<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XQL Query - File Delete Action in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588201#M6753</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197591"&gt;@chinsiongwong&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Its not a deletion&amp;nbsp; when you delete a file, it just moves it to the Recycle Bin. Shift delete shows up in XQL results and its a proper deletion.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also,&amp;nbsp;hard delete shows up in XQL when deleting file in Cyvera folder.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 May 2024 04:23:07 GMT</pubDate>
    <dc:creator>aspatil</dc:creator>
    <dc:date>2024-05-29T04:23:07Z</dc:date>
    <item>
      <title>XQL Query - File Delete Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588036#M6750</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please may i know if anyone may have the issue i encounter since early May 2024?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Delete a folder (100+ files) from specific endpoint (right click mouse and select delete)&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;From Cortex XDR Query Builder - File Query and Select Action = Delete - filter the particular endpoint hostname/ip&lt;/P&gt;
&lt;P&gt;The query no longer returns the file delete/file remove action.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or am i alone here... :(.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you very much for your advise..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 01:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588036#M6750</guid>
      <dc:creator>chinsiongwong</dc:creator>
      <dc:date>2024-05-28T01:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query - File Delete Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588201#M6753</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197591"&gt;@chinsiongwong&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Its not a deletion&amp;nbsp; when you delete a file, it just moves it to the Recycle Bin. Shift delete shows up in XQL results and its a proper deletion.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also,&amp;nbsp;hard delete shows up in XQL when deleting file in Cyvera folder.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 04:23:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588201#M6753</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-05-29T04:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query - File Delete Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588205#M6755</link>
      <description>&lt;P&gt;Dear Asptail,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is not the case before the May upgrade.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before the May upgrade, the query returns all the File_Remove action, being either i use the "del" button, or right click mouse and select delete.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on your description, when we delete the file from local drive, yes, it will rename (logical name) and move to recycle.bin.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried to delete files from network shared drive? Deletion from network drive (either del button, right click mouse and select delete or hard delete), they won't go to the recycle bin. The rename and move to recycle.bin action will not be present. Only file located on your local PC will go to your recycle bin.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can i still use Cortex XDR for files actions investigation? This is not the case before the May 2024.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 04:42:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588205#M6755</guid>
      <dc:creator>chinsiongwong</dc:creator>
      <dc:date>2024-05-29T04:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query - File Delete Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588334#M6762</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197591"&gt;@chinsiongwong&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is not the scenario. We have never monitored soft delete and XDR doesn't monitor all the file deletion activities.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you think this was working previously, then please go head and open a TAC support case for further troubleshooting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 05:38:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588334#M6762</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-05-30T05:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Query - File Delete Action</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588338#M6764</link>
      <description>&lt;P&gt;Dear Aspatil,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Sound like the Cortex XDR document need to be update?&lt;/P&gt;
&lt;P&gt;Under Endpoint Data Collection --&amp;gt; EDR Data Collected for Windows Endpoints.&lt;/P&gt;
&lt;P&gt;Files Events of Create,Write,Delete,Rename,Move, etc collected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyway, thank you very much...the TAC case opened with the support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks again.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 06:01:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-file-delete-action/m-p/588338#M6764</guid>
      <dc:creator>chinsiongwong</dc:creator>
      <dc:date>2024-05-30T06:01:25Z</dc:date>
    </item>
  </channel>
</rss>

