<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XQL Query in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-query/m-p/509912#M2390</link>
    <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sort of new to XDR does anyone have any good xql queries for detecting assets without cortex agents installed and if the cyserver service has stopped working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jul 2022 14:19:42 GMT</pubDate>
    <dc:creator>KarlHalpin</dc:creator>
    <dc:date>2022-07-26T14:19:42Z</dc:date>
    <item>
      <title>Cortex XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-query/m-p/509912#M2390</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sort of new to XDR does anyone have any good xql queries for detecting assets without cortex agents installed and if the cyserver service has stopped working?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 14:19:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-query/m-p/509912#M2390</guid>
      <dc:creator>KarlHalpin</dc:creator>
      <dc:date>2022-07-26T14:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-query/m-p/509981#M2391</link>
      <description>&lt;P data-unlink="true"&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211922"&gt;@KarlHalpin&lt;/a&gt;&amp;nbsp;The Agent Service is captured in the &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/monitoring/monitor-agent-activity" target="_self"&gt;Agent Audit Logs&lt;/A&gt;. The agent audit logs are not currently exposed as a dataset in ordered to be queried utilizing XQL. The agent audit logs are able to be exported to file or you may to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/logs/create-notifications#ida889bdb8-1bb5-4133-b6c4-e39d02a3d67b" target="_self"&gt;configure notification forwarding&lt;/A&gt; to support your monitoring needs.&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;From an XQL enablement standpoint, there is a new feature to &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/response-actions/pause-endpoint-protection#:~:text=Prevent%20Administrator%E2%80%99s%20Guide-,Pause%20Endpoint%20Protection,-PREVIOUS" target="_self"&gt;Pause Endpoint Protection&lt;/A&gt; that requires the Cortex XDR agent 7.7 and above, which is apart of the Endpoints dataset; therefore, you can leverage XQL. Please reference the following example query:&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;dataset = endpoints |filter manual_protection_pause = "PROTECTION_PAUSED"&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;The results from this XQL query will display only endpoints that are configured with the XDR agent and have the endpoint protection manually paused.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2022 21:00:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-query/m-p/509981#M2391</guid>
      <dc:creator>WSeldenIII</dc:creator>
      <dc:date>2022-07-26T21:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-query/m-p/510021#M2392</link>
      <description>&lt;P&gt;To add onto what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/130343"&gt;@WSeldenIII&lt;/a&gt;&amp;nbsp;stated for endpoints without XDR, you can achieeve the same with &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-network-mapper" target="_blank"&gt;Network Mapper&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Alternately, you can look at integrating &lt;A href="https://docs.paloaltonetworks.com/cloud-identity/cloud-identity-engine-getting-started/get-started-with-the-cloud-identity-engine/learn-about-the-cloud-identity-engine" target="_blank"&gt;Cloud Identity Engine&lt;/A&gt; and compare the assets with endpoints dataset and identify the assets that do not appear in both datasets with XQL.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 06:59:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xql-query/m-p/510021#M2392</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-07-27T06:59:42Z</dc:date>
    </item>
  </channel>
</rss>

