<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Join Alerts and Incidents table to get all alerts attached to an incident in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/join-alerts-and-incidents-table-to-get-all-alerts-attached-to-an/m-p/569467#M5709</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275370"&gt;@ogtay.nabili&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Alerts and Incidents are already joined under Incidents tab. You can filter out True Positive incidents by using "status" field in incident filter. To see relative alerts for a particular incident go to "Alerts &amp;amp; Insights" within an incident. Now to see alerts with Detection/Prevention status you can filter with "Action" field in alerts filter.&lt;/P&gt;
&lt;P&gt;Alternate to above, you can write XQL query using datasets "alerts" and "incidents". In order to combine the output of both datasets, you can use "join" stage with fields like "incident_id" to get combined result. Below is the reference guide for "join" stage.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/Join" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/Join&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Dec 2023 14:13:50 GMT</pubDate>
    <dc:creator>nsinghvirk</dc:creator>
    <dc:date>2023-12-12T14:13:50Z</dc:date>
    <item>
      <title>Join Alerts and Incidents table to get all alerts attached to an incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/join-alerts-and-incidents-table-to-get-all-alerts-attached-to-an/m-p/568883#M5679</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to join alerts and incidents table to list all True Positive incidents along with their alerts (I need Prevention/Detection status of alerts of each incident). Is there a way to achieve this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 14:04:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/join-alerts-and-incidents-table-to-get-all-alerts-attached-to-an/m-p/568883#M5679</guid>
      <dc:creator>ogtay.nabili</dc:creator>
      <dc:date>2023-12-07T14:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: Join Alerts and Incidents table to get all alerts attached to an incident</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/join-alerts-and-incidents-table-to-get-all-alerts-attached-to-an/m-p/569467#M5709</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/275370"&gt;@ogtay.nabili&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;Alerts and Incidents are already joined under Incidents tab. You can filter out True Positive incidents by using "status" field in incident filter. To see relative alerts for a particular incident go to "Alerts &amp;amp; Insights" within an incident. Now to see alerts with Detection/Prevention status you can filter with "Action" field in alerts filter.&lt;/P&gt;
&lt;P&gt;Alternate to above, you can write XQL query using datasets "alerts" and "incidents". In order to combine the output of both datasets, you can use "join" stage with fields like "incident_id" to get combined result. Below is the reference guide for "join" stage.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/Join" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-XQL-Language-Reference/Join&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 14:13:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/join-alerts-and-incidents-table-to-get-all-alerts-attached-to-an/m-p/569467#M5709</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2023-12-12T14:13:50Z</dc:date>
    </item>
  </channel>
</rss>

