<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XQL Query to view the &amp;quot;Incident Name&amp;quot; in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/534815#M3856</link>
    <description>&lt;P&gt;I think this Top 10 Incidents provides list of last 24 hrs incidents only , can you help me how to get data for last 30 days.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Mar 2023 07:48:27 GMT</pubDate>
    <dc:creator>ShahrukhReza</dc:creator>
    <dc:date>2023-03-17T07:48:27Z</dc:date>
    <item>
      <title>XQL Query to view the "Incident Name"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518080#M3029</link>
      <description>&lt;P&gt;Hi People,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was wondering if anyone could assist me with XQL Query to display the Incident name. Please refer to the attached photo to get an idea of what I am trying to achieve. I have used the xdr_data dataset, however i cannot find the relevant field. Appreciate anyone's support.&amp;nbsp;&lt;/P&gt;&lt;BR /&gt;&lt;BR /&gt;Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.</description>
      <pubDate>Mon, 17 Oct 2022 08:15:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518080#M3029</guid>
      <dc:creator>JBahardeen</dc:creator>
      <dc:date>2022-10-17T08:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query to view the "Incident Name"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518084#M3030</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/247903"&gt;@JBahardeen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR XQL shows raw data only. Incidents and alerts are events created by processing and stitching raw logs which we see in XQL and hence they are not exposed as of now with the capability to run queries on incidents and alerts.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a result, this is not possible,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 10:41:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518084#M3030</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-10-17T10:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query to view the "Incident Name"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518268#M3035</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;BR /&gt;Thank you for the prompt response and clarification. So just to confirm, it is impossible to achieve what is shown in the image and only through a feature request we could display the Incident "Description" ? and also The widget is created by PAN Internally ?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-10-17 181229.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/44719i669F6D892770AD46/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-10-17 181229.png" alt="Screenshot 2022-10-17 181229.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 22:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518268#M3035</guid>
      <dc:creator>JBahardeen</dc:creator>
      <dc:date>2022-10-18T22:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query to view the "Incident Name"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518302#M3036</link>
      <description>&lt;P&gt;That's right. The incidents/alerts dataset is not exposed over XQL.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 05:43:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518302#M3036</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-10-19T05:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query to view the "Incident Name"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518303#M3037</link>
      <description>&lt;P&gt;Thanks for the clarification everyone !&lt;/P&gt;
&lt;P&gt;I will&amp;nbsp;&lt;SPAN&gt;reach out to your Customer Success Teams or TAC team to raise a feature request.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 05:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/518303#M3037</guid>
      <dc:creator>JBahardeen</dc:creator>
      <dc:date>2022-10-19T05:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query to view the "Incident Name"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/534815#M3856</link>
      <description>&lt;P&gt;I think this Top 10 Incidents provides list of last 24 hrs incidents only , can you help me how to get data for last 30 days.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 07:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/534815#M3856</guid>
      <dc:creator>ShahrukhReza</dc:creator>
      <dc:date>2023-03-17T07:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query to view the "Incident Name"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/555651#M5052</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have the same question.&amp;nbsp; I understand that it is not possible to create custom dashboard and reports based on incidents and alerts. For large company with multiple entities it is a must for me.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 09:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-view-the-quot-incident-name-quot/m-p/555651#M5052</guid>
      <dc:creator>Binetou_Lo</dc:creator>
      <dc:date>2023-08-29T09:13:02Z</dc:date>
    </item>
  </channel>
</rss>

