<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detail Description of Alert Log Fields XDR API in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545487#M4524</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&amp;nbsp;for the quick response. Really appreciate it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Followup to your response, currently we query based on creation time to pull logs and to keep a pointer of the log fetched.. If&amp;nbsp;&lt;STRONG data-stringify-type="bold"&gt;local_insert_ts &lt;/STRONG&gt;is the time when XDR agent ingests an alert, can we use this field in the API query to pull the logs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you again for your response.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jun 2023 16:50:11 GMT</pubDate>
    <dc:creator>sushant1601</dc:creator>
    <dc:date>2023-06-09T16:50:11Z</dc:date>
    <item>
      <title>Detail Description of Alert Log Fields XDR API</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545472#M4522</link>
      <description>&lt;P&gt;Hello Everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are pulling alerts from the XDR API using below endpoint:&lt;/P&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;/public_api/v1/alerts/get_alerts&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;We query based on creation time which is shown as detection_timestamp in the log.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;I am looking for clarity on below points:&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;1. what is&amp;nbsp;local_insert_ts field? What is the significance of this field? How it is different from creation time?&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;2. Without&amp;nbsp;local_insert_ts, is the log available in API to fetch?&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;3. Is it possible that the&amp;nbsp;local_insert_ts value may get changed for the same event? If it get changed, in what condition it happens?&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;Thank you.&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="sl-flex-1 sl-font-semibold"&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 09 Jun 2023 13:31:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545472#M4522</guid>
      <dc:creator>sushant1601</dc:creator>
      <dc:date>2023-06-09T13:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Detail Description of Alert Log Fields XDR API</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545486#M4523</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/293860"&gt;@sushant1601&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Please find below answers to your queries.&lt;/P&gt;
&lt;OL class="p-rich_text_list p-rich_text_list__ordered" data-stringify-type="ordered-list" data-indent="0" data-border="0"&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;&lt;STRONG data-stringify-type="bold"&gt;local_insert_ts&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;field contains the date and time when XDR agent ingests an alert into cortex XDR tenant. In other words, it is the date and time when Cortex XDR’s Investigation and response became aware about an alert.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;STRONG style="font-family: inherit;" data-stringify-type="bold"&gt;Creation_time&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;field represents the date and time when an alert was created on the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;endpoint.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;&lt;SPAN&gt;For the log to be available to fetch , it will be created with insertion time, that is when the log is ingested.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;No, each log has its local_insert_ts, once the value is created it wont be changed , when&amp;nbsp; a new log is ingested into XDR then a new local_insert_ts will be present in the log for that specific event&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 09 Jun 2023 16:25:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545486#M4523</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-06-09T16:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Detail Description of Alert Log Fields XDR API</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545487#M4524</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&amp;nbsp;for the quick response. Really appreciate it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Followup to your response, currently we query based on creation time to pull logs and to keep a pointer of the log fetched.. If&amp;nbsp;&lt;STRONG data-stringify-type="bold"&gt;local_insert_ts &lt;/STRONG&gt;is the time when XDR agent ingests an alert, can we use this field in the API query to pull the logs?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you again for your response.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 16:50:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545487#M4524</guid>
      <dc:creator>sushant1601</dc:creator>
      <dc:date>2023-06-09T16:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Detail Description of Alert Log Fields XDR API</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545557#M4528</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/293860"&gt;@sushant1601&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use of a field depends on the use case or type of data that you want to obtain. Please take help from&amp;nbsp;&lt;A href="https://cortex-panw.stoplight.io/docs/cortex-xdr/0c82b9a6e79d9-get-all-alerts" target="_self"&gt;API reference guide&lt;/A&gt;&amp;nbsp;according to your use case.&lt;/P&gt;
&lt;P&gt;I hope this answers your question.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jun 2023 12:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-xdr-api/m-p/545557#M4528</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-06-10T12:12:24Z</dc:date>
    </item>
  </channel>
</rss>

