<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I'm looking to create a report template with some detailed information in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538479#M4096</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231174"&gt;@timurphy&lt;/a&gt; thanks for that... is there a way to have the XQL widget (when added to a report template) show as a graph and not just a list? &lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2023 15:06:57 GMT</pubDate>
    <dc:creator>${userLoginName}</dc:creator>
    <dc:date>2023-04-12T15:06:57Z</dc:date>
    <item>
      <title>I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538311#M4079</link>
      <description>&lt;P&gt;What I've found in the information available in the Reports of XDR seems to be fairly high level data.&lt;/P&gt;
&lt;P&gt;I'm looking to get some more detailed information.&lt;/P&gt;
&lt;P&gt;Kind of like what I can get by filtering my Endpoints and manually saving to file.&lt;/P&gt;
&lt;P&gt;Is this possible?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 21:21:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538311#M4079</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2023-04-11T21:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538317#M4080</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out to LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm looking into this and I'll get back with you shortly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a great day!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 21:32:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538317#M4080</guid>
      <dc:creator>anlynch</dc:creator>
      <dc:date>2023-04-11T21:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538342#M4084</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275427"&gt;@${userLoginName}&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes. You can do this by utilizing XQL widgets.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;XQL widgets results can be attached to a report template and will be sent to your email or generated via console as CSV once successfully generated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Utilize the XQL queries to get the data that you are looking for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are helpful articles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/Get-Started-with-XQL" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/Get-Started-with-XQL&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Your-Widget-Library" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Manage-Your-Widget-Library&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 01:25:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538342#M4084</guid>
      <dc:creator>MarvinC</dc:creator>
      <dc:date>2023-04-12T01:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538461#M4093</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/191267"&gt;@MarvinC&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Can you give me an example XQL query that would find endpoints and their agent version?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 14:02:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538461#M4093</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2023-04-12T14:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538477#M4095</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275427"&gt;@${userLoginName}&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should help you get started:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = endpoints 
| fields endpoint_name, agent_version, operating_system 
| sort desc agent_version &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Tim&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 15:00:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538477#M4095</guid>
      <dc:creator>timurphy</dc:creator>
      <dc:date>2023-04-12T15:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538479#M4096</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231174"&gt;@timurphy&lt;/a&gt; thanks for that... is there a way to have the XQL widget (when added to a report template) show as a graph and not just a list? &lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 15:06:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538479#M4096</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2023-04-12T15:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538483#M4097</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275427"&gt;@${userLoginName}&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sure, you can definitely display it as a graph. After you run the query, if you select the "Graph" tab you can use the Chart Editor and adjust everything as you see fit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="timurphy_0-1681312807913.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49415i6564C518E626D3C8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="timurphy_0-1681312807913.png" alt="timurphy_0-1681312807913.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once you are satisfied with the preview, you can save it directly to your Widget Library, or click "Add to query" and a &lt;CODE&gt;view&lt;/CODE&gt; stage will be added to your query.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your use case sounds very similar to the out of the box widget titled "Agent Version Breakdown" - so you may want to give that a look first, if you are looking for a count of agents broken out by version. The graph could get pretty messy if you are trying to display version information alongside every hostname versus a count, for example.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 15:28:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538483#M4097</guid>
      <dc:creator>timurphy</dc:creator>
