<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible Values for event_types in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/possible-values-for-event-types/m-p/544577#M4476</link>
    <description>&lt;P&gt;Thank you for your response. This does help me in understanding the schema, however the value I am using in event_type in XQL query does not match with the possible values provided in schema.&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;"query"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"dataset=xdr_data | filter event_type = EVENT_LOG"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;Also, I am using postman to query API, autofill values I don't get.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2023 13:32:34 GMT</pubDate>
    <dc:creator>sushant1601</dc:creator>
    <dc:date>2023-06-02T13:32:34Z</dc:date>
    <item>
      <title>Possible Values for event_types</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/possible-values-for-event-types/m-p/543207#M4457</link>
      <description>&lt;P&gt;Hello Community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to understand Palo Alto XDR logs fetched using API(XQL Query).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am using dataset as&amp;nbsp;&lt;SPAN&gt;xdr_data, want to know what all event_types can come under this dataset.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For ex:&amp;nbsp;EVENT_LOG.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What are the possible values we can get in the field&amp;nbsp;event_type when using dataset=xdr_data.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I want to use event_type in the filter of XQL query, that is why I want to know the possible values.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any help would appreciate.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 15:01:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/possible-values-for-event-types/m-p/543207#M4457</guid>
      <dc:creator>sushant1601</dc:creator>
      <dc:date>2023-05-24T15:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Values for event_types</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/possible-values-for-event-types/m-p/544134#M4459</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/293860"&gt;@sushant1601&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may refer to XQL schema reference guide to know the fields of &lt;SPAN&gt;xdr_data dataset&amp;nbsp;&lt;/SPAN&gt;along with their description &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XQL-Schema-Reference-Guide/XDR_DATA-Fields" target="_self"&gt;here&lt;/A&gt;. Additionally when you create XQl query you get values like Autofill to select for that field, so either you may select from that or when write it will show the available value. As shared in below screenshot for reference:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_0-1685525182383.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50497iF19B4203F7A180A5/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_0-1685525182383.png" alt="PiyushKohli_0-1685525182383.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PiyushKohli_1-1685527292923.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50498iB360432997C7ED1A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="PiyushKohli_1-1685527292923.png" alt="PiyushKohli_1-1685527292923.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 10:02:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/possible-values-for-event-types/m-p/544134#M4459</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-05-31T10:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Possible Values for event_types</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/possible-values-for-event-types/m-p/544577#M4476</link>
      <description>&lt;P&gt;Thank you for your response. This does help me in understanding the schema, however the value I am using in event_type in XQL query does not match with the possible values provided in schema.&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;&lt;SPAN&gt;"query"&lt;/SPAN&gt;&lt;SPAN&gt;: &lt;/SPAN&gt;&lt;SPAN&gt;"dataset=xdr_data | filter event_type = EVENT_LOG"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;Also, I am using postman to query API, autofill values I don't get.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:32:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/possible-values-for-event-types/m-p/544577#M4476</guid>
      <dc:creator>sushant1601</dc:creator>
      <dc:date>2023-06-02T13:32:34Z</dc:date>
    </item>
  </channel>
</rss>

