<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XQL Query for incidents/alerts in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515214#M2847</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks. We were looking for a similar widget as in the total number of open incidents but customized to last 7 days. For alerts like the top 4 alerts in the last 7 days , Something along those lines...&lt;/P&gt;</description>
    <pubDate>Sun, 18 Sep 2022 17:23:15 GMT</pubDate>
    <dc:creator>NivedaR</dc:creator>
    <dc:date>2022-09-18T17:23:15Z</dc:date>
    <item>
      <title>XQL Query for incidents/alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515211#M2845</link>
      <description>&lt;P&gt;Hello ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a way to create XQL query for the details related to incidents or alerts for past 7 days that can be used as a widget . The current widget options do no give us the output we require.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 15:17:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515211#M2845</guid>
      <dc:creator>NivedaR</dc:creator>
      <dc:date>2022-09-18T15:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query for incidents/alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515213#M2846</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203132"&gt;@NivedaR&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As of now we do not support XQL on incidents and alerts as incidents and alerts are processed data and XQL shows only raw events for the data we gather.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, we would like to know your used case for details on incidents and alerts as to what is the exact data you would want to see so that we could help you with more specific answer to the above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 16:45:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515213#M2846</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-09-18T16:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query for incidents/alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515214#M2847</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks. We were looking for a similar widget as in the total number of open incidents but customized to last 7 days. For alerts like the top 4 alerts in the last 7 days , Something along those lines...&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 17:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515214#M2847</guid>
      <dc:creator>NivedaR</dc:creator>
      <dc:date>2022-09-18T17:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query for incidents/alerts</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515219#M2848</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203132"&gt;@NivedaR&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We understand your request. As stated above, though there's not much customisation available to the same. However, one of your used cases can be covered and that is with respect to new incidents over a 7 days period. We have a Security Admin Dashboard with widget which shows incidents generated(vs resolved) over a period of time which is a period of 7 days. Sample screenshot attached for reference.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a workaround, if this suits you fine. Alternatively, you can&amp;nbsp; reach out to your Customer Success Teams or TAC team to raise a feature request for the same.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-09-19 at 2.49.32 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43941i9776B946E403F302/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2022-09-19 at 2.49.32 AM.png" alt="Screenshot 2022-09-19 at 2.49.32 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 18:53:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-incidents-alerts/m-p/515219#M2848</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-09-18T18:53:07Z</dc:date>
    </item>
  </channel>
</rss>

