<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Event_Sub_Type Failed to run in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510707#M2449</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD colspan="1" class=""&gt;1&lt;/TD&gt;
&lt;TD colspan="1" class=""&gt;create_new&lt;/TD&gt;
&lt;TD class=""&gt;2&lt;/TD&gt;
&lt;TD class=""&gt;open&lt;/TD&gt;
&lt;TD class=""&gt;3&lt;/TD&gt;
&lt;TD class=""&gt;rename&lt;/TD&gt;
&lt;TD class=""&gt;4&lt;/TD&gt;
&lt;TD class=""&gt;link&lt;/TD&gt;
&lt;TD class=""&gt;5&lt;/TD&gt;
&lt;TD class=""&gt;remove&lt;/TD&gt;
&lt;TD class=""&gt;6&lt;/TD&gt;
&lt;TD class=""&gt;write&lt;/TD&gt;
&lt;TD class=""&gt;7&lt;/TD&gt;
&lt;TD class=""&gt;set_attribute&lt;/TD&gt;
&lt;TD class=""&gt;8&lt;/TD&gt;
&lt;TD class=""&gt;dir_create&lt;/TD&gt;
&lt;TD class=""&gt;9&lt;/TD&gt;
&lt;TD class=""&gt;dir_open&lt;/TD&gt;
&lt;TD class=""&gt;10&lt;/TD&gt;
&lt;TD class=""&gt;dir_rename&lt;/TD&gt;
&lt;TD class=""&gt;11&lt;/TD&gt;
&lt;TD class=""&gt;dir_link&lt;/TD&gt;
&lt;TD class=""&gt;12&lt;/TD&gt;
&lt;TD class=""&gt;dir_remove&lt;/TD&gt;
&lt;TD class=""&gt;13&lt;/TD&gt;
&lt;TD class=""&gt;dir_write&lt;/TD&gt;
&lt;TD class=""&gt;14&lt;/TD&gt;
&lt;TD class=""&gt;dir_set_attr&lt;/TD&gt;
&lt;TD class=""&gt;15&lt;/TD&gt;
&lt;TD class=""&gt;reparse&lt;/TD&gt;
&lt;TD class=""&gt;16&lt;/TD&gt;
&lt;TD class=""&gt;set_sec&lt;/TD&gt;
&lt;TD class=""&gt;17&lt;/TD&gt;
&lt;TD class=""&gt;dir_set_sec&lt;/TD&gt;
&lt;TD class=""&gt;18&lt;/TD&gt;
&lt;TD class=""&gt;change_mode&lt;/TD&gt;
&lt;TD class=""&gt;19&lt;/TD&gt;
&lt;TD class=""&gt;dir_change_mode&lt;/TD&gt;
&lt;TD class=""&gt;20&lt;/TD&gt;
&lt;TD class=""&gt;change_owner&lt;/TD&gt;
&lt;TD class=""&gt;21&lt;/TD&gt;
&lt;TD class=""&gt;dir_change_owner&lt;/TD&gt;
&lt;TD class=""&gt;22&lt;/TD&gt;
&lt;TD class=""&gt;dir_query&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
    <pubDate>Wed, 03 Aug 2022 14:36:42 GMT</pubDate>
    <dc:creator>afurze</dc:creator>
    <dc:date>2022-08-03T14:36:42Z</dc:date>
    <item>
      <title>Event_Sub_Type Failed to run</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510605#M2432</link>
      <description>&lt;P&gt;When running this XQL query if I&amp;nbsp;add event_sub_type to the filter it fails to run&lt;/P&gt;
&lt;P&gt;I can run the query without any filters, and then add the event_sub_type column without issues&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dataset = xdr_data&lt;BR /&gt;| filter event_type = ENUM.FILE and (event_sub_type = ENUM.FILE_CREATE_NEW or event_sub_type = ENUM.FILE_WRITE or event_sub_type = enum.FILE_OPEN )&lt;BR /&gt;| filter agent_ip_addresses = "x.x.x.x"&lt;BR /&gt;| filter action_file_path contains "Path" &lt;BR /&gt;| filter action_file_name not contains "$"&lt;BR /&gt;| filter action_file_extension != "tmp"&lt;BR /&gt;| fields agent_hostname, agent_ip_addresses, actor_effective_username, action_file_name, action_file_path, action_file_extension, &lt;STRONG&gt;event_sub_type &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NathanBradley_0-1659458727567.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42743iB975481EA7CA0877/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="NathanBradley_0-1659458727567.png" alt="NathanBradley_0-1659458727567.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 16:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510605#M2432</guid>
      <dc:creator>NathanBradley</dc:creator>
      <dc:date>2022-08-02T16:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Event_Sub_Type Failed to run</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510617#M2435</link>
      <description>&lt;P&gt;Hi NathanBradley,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is definitely a strange behavior, I'm honestly not sure why this query is failing.&amp;nbsp; I was able to get the following query to work successfully&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = xdr_data
| filter event_type = ENUM.FILE
| filter event_sub_type in (ENUM.FILE_OPEN, ENUM.FILE_CREATE_NEW, ENUM.FILE_WRITE)
| filter agent_ip_addresses = “x.x.x.x”
| filter action_file_path contains “Path”
| filter action_file_name not contains “$”
| filter action_file_extension != “tmp”
| alter file_action = if(event_sub_type = 1, replace(to_string(event_sub_type), “1”, “CREATE”), if(event_sub_type = 6, replace(to_string(event_sub_type), “6”, “WRITE”), if(event_sub_type = 2, replace(to_string(event_sub_type), “2”, “OPEN”))))
