<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between host_inventory and endpoint in XQL Query in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/556100#M5072</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your answer!&lt;/P&gt;
&lt;P&gt;You're right, this is a licenses problem; I didn't check that.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Sep 2023 08:11:48 GMT</pubDate>
    <dc:creator>RemiLiquete</dc:creator>
    <dc:date>2023-09-01T08:11:48Z</dc:date>
    <item>
      <title>Difference between host_inventory and endpoint in XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/556023#M5070</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to search for all installed vpn on endpoints using an XQL Query.&lt;/P&gt;
&lt;P&gt;Before going further in my query, I'm trying to list all hosts where the application name contains "*vpn*".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This result and the result from host insight doing the same search are different. Somes endpoints are not showing in the query. So I've tried to search for those missing endpoints in query. I only find them when using the dataset "endpoints". I can't find them using host_inventory.&lt;BR /&gt;Why?&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 15:10:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/556023#M5070</guid>
      <dc:creator>RemiLiquete</dc:creator>
      <dc:date>2023-08-31T15:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between host_inventory and endpoint in XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/556034#M5071</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/311763"&gt;@RemiLiquete&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Possible reason for not getting same number of hosts in endpoint and host_inventory dataset can be that the host insight capability was not enabled for all the hosts in agent setting profile. Other possible reason can be that you have limited number of Host Insight licenses which are required for host_inventory to work. Hence you may be missing out data from some of the hosts in host_inventory dataset.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 17:32:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/556034#M5071</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-08-31T17:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between host_inventory and endpoint in XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/556100#M5072</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256101"&gt;@nsinghvirk&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your answer!&lt;/P&gt;
&lt;P&gt;You're right, this is a licenses problem; I didn't check that.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 08:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/556100#M5072</guid>
      <dc:creator>RemiLiquete</dc:creator>
      <dc:date>2023-09-01T08:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between host_inventory and endpoint in XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/557573#M5133</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/311763"&gt;@RemiLiquete&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please set me know if you also have the problem to get them inside host inventory when your licence issue is solved.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my opinion you have to reinstall the agent, because I have severall clients which are not visible in the host inventory after license upgrade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;Rob&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 16:16:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/557573#M5133</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-09-12T16:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between host_inventory and endpoint in XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/557741#M5143</link>
      <description>&lt;P&gt;Hello, thank you for the information.&lt;BR /&gt;For now, I did not resolve this issue since it's not impacting for now. I let you know if it changes.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 15:20:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/557741#M5143</guid>
      <dc:creator>RemiLiquete</dc:creator>
      <dc:date>2023-09-13T15:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between host_inventory and endpoint in XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/557802#M5147</link>
      <description>&lt;P&gt;You're welcome!&lt;/P&gt;
&lt;P&gt;Maybe you have more visibility with this XQL:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;config case_sensitive = false&lt;BR /&gt;| dataset = endpoints &lt;BR /&gt;|join conflict_strategy = both type = left (dataset = host_inventory ) as HI HI.host_name = endpoint_name and HI.agent_domain = domain &lt;BR /&gt;|fields domain , endpoint_name, last_seen, host_name, endpoint_status &lt;BR /&gt;|filter host_name = null&lt;BR /&gt;|sort desc last_seen&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 20:42:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/difference-between-host-inventory-and-endpoint-in-xql-query/m-p/557802#M5147</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-09-13T20:42:27Z</dc:date>
    </item>
  </channel>
</rss>