      <dc:date>2023-04-12T15:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538486#M4099</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231174"&gt;@timurphy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found that just before you replied.&lt;/P&gt;
&lt;P&gt;I was able to create a query but&amp;nbsp; not a graph, it keeps saying "could not visualize"&lt;/P&gt;
&lt;P&gt;Something is wrong with my final line... it works without it.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = endpoints 
| fields endpoint_name, agent_version, domain 
| comp count_distinct(endpoint_name) as count by domain, agent_version
| view graph type = column subtype = grouped layout = horizontal xaxis = count yaxis = domain &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm assuming that I will need some extra grouping to group the version and the domain together to be the y-axis value?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 15:36:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538486#M4099</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2023-04-12T15:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538498#M4101</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275427"&gt;@${userLoginName}&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The count should be on the y-axis, with agent version being on the x-axis. If I'm understanding correctly, it seems you want a count of agent versions broken out by domain. Give this a try and see if it helps:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = endpoints 
| filter endpoint_status in(ENUM.CONNECTED, ENUM.DISCONNECTED)
| alter version_and_domain = if(domain != "", concat(agent_version, " (", domain, ")" ), concat(agent_version, " (", "Domain not available", ")")) 
| fields endpoint_name, agent_version, domain, version_and_domain, endpoint_id  
| comp count(endpoint_id) as num_agents by version_and_domain 
| sort asc version_and_domain 
| view graph type = column subtype = grouped header = "Agent Versions by Domain" xaxis = version_and_domain yaxis = num_agents &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using the &lt;CODE&gt;alter&lt;/CODE&gt; stage, you can create a new field. Here I created &lt;CODE&gt;version_and_domain&lt;/CODE&gt; which is a combination of the two fields with some simple logic in case the domain field is empty. What you will end up with is &lt;EM&gt;&amp;lt;agent_version&amp;gt; (&amp;lt;domain&amp;gt;)&lt;/EM&gt;, e.g., &lt;EM&gt;8.0.0.30814 (example.com)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 17:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538498#M4101</guid>
      <dc:creator>timurphy</dc:creator>
      <dc:date>2023-04-12T17:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538500#M4102</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231174"&gt;@timurphy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Perfect! (almost)&lt;/P&gt;
&lt;P&gt;Alter is what I was missing...&lt;/P&gt;
&lt;P&gt;I've swapped the graph to horizontal (which is why I thought I had to switch the x and y axis) and now it only shows every third agent_and_domain...&amp;nbsp; can I make it show them all?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = endpoints 
| filter endpoint_status in(ENUM.CONNECTED, ENUM.DISCONNECTED)
| alter version_and_domain = if(domain != "", concat(agent_version, " (", domain, ")" ), concat(agent_version, " (", "Domain not available", ")")) 
| fields endpoint_name, agent_version, domain, version_and_domain, endpoint_id  
| comp count(endpoint_id) as num_agents by version_and_domain 
| sort asc version_and_domain
| view graph type = column subtype = grouped layout = horizontal header = "Agent Versions by Domain" xaxis = version_and_domain yaxis = num_agents &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 20:18:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538500#M4102</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2023-04-12T20:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538516#M4104</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275427"&gt;@${userLoginName}&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're referring to the labels for each item, this looks to me like a rendering issue. If there was more vertical screen real estate they should all be shown - the query itself isn't governing how many labels are being displayed. This is why many built-in widgets limit how many results are shown, otherwise the view can be crowded. You might want to consider adjusting the graph type to something else that will fit better with your screen's resolution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is what your query looks like to me without any changes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="timurphy_0-1681330456751.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/49420i30E8E701CE37F430/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="timurphy_0-1681330456751.png" alt="timurphy_0-1681330456751.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 20:15:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538516#M4104</guid>
      <dc:creator>timurphy</dc:creator>
      <dc:date>2023-04-12T20:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: I'm looking to create a report template with some detailed information</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538520#M4106</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/231174"&gt;@timurphy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for your help with this&lt;BR /&gt;i've decided to stick with the vertical layout and added in some more filters to restrict versions (and created separate widgets for those versions)&lt;/P&gt;
&lt;P&gt;this way I can stay under the 15 result limit for the charts&lt;/P&gt;
&lt;P&gt;have a great day&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 20:19:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/i-m-looking-to-create-a-report-template-with-some-detailed/m-p/538520#M4106</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2023-04-12T20:19:22Z</dc:date>
    </item>
  </channel>
</rss>

