<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Query Builder in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-builder/m-p/510724#M2453</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/229028"&gt;@willh1&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you have already confirmed that the Cortex Data Lake is sending the necessary logs (following the adequate procedures found at the documentation listed below), please ensure that you are able to view the firewall on the hub. From apps.paloaltonetworks.com/apps, navigate to the “Cortex Data Lake” app and ensure that your configured firewall is connected. This is indicated on the Inventory page with a green connected button under the "Connection Status" column.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please ensure that you have an up-to-date Pro-per-TB license as well since it could be the case that you are not hitting a quota under Dataset Management with an expired license. Navigate to Configurations &amp;gt; Data Management &amp;gt; Dataset Management to view your quota under the "Storage License Details" and ensure it does not exceed as indicated by the graph.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Would you be able to provide the query you are searching with on the Query Builder or see if there are any results when utilizing the Network Connection query?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Relevant documentation:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Start sending logs to the Cortex Data Lake:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;View Data Lake Inventory to see if the Firewall is connected:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/monitor-cortex-data-lake/devices-tab" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/monitor-cortex-data-lake/devices-tab&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Data Management page:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/data-management/dataset-management" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/data-management/dataset-management&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Aug 2022 19:17:11 GMT</pubDate>
    <dc:creator>mfakhouri</dc:creator>
    <dc:date>2022-08-03T19:17:11Z</dc:date>
    <item>
      <title>Cortex XDR Query Builder</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-builder/m-p/510307#M2427</link>
      <description>&lt;P&gt;Hello Community,&lt;BR /&gt;&lt;BR /&gt;Was wondering whether someone could assit me with an issue.&lt;BR /&gt;&lt;BR /&gt;So at the moment i cannot make any search via the "Query Builder".&lt;BR /&gt;&lt;BR /&gt;When i move to query center and create a custom query i can only return results when i search "&lt;SPAN class=""&gt;dataset = pan_ngfw"&lt;BR /&gt;&lt;BR /&gt;when i enter a search for network story i get results but with barely any information (below)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I have checked that cortex data lake is sending all necsassary logs from fw (file_data, threat, traffic, global protect etc)&lt;BR /&gt;&lt;BR /&gt;Can someone please adivse&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="willh1_0-1659109209207.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/42696iC345FBF3D0021B65/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="willh1_0-1659109209207.png" alt="willh1_0-1659109209207.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 15:46:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-builder/m-p/510307#M2427</guid>
      <dc:creator>willh1</dc:creator>
      <dc:date>2022-07-29T15:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Query Builder</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-builder/m-p/510724#M2453</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/229028"&gt;@willh1&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you have already confirmed that the Cortex Data Lake is sending the necessary logs (following the adequate procedures found at the documentation listed below), please ensure that you are able to view the firewall on the hub. From apps.paloaltonetworks.com/apps, navigate to the “Cortex Data Lake” app and ensure that your configured firewall is connected. This is indicated on the Inventory page with a green connected button under the "Connection Status" column.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please ensure that you have an up-to-date Pro-per-TB license as well since it could be the case that you are not hitting a quota under Dataset Management with an expired license. Navigate to Configurations &amp;gt; Data Management &amp;gt; Dataset Management to view your quota under the "Storage License Details" and ensure it does not exceed as indicated by the graph.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Would you be able to provide the query you are searching with on the Query Builder or see if there are any results when utilizing the Network Connection query?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Relevant documentation:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Start sending logs to the Cortex Data Lake:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/get-started-with-cortex-data-lake/start-sending-logs-to-cortex-data-lake&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;View Data Lake Inventory to see if the Firewall is connected:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/monitor-cortex-data-lake/devices-tab" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-data-lake/cortex-data-lake-getting-started/monitor-cortex-data-lake/devices-tab&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Data Management page:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/data-management/dataset-management" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/data-management/dataset-management&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 19:17:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-builder/m-p/510724#M2453</guid>
      <dc:creator>mfakhouri</dc:creator>
      <dc:date>2022-08-03T19:17:11Z</dc:date>
    </item>
  </channel>
</rss>

