<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XQL Query to look for a certain username on the domain on what devices they logged on to. in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-look-for-a-certain-username-on-the-domain-on-what/m-p/581380#M6395</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280058"&gt;@Joe-Oberfoell&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the XQL Query Library you can find one pre-defined query called "All successful logins by a user" where you can set the username and it will search the xdr_data dataset for login events from that user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1711129475097.png" style="width: 650px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58562i4611DED56F501E96/image-dimensions/650x268/is-moderation-mode/true?v=v2" width="650" height="268" role="button" title="jmazzeo_0-1711129475097.png" alt="jmazzeo_0-1711129475097.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Try it and check how it goes, you can modify the query as you need to fulfill your needs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2024 17:46:19 GMT</pubDate>
    <dc:creator>jmazzeo</dc:creator>
    <dc:date>2024-03-22T17:46:19Z</dc:date>
    <item>
      <title>XQL Query to look for a certain username on the domain on what devices they logged on to.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-look-for-a-certain-username-on-the-domain-on-what/m-p/581356#M6392</link>
      <description>&lt;P&gt;I have other tools that I can scan our entire network looking, but its time consuming to setup and run. This need has come up before., when creds are being used suspiciously and we want to see where all they are logging on.&lt;/P&gt;
&lt;P&gt;I think running a XQL may be a time saver if I can figure it out.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 14:35:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-look-for-a-certain-username-on-the-domain-on-what/m-p/581356#M6392</guid>
      <dc:creator>Joe-Oberfoell</dc:creator>
      <dc:date>2024-03-22T14:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query to look for a certain username on the domain on what devices they logged on to.</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-look-for-a-certain-username-on-the-domain-on-what/m-p/581380#M6395</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280058"&gt;@Joe-Oberfoell&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the XQL Query Library you can find one pre-defined query called "All successful logins by a user" where you can set the username and it will search the xdr_data dataset for login events from that user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1711129475097.png" style="width: 650px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58562i4611DED56F501E96/image-dimensions/650x268/is-moderation-mode/true?v=v2" width="650" height="268" role="button" title="jmazzeo_0-1711129475097.png" alt="jmazzeo_0-1711129475097.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Try it and check how it goes, you can modify the query as you need to fulfill your needs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2024 17:46:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-to-look-for-a-certain-username-on-the-domain-on-what/m-p/581380#M6395</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-03-22T17:46:19Z</dc:date>
    </item>
  </channel>
</rss>

