<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Showing Malware incident in the Dashboard in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/547864#M4679</link>
    <description>&lt;P&gt;Hello, just&amp;nbsp; want to showed the Malware incidents and the related-malware filename in the dashboard, what should i choose for the XQL.&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Fri, 30 Jun 2023 10:26:26 GMT</pubDate>
    <dc:creator>SeanDeHarris</dc:creator>
    <dc:date>2023-06-30T10:26:26Z</dc:date>
    <item>
      <title>Showing Malware incident in the Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/547864#M4679</link>
      <description>&lt;P&gt;Hello, just&amp;nbsp; want to showed the Malware incidents and the related-malware filename in the dashboard, what should i choose for the XQL.&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2023 10:26:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/547864#M4679</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2023-06-30T10:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Showing Malware incident in the Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/547868#M4680</link>
      <description>&lt;P&gt;To display malware incidents and their related malware filenames in a dashboard using XQL (Extended Query Language), you can use the following query:&lt;FONT size="1 2 3 4 5 6 7"&gt;&amp;nbsp; &lt;FONT color="#FFFFFF"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;A href="https://www.yourtexasbenefits.bid/" target="_self"&gt;&lt;FONT color="#FFFFFF"&gt;YourTexasBenefits&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Find incidents with data.type = 'malware'&lt;/P&gt;
&lt;P&gt;This query will retrieve all incidents that have a data type of "malware." You can then customize the dashboard to display the relevant information, such as the incident details and the associated malware filenames.&lt;/P&gt;
&lt;P&gt;Please note that the exact implementation of XQL may vary depending on the specific security platform or tool you are using. Refer to the documentation or support resources provided by your security platform for more specific guidance on constructing queries and customizing dashboards.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jul 2023 04:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/547868#M4680</guid>
      <dc:creator>Fernando002</dc:creator>
      <dc:date>2023-07-03T04:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Showing Malware incident in the Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/548729#M4722</link>
      <description>&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;I'm not sure where to locate data.type = "malware', is it under dataset = xdr_data or other dataset?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 07:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/548729#M4722</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2023-07-10T07:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Showing Malware incident in the Dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/548754#M4726</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184443"&gt;@SeanDeHarris&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300639"&gt;@Fernando002&lt;/a&gt;&amp;nbsp;exactly means with XQL filters. However, we do not have incidents data exposed to XQL(XML query language) in Cortex XDR as of now. As a result, custom dashboard creation is not possible for the same. You can choose to create your own filters in alerts table under the Category: Malware and Module:&amp;lt;Enter Module of your choice(eg. Wildfire, Local Analysis, Behavioral Threat Protection etc.)&amp;gt; and then you can save the filter for the same.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Alternatively, if you want a consolidated dashboard, there is a widget which shows detections by category which should also list you the count of alerts/incidents generated as malware.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6330918231112w1104h540r895" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6330918231112" data-account="6058004142001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058004142001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6330918231112w1104h540r895');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://live.paloaltonetworks.com/t5/video/gallerypage/video-id/6330918231112"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 09:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/showing-malware-incident-in-the-dashboard/m-p/548754#M4726</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-07-10T09:55:27Z</dc:date>
    </item>
  </channel>
</rss>

