<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XQL &amp;quot;call&amp;quot; functions from scripts library in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510479#M2423</link>
    <description>&lt;P&gt;Hi Bbamanroy,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Yeah.. this one I created myself. Take this for example&lt;/P&gt;
&lt;P&gt;=====&lt;/P&gt;
&lt;P&gt;config case_sensitive = false timeframe = 7d&lt;BR /&gt;| preset = host_inventory_auto_runs &lt;BR /&gt;| filter endpoint_name = $Hostname and cmd in ("*appdata*","c:\users*")&lt;BR /&gt;=====&lt;BR /&gt;I'm taking $Hostname as a parameter for the query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have multiple saved queries in the library that requires a hostname to be passed and I wanted to be able to call them and probably use join/union to merge the results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sure I can use both join/union in the query but I want to make them flexible like:&lt;/P&gt;
&lt;P&gt;I will use w, x, y, and z queries for a certain event&amp;nbsp;&lt;/P&gt;
&lt;P&gt;w, x, and y for another&lt;/P&gt;
&lt;P&gt;and so on..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate the response!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Aug 2022 18:43:02 GMT</pubDate>
    <dc:creator>JillianSagun</dc:creator>
    <dc:date>2022-08-01T18:43:02Z</dc:date>
    <item>
      <title>XQL "call" functions from scripts library</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510345#M2410</link>
      <description>&lt;P&gt;Hi Peeps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So XQL has this call function to fetch results from a saved query in the query library. Lets take this for example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;call "All appdata executions for the past 30 days"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, the problem is that my saved query is waiting for a parameter "$hostname". Anyone have any ideas how to pass that parameter through XQL?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or probably point me to a KB of some sorts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot,&lt;/P&gt;
&lt;P&gt;Jill&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 23:25:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510345#M2410</guid>
      <dc:creator>JillianSagun</dc:creator>
      <dc:date>2022-07-29T23:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: XQL "call" functions from scripts library</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510346#M2411</link>
      <description>&lt;P&gt;Sorry&lt;BR /&gt;&lt;SPAN&gt;XQL "call" functions from &lt;STRONG&gt;query&lt;/STRONG&gt; library I mean&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 23:26:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510346#M2411</guid>
      <dc:creator>JillianSagun</dc:creator>
      <dc:date>2022-07-29T23:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: XQL "call" functions from scripts library</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510385#M2414</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/198067"&gt;@JillianSagun&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go to Query library, and paste the XQL query in the thread here for us to replicate and advise accordingly. I believe this might not be created by Palo Alto Networks.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1659332020885.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42713i4329B92D5D3095B7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_0-1659332020885.png" alt="bbarmanroy_0-1659332020885.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 05:33:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510385#M2414</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-08-01T05:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: XQL "call" functions from scripts library</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510479#M2423</link>
      <description>&lt;P&gt;Hi Bbamanroy,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Yeah.. this one I created myself. Take this for example&lt;/P&gt;
&lt;P&gt;=====&lt;/P&gt;
&lt;P&gt;config case_sensitive = false timeframe = 7d&lt;BR /&gt;| preset = host_inventory_auto_runs &lt;BR /&gt;| filter endpoint_name = $Hostname and cmd in ("*appdata*","c:\users*")&lt;BR /&gt;=====&lt;BR /&gt;I'm taking $Hostname as a parameter for the query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have multiple saved queries in the library that requires a hostname to be passed and I wanted to be able to call them and probably use join/union to merge the results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sure I can use both join/union in the query but I want to make them flexible like:&lt;/P&gt;
&lt;P&gt;I will use w, x, y, and z queries for a certain event&amp;nbsp;&lt;/P&gt;
&lt;P&gt;w, x, and y for another&lt;/P&gt;
&lt;P&gt;and so on..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate the response!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 18:43:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510479#M2423</guid>
      <dc:creator>JillianSagun</dc:creator>
      <dc:date>2022-08-01T18:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: XQL "call" functions from scripts library</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510509#M2425</link>
      <description>&lt;P&gt;This works for me:&lt;BR /&gt;call "Host Inventory Autorun" Hostname="Bisma"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_0-1659406766161.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42722iAF5585111C6E51AB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="bbarmanroy_0-1659406766161.png" alt="bbarmanroy_0-1659406766161.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 02:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510509#M2425</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-08-02T02:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: XQL "call" functions from scripts library</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510577#M2428</link>
      <description>&lt;P&gt;Weird.. I tried something similar but anyways thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Works for me too.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 14:02:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-quot-call-quot-functions-from-scripts-library/m-p/510577#M2428</guid>
      <dc:creator>JillianSagun</dc:creator>
      <dc:date>2022-08-02T14:02:15Z</dc:date>
    </item>
  </channel>
</rss>