| fields agent_hostname, agent_ip_addresses, actor_effective_username, action_file_name, action_file_path, action_file_extension, file_action&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 02 Aug 2022 18:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510617#M2435</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-02T18:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Event_Sub_Type Failed to run</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510620#M2436</link>
      <description>&lt;P&gt;Thanks, It does get what im needing&lt;/P&gt;
&lt;P&gt;But it didnt replace the numerical value&lt;/P&gt;
&lt;P&gt;Also where did you get the numerical values for event_sub_type&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NathanBradley_0-1659465584069.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42745iB504A6507743B572/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="NathanBradley_0-1659465584069.png" alt="NathanBradley_0-1659465584069.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Aug 2022 18:42:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510620#M2436</guid>
      <dc:creator>NathanBradley</dc:creator>
      <dc:date>2022-08-02T18:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Event_Sub_Type Failed to run</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510703#M2447</link>
      <description>&lt;P&gt;Hmm, for some reason the XQL query does not like to be copied and pasted.&amp;nbsp; I had to remove the "1", "CREATE", "2", "OPEN", "6", "WRITE", and then type them in again before it would properly replace.&amp;nbsp; It doesn't appear that these values have public documentation, I was able to reference some internal documentation.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 14:20:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510703#M2447</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-03T14:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Event_Sub_Type Failed to run</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510704#M2448</link>
      <description>&lt;P&gt;Thanks, did that and it worked&lt;/P&gt;
&lt;P&gt;Can the other numerical values for the other event sub types be shared?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 14:29:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510704#M2448</guid>
      <dc:creator>NathanBradley</dc:creator>
      <dc:date>2022-08-03T14:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Event_Sub_Type Failed to run</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510707#M2449</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD colspan="1" class=""&gt;1&lt;/TD&gt;
&lt;TD colspan="1" class=""&gt;create_new&lt;/TD&gt;
&lt;TD class=""&gt;2&lt;/TD&gt;
&lt;TD class=""&gt;open&lt;/TD&gt;
&lt;TD class=""&gt;3&lt;/TD&gt;
&lt;TD class=""&gt;rename&lt;/TD&gt;
&lt;TD class=""&gt;4&lt;/TD&gt;
&lt;TD class=""&gt;link&lt;/TD&gt;
&lt;TD class=""&gt;5&lt;/TD&gt;
&lt;TD class=""&gt;remove&lt;/TD&gt;
&lt;TD class=""&gt;6&lt;/TD&gt;
&lt;TD class=""&gt;write&lt;/TD&gt;
&lt;TD class=""&gt;7&lt;/TD&gt;
&lt;TD class=""&gt;set_attribute&lt;/TD&gt;
&lt;TD class=""&gt;8&lt;/TD&gt;
&lt;TD class=""&gt;dir_create&lt;/TD&gt;
&lt;TD class=""&gt;9&lt;/TD&gt;
&lt;TD class=""&gt;dir_open&lt;/TD&gt;
&lt;TD class=""&gt;10&lt;/TD&gt;
&lt;TD class=""&gt;dir_rename&lt;/TD&gt;
&lt;TD class=""&gt;11&lt;/TD&gt;
&lt;TD class=""&gt;dir_link&lt;/TD&gt;
&lt;TD class=""&gt;12&lt;/TD&gt;
&lt;TD class=""&gt;dir_remove&lt;/TD&gt;
&lt;TD class=""&gt;13&lt;/TD&gt;
&lt;TD class=""&gt;dir_write&lt;/TD&gt;
&lt;TD class=""&gt;14&lt;/TD&gt;
&lt;TD class=""&gt;dir_set_attr&lt;/TD&gt;
&lt;TD class=""&gt;15&lt;/TD&gt;
&lt;TD class=""&gt;reparse&lt;/TD&gt;
&lt;TD class=""&gt;16&lt;/TD&gt;
&lt;TD class=""&gt;set_sec&lt;/TD&gt;
&lt;TD class=""&gt;17&lt;/TD&gt;
&lt;TD class=""&gt;dir_set_sec&lt;/TD&gt;
&lt;TD class=""&gt;18&lt;/TD&gt;
&lt;TD class=""&gt;change_mode&lt;/TD&gt;
&lt;TD class=""&gt;19&lt;/TD&gt;
&lt;TD class=""&gt;dir_change_mode&lt;/TD&gt;
&lt;TD class=""&gt;20&lt;/TD&gt;
&lt;TD class=""&gt;change_owner&lt;/TD&gt;
&lt;TD class=""&gt;21&lt;/TD&gt;
&lt;TD class=""&gt;dir_change_owner&lt;/TD&gt;
&lt;TD class=""&gt;22&lt;/TD&gt;
&lt;TD class=""&gt;dir_query&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Wed, 03 Aug 2022 14:36:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/event-sub-type-failed-to-run/m-p/510707#M2449</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-03T14:36:42Z</dc:date>
    </item>
  </channel>
</rss>

