<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query to Monitor Computer Uptime in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-to-monitor-computer-uptime/m-p/573967#M5925</link>
    <description>&lt;P&gt;Have you confirmed that the system uptime field is populated for any endpoints?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;None of our 4000+ endpoints show values in that field and I posted this question in December.&lt;/P&gt;
&lt;P&gt;The response was it is only for iOS devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/system-uptime-field-for-cortex-pro-agents-is-empty/m-p/568917" target="_blank"&gt;LIVEcommunity - System uptime field for Cortex Pro agents is empty. - LIVEcommunity - 568917 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jan 2024 19:02:30 GMT</pubDate>
    <dc:creator>PC-TomS</dc:creator>
    <dc:date>2024-01-22T19:02:30Z</dc:date>
    <item>
      <title>Query to Monitor Computer Uptime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-to-monitor-computer-uptime/m-p/573918#M5922</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I intend to formulate a new query to retrieve the computer's uptime, and if the system has been active for more than 30 days, generate an alert. Although I attempted the following XQL Search, the outcome yielded no results:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;config case_sensitive = false &lt;BR /&gt;| preset = xdr_event_log &lt;BR /&gt;| filter event_type = EVENT_LOG and action_evtlog_event_id in (6013)&amp;nbsp;&lt;BR /&gt;| fields action_evtlog_message as message, action_evtlog_event_id as event_id&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can u help me, please&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 13:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-to-monitor-computer-uptime/m-p/573918#M5922</guid>
      <dc:creator>Melvin_Machado</dc:creator>
      <dc:date>2024-01-22T13:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Query to Monitor Computer Uptime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-to-monitor-computer-uptime/m-p/573967#M5925</link>
      <description>&lt;P&gt;Have you confirmed that the system uptime field is populated for any endpoints?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;None of our 4000+ endpoints show values in that field and I posted this question in December.&lt;/P&gt;
&lt;P&gt;The response was it is only for iOS devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/system-uptime-field-for-cortex-pro-agents-is-empty/m-p/568917" target="_blank"&gt;LIVEcommunity - System uptime field for Cortex Pro agents is empty. - LIVEcommunity - 568917 (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 19:02:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-to-monitor-computer-uptime/m-p/573967#M5925</guid>
      <dc:creator>PC-TomS</dc:creator>
      <dc:date>2024-01-22T19:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Query to Monitor Computer Uptime</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-to-monitor-computer-uptime/m-p/574482#M5958</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have different inquiries and issues ;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;While you utilize an add-on named "Host Insights" to retrieve your machine's uptime, someone mentions that it's not feasible because it's solely accessible for iOS&lt;/LI&gt;
&lt;LI&gt;On my end, what I aim for is to extract the description of event 6013 from the event log using an XQL Search. If the value within the description exceeds 2,592e+6, I want to trigger an alert&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 25 Jan 2024 15:29:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/query-to-monitor-computer-uptime/m-p/574482#M5958</guid>
      <dc:creator>Melvin_Machado</dc:creator>
      <dc:date>2024-01-25T15:29:59Z</dc:date>
    </item>
  </channel>
</rss>

