<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exporting alert related data in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510174#M2400</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223431"&gt;@MithunKT&lt;/a&gt;&amp;nbsp;You would be able to retrieve alert data by selecting an existing alert only.&lt;BR /&gt;&lt;BR /&gt;To retrieve the alert data follow the documentation here: &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoint-alerts/manage-alerts.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoint-alerts/manage-alerts.html&lt;/A&gt;&lt;BR /&gt;See section Retrieve Additional Alert Details&lt;BR /&gt;In Step 2 - follow the Retrieve alert data section&lt;BR /&gt;Once in new tab(pivot to view Additional data) right click, then Download Files&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jul 2022 12:02:01 GMT</pubDate>
    <dc:creator>creddy</dc:creator>
    <dc:date>2022-07-28T12:02:01Z</dc:date>
    <item>
      <title>Exporting alert related data</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510145#M2398</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to export all the alert data which appears below Causality chain like network connections, registry changes, etc ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't see any download or export icon on the right-hand side of the pane.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do we have any other way to export these data?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!!&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Thu, 28 Jul 2022 07:07:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510145#M2398</guid>
      <dc:creator>MithunKT</dc:creator>
      <dc:date>2022-07-28T07:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting alert related data</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510174#M2400</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223431"&gt;@MithunKT&lt;/a&gt;&amp;nbsp;You would be able to retrieve alert data by selecting an existing alert only.&lt;BR /&gt;&lt;BR /&gt;To retrieve the alert data follow the documentation here: &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoint-alerts/manage-alerts.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoint-alerts/manage-alerts.html&lt;/A&gt;&lt;BR /&gt;See section Retrieve Additional Alert Details&lt;BR /&gt;In Step 2 - follow the Retrieve alert data section&lt;BR /&gt;Once in new tab(pivot to view Additional data) right click, then Download Files&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jul 2022 12:02:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510174#M2400</guid>
      <dc:creator>creddy</dc:creator>
      <dc:date>2022-07-28T12:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting alert related data</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510228#M2404</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/223431"&gt;@MithunKT&lt;/a&gt;&amp;nbsp;what is the use case you're trying to achieve by exporting the data? Is the end goal to ingest into a SIEM?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 01:59:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510228#M2404</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-07-29T01:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting alert related data</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510266#M2408</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192661"&gt;@bbarmanroy&lt;/a&gt;&amp;nbsp;it was for analysis and Investigation purposes. We got an incident from Analytics alert source stating internal scanning was observed, on checking the alert data we found multiple failed network connections from a single host towards multiple internal Destinations.&lt;/P&gt;
&lt;P&gt;We just wanted to pass on this data (List of destinations, protocols) everything to the network team but exporting option was not available.&lt;/P&gt;
&lt;P&gt;So how do we export the data in these scenarios?&amp;nbsp; We can't give access to the XDR console to our network team but they should be given alert data in csv or tsv format.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 08:25:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510266#M2408</guid>
      <dc:creator>MithunKT</dc:creator>
      <dc:date>2022-07-29T08:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Exporting alert related data</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510384#M2413</link>
      <description>&lt;P&gt;You can run a XQL query to retrieve the information and export the data to pass to your n/w Ops team.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1659326605613.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42710i1509B050664052B6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1659326605613.png" alt="bbarmanroy_0-1659326605613.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also leverage the Network Connections in Query Builder to identify connections.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_2-1659326711085.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42712i43E7403C474E8F8D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_2-1659326711085.png" alt="bbarmanroy_2-1659326711085.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_1-1659326653295.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42711iAEC00FA23FD4AB7E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_1-1659326653295.png" alt="bbarmanroy_1-1659326653295.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The results can be downloaded in TSV format and shared across other teams.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 04:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/exporting-alert-related-data/m-p/510384#M2413</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-08-01T04:05:53Z</dc:date>
    </item>
  </channel>
</rss>

