<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to query XDR for all incidents that relate to a device group in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506350#M2281</link>
    <description>&lt;P&gt;These widgets are leveraging the built-in functions not currently exposed in the User Interface but via API.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jun 2022 07:40:29 GMT</pubDate>
    <dc:creator>SilviuMihailDascalu</dc:creator>
    <dc:date>2022-06-27T07:40:29Z</dc:date>
    <item>
      <title>How to query XDR for all incidents that relate to a device group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/503808#M2198</link>
      <description>&lt;P&gt;The&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/get-incidents" target="_self"&gt;Get Incidents API&lt;/A&gt;&amp;nbsp;allows you to filter based on an incident_id_list, but not a list of endpoint_ids much less endpoint group. The&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-api/cortex-xdr-apis/incident-management/get-alerts" target="_self"&gt;Get Alerts API&lt;/A&gt;&amp;nbsp;allows you to filter on an alert_id_list, but not a list of endpoint_ids much less endpoint group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to figure out how to get a list of alert_ids or incident_ids filtered by endpoint group or even endpoint_id so that I could use it filter either of the above API's. I can't figure out how build a query in XDR for this because I don't see any endpoint or incident information in the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-xql-schema-reference/all-xdr-data-fields/all-xdr-data-fields-reference" target="_self"&gt;xdr_data schema&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems like a standard bit of data to pull.. just incidents or alerts by endpoint but I can't seem to figure it out. What am I missing?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 13:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/503808#M2198</guid>
      <dc:creator>JamesWiggins</dc:creator>
      <dc:date>2022-06-15T13:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to query XDR for all incidents that relate to a device group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/503913#M2203</link>
      <description>&lt;P&gt;Hi JamesWiggins,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, Incidents and Alerts are not exposed as a dataset so they cannot be queried using XQL.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2022 19:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/503913#M2203</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-06-15T19:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to query XDR for all incidents that relate to a device group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506349#M2280</link>
      <description>&lt;P&gt;Hi Afurze&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how do the Palo Alto provided widgets filter on incidents (for example the widgets 'incidents by assignee' or 'incidents by status'?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Danny&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 07:33:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506349#M2280</guid>
      <dc:creator>DannyMulheran</dc:creator>
      <dc:date>2022-06-27T07:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to query XDR for all incidents that relate to a device group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506350#M2281</link>
      <description>&lt;P&gt;These widgets are leveraging the built-in functions not currently exposed in the User Interface but via API.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 07:40:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506350#M2281</guid>
      <dc:creator>SilviuMihailDascalu</dc:creator>
      <dc:date>2022-06-27T07:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to query XDR for all incidents that relate to a device group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506351#M2282</link>
      <description>&lt;P&gt;Hey James,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you ever thought about retrieving the incidents and alerts and then mapping them in the code to the endpoint groups? In short what I'm saying is that you can easily filter by endpoints directly from your code.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jun 2022 07:46:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506351#M2282</guid>
      <dc:creator>SilviuMihailDascalu</dc:creator>
      <dc:date>2022-06-27T07:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to query XDR for all incidents that relate to a device group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506352#M2283</link>
      <description>&lt;DIV class=""&gt;Hi Silviu&lt;/DIV&gt;&lt;DIV class=""&gt;Good to hear from you.&amp;nbsp; Thanks for the info which led me to try using the XDR integration command (example test !xdr-get-incidents gte_creation_time="2022-06-20T23:59:00" raw-response=true) in XSOAR. I will create my report in XSOAR instead.&lt;/DIV&gt;&lt;DIV class=""&gt;Regards&lt;/DIV&gt;&lt;DIV class=""&gt;Danny&lt;/DIV&gt;</description>
      <pubDate>Mon, 27 Jun 2022 08:00:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/506352#M2283</guid>
      <dc:creator>DannyMulheran</dc:creator>
      <dc:date>2022-06-27T08:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to query XDR for all incidents that relate to a device group</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/507665#M2316</link>
      <description>&lt;P&gt;Yes, this is exactly what I ended up doing. I had to pull down all of the incidents for the tenant, and then filter the incidents by host in script with a list of endpoint ID's I had previously retrieved from the get_endpoints API. Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 13:12:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/how-to-query-xdr-for-all-incidents-that-relate-to-a-device-group/m-p/507665#M2316</guid>
      <dc:creator>JamesWiggins</dc:creator>
      <dc:date>2022-07-01T13:12:53Z</dc:date>
    </item>
  </channel>
</rss>

