<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: xql query for file \ folder name. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574721#M5967</link>
    <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/593283889"&gt;@Prashanta&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well, and thank you for reaching out to our live community. From the above query I understand that you would like to search for a file or a folder across the environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please try the query below and see if you are able to get the desired results, thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;preset = xdr_file&lt;BR /&gt;| filter agent_hostname = "Host_name" // To filter a particular host&lt;BR /&gt;| filter action_file_name contains "file.txt" // To find file by file name&lt;BR /&gt;| filter (action_file_path contains """test_folder""") //To find the folder by folder name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 29 Jan 2024 10:56:52 GMT</pubDate>
    <dc:creator>abdrahman</dc:creator>
    <dc:date>2024-01-29T10:56:52Z</dc:date>
    <item>
      <title>xql query for file \ folder name.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574629#M5962</link>
      <description>&lt;P&gt;&lt;SPAN&gt;How can I locate a particular file or folder across all endpoints?&amp;nbsp;&lt;BR /&gt;file or folder name :&amp;nbsp;&lt;SPAN class="ui-provider ee bjo bft bnh bni bnj bnk bnl bnm bnn bno bnp bnq bnr bns bnt bnu bnv bnw bnx bny bnz boa bob boc bod boe bof bog boh boi boj bok bol bom"&gt;bihmplhobchoageeokmgbdihknkjbknd&lt;BR /&gt;&lt;BR /&gt;Thanks community&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="ui-provider ee bjo bft bnh bni bnj bnk bnl bnm bnn bno bnp bnq bnr bns bnt bnu bnv bnw bnx bny bnz boa bob boc bod boe bof bog boh boi boj bok bol bom"&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 06:02:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574629#M5962</guid>
      <dc:creator>Prashanta</dc:creator>
      <dc:date>2024-01-28T06:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: xql query for file \ folder name.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574721#M5967</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/593283889"&gt;@Prashanta&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you are doing well, and thank you for reaching out to our live community. From the above query I understand that you would like to search for a file or a folder across the environment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please try the query below and see if you are able to get the desired results, thank you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;preset = xdr_file&lt;BR /&gt;| filter agent_hostname = "Host_name" // To filter a particular host&lt;BR /&gt;| filter action_file_name contains "file.txt" // To find file by file name&lt;BR /&gt;| filter (action_file_path contains """test_folder""") //To find the folder by folder name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 10:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574721#M5967</guid>
      <dc:creator>abdrahman</dc:creator>
      <dc:date>2024-01-29T10:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: xql query for file \ folder name.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574728#M5969</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I believe you want to locate the file or path across all endpoints. I am adding my suggestions for the same,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;File name:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;preset = xdr_file&lt;BR /&gt;|filter action_file_name contains "usage"&lt;BR /&gt;|fields action_file_name ,_time , agent_hostname ,agent_ip_addresses ,agent_mac_addresses ,agent_os_type , action_file_path&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Folder path:&lt;/P&gt;
&lt;P&gt;preset = xdr_file&lt;BR /&gt;|filter&amp;nbsp;&lt;SPAN&gt;action_file_path contains """test_folder"""&lt;/SPAN&gt;&lt;BR /&gt;|fields &amp;nbsp;&lt;SPAN&gt;action_file_path&lt;/SPAN&gt; ,_time , agent_hostname ,agent_ip_addresses ,agent_mac_addresses ,agent_os_type , action_file_path&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;By running just "preset = xdr_file" in Query builder, you will see multiple fields. You can modify the filed or join with another tables to get more information and modify the query as per the requirement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 12:22:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574728#M5969</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-01-29T12:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: xql query for file \ folder name.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574899#M5977</link>
      <description>&lt;P&gt;Its works. Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 09:56:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-file-folder-name/m-p/574899#M5977</guid>
      <dc:creator>Prashanta</dc:creator>
      <dc:date>2024-01-30T09:56:54Z</dc:date>
    </item>
  </channel>
</rss>

