<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Console Events visibility on XDR Dashboard in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-console-events-visibility-on-xdr-dashboard/m-p/528861#M3479</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I need the events from the screenshot below to be visible from the Cortex XDR dashboard. Is there any XQL query that could showcase these events with the endpoints hostname?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MayurLad_0-1674823579578.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47465iB78D0C01D4DB0BDB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MayurLad_0-1674823579578.png" alt="MayurLad_0-1674823579578.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2023 12:46:36 GMT</pubDate>
    <dc:creator>MayurLad</dc:creator>
    <dc:date>2023-01-27T12:46:36Z</dc:date>
    <item>
      <title>Endpoint Console Events visibility on XDR Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-console-events-visibility-on-xdr-dashboard/m-p/528861#M3479</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I need the events from the screenshot below to be visible from the Cortex XDR dashboard. Is there any XQL query that could showcase these events with the endpoints hostname?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MayurLad_0-1674823579578.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47465iB78D0C01D4DB0BDB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MayurLad_0-1674823579578.png" alt="MayurLad_0-1674823579578.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 12:46:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-console-events-visibility-on-xdr-dashboard/m-p/528861#M3479</guid>
      <dc:creator>MayurLad</dc:creator>
      <dc:date>2023-01-27T12:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Console Events visibility on XDR Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-console-events-visibility-on-xdr-dashboard/m-p/528865#M3481</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/270308"&gt;@MayurLad&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Incidents and alert data is not part of the XQL dataset to query upon. However, all of the events convert to XDR alerts and hence, you can navigate to alerts table to filter out all alerts from a particular hostname.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use the filter as mentioned here: alert source=XDR Agent AND hostname="xxxx" Timestamp="&amp;lt;your choice of timestamp&amp;gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 13:00:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-console-events-visibility-on-xdr-dashboard/m-p/528865#M3481</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-01-27T13:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Console Events visibility on XDR Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-console-events-visibility-on-xdr-dashboard/m-p/529111#M3491</link>
      <description>&lt;P&gt;I was able to find the required incidents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 05:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/endpoint-console-events-visibility-on-xdr-dashboard/m-p/529111#M3491</guid>
      <dc:creator>MayurLad</dc:creator>
      <dc:date>2023-01-30T05:45:49Z</dc:date>
    </item>
  </channel>
</rss>

