<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automation of Reports in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534642#M3848</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/276269"&gt;@PiyushKohli&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We need to create a report for the alerts that are triggered for the above files. Is the possible to automate report based on alerts?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Mar 2023 05:31:11 GMT</pubDate>
    <dc:creator>RamyashreeMada</dc:creator>
    <dc:date>2023-03-16T05:31:11Z</dc:date>
    <item>
      <title>Automation of Reports</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534506#M3844</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;We need to create automated XDR report to detect executions of “Python.exe” and “PowerShell.exe &amp;amp; PowerShell_ise.exe” in our environment.&lt;/LI&gt;
&lt;LI&gt;Can we query a incident/alerts to make a report or suggest us how we can generate reports based on the above requirements.&lt;/LI&gt;
&lt;LI&gt;Can we configure a scheduler in this report so that all the intended recipients would receive this report.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 17:06:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534506#M3844</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-03-15T17:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Automation of Reports</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534641#M3847</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For your above use case, one approach could be by creating a new Report from scratch under the Report Template using XQL Query and under XQL query bolt query to search for actor/action process image name with&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;“Python.exe” , “PowerShell.exe" &amp;amp; "PowerShell_ise.exe”. However you may have to tweak this query to exclude administrative executions of this processes based on your Use Case.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For Report creation you may refer to &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/how-to-video-playlist-cortex-xdr-dashboards-amp-reports/ta-p/415324" target="_self"&gt;this&amp;nbsp;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Report_builder.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48811i2771F592BE73A578/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Report_builder.png" alt="Report_builder.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps!&lt;BR /&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 05:10:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534641#M3847</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-03-16T05:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Automation of Reports</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534642#M3848</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/276269"&gt;@PiyushKohli&lt;/a&gt;,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We need to create a report for the alerts that are triggered for the above files. Is the possible to automate report based on alerts?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 05:31:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534642#M3848</guid>
      <dc:creator>RamyashreeMada</dc:creator>
      <dc:date>2023-03-16T05:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Automation of Reports</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534654#M3849</link>
      <description>&lt;P&gt;You may try the below query and see if this results with your requirement. This did work for us.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dataset = xdr_data &lt;BR /&gt;|filter event_type = ENUM.PROCESS &lt;BR /&gt;|filter lowercase(actor_process_image_name ) ="python.exe" or lowercase(actor_process_image_name ) ="powershell.exe" or lowercase(actor_process_image_name ) ="powershell_ise.exe"&lt;BR /&gt;|fields causality_actor_process_image_path, actor_process_image_path, agent_hostname, action_file_path, action_file_name&lt;BR /&gt;|dedup causality_actor_process_image_path, actor_process_image_path, agent_hostname, action_file_path, action_file_name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 07:42:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534654#M3849</guid>
      <dc:creator>VenuK</dc:creator>
      <dc:date>2023-03-16T07:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Automation of Reports</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534680#M3850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/206335"&gt;@RamyashreeMada&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for clarifying. Since you need a report/notification for&amp;nbsp;&lt;SPAN&gt;the alerts that are triggered for mentioned processes. You may configure the Notifications under Configuration for the same.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Reference&lt;SPAN&gt;&amp;nbsp;URL:&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Configure-Notification-Forwarding" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Configure-Notification-Forwarding&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Screenshot for Reference:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="notification.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48825i6DEEA8CE7E0F2A78/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="notification.png" alt="notification.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: Update the configuration scope according to your Use Case, so that all alerts corresponding to those processes for which you want to be notified are selected.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Aside to&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239161"&gt;@VenuK&lt;/a&gt;&amp;nbsp;. Thanks for sharing the query!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please mark the response as "Accept as Solution" if it answers your query.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 09:02:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/automation-of-reports/m-p/534680#M3850</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-03-16T09:02:08Z</dc:date>
    </item>
  </channel>
</rss>

