDR already has the ASN information as they have some alerts based off of it.&amp;nbsp; Is there a way a customer could leverage this data instead of building our own dataset?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 14:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cidr-lookup-or-join-for-ip-enrichment/m-p/501775#M2147</guid>
      <dc:creator>GolfHacker</dc:creator>
      <dc:date>2022-06-08T14:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: CIDR Lookup or Join for IP Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cidr-lookup-or-join-for-ip-enrichment/m-p/506410#M2285</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222722"&gt;@GolfHacker&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for posting to our Live Community Forum. Currently the ASN information is not present in the XQL so we recommend leveraging custom datasets just like the one you've created for mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Silviu&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 11:04:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cidr-lookup-or-join-for-ip-enrichment/m-p/506410#M2285</guid>
      <dc:creator>SilviuMihailDascalu</dc:creator>
      <dc:date>2022-06-27T11:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: CIDR Lookup or Join for IP Enrichment</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cidr-lookup-or-join-for-ip-enrichment/m-p/506461#M2286</link>
      <description>&lt;P&gt;That is good to know that a custom dataset is the only option today.&lt;BR /&gt;&lt;BR /&gt;Do you know of an XQL command that will work with a custom CIDR dataset like I have listed above?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 13:54:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cidr-lookup-or-join-for-ip-enrichment/m-p/506461#M2286</guid>
      <dc:creator>GolfHacker</dc:creator>
      <dc:date>2022-06-27T13:54:10Z</dc:date>
    </item>
  </channel>
</rss>

