<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XQL Help - Any AI tools, query library? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/606331#M7343</link>
    <description>&lt;P&gt;Wondering if there are plans to help build queries? Something as simple as looking for a file called "testfile" requires the query with the below code:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;BR /&gt;|preset = xdr_file&lt;BR /&gt;|filter action_file_name contains "testfile"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Another example that we are currently working on is a way to search for specific models of computers. As an example: "find all &lt;SPAN&gt;Latitude 7440" and show hostname, user, ip, last seen. We are assuming the information is hidden in a json file somewhere.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It makes it difficult to figure out what's needed when the easy way (builder) doesn't have certain forms and aspects to drill into. That leads to trial and error to find a solution. We tried converting Splunk queries using the convert to XQL slider which has yet to work for us.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;BR /&gt;Is there a user Library other than&amp;nbsp;&lt;A href="https://github.com/PaloAltoNetworks/cortex-xql-queries" target="_self"&gt;the official one&lt;/A&gt; which only has 1 in it?&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Are there plans to add an AI helper to Cortex to help build queries?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SentinelONE has Purple, Crowdstrike has&amp;nbsp;&lt;SPAN&gt;Charlotte, Sophos has it built into their platform as a few examples.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 17:56:46 GMT</pubDate>
    <dc:creator>J.Suter</dc:creator>
    <dc:date>2024-10-17T17:56:46Z</dc:date>
    <item>
      <title>XQL Help - Any AI tools, query library?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/606331#M7343</link>
      <description>&lt;P&gt;Wondering if there are plans to help build queries? Something as simple as looking for a file called "testfile" requires the query with the below code:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;BR /&gt;|preset = xdr_file&lt;BR /&gt;|filter action_file_name contains "testfile"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Another example that we are currently working on is a way to search for specific models of computers. As an example: "find all &lt;SPAN&gt;Latitude 7440" and show hostname, user, ip, last seen. We are assuming the information is hidden in a json file somewhere.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It makes it difficult to figure out what's needed when the easy way (builder) doesn't have certain forms and aspects to drill into. That leads to trial and error to find a solution. We tried converting Splunk queries using the convert to XQL slider which has yet to work for us.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;BR /&gt;Is there a user Library other than&amp;nbsp;&lt;A href="https://github.com/PaloAltoNetworks/cortex-xql-queries" target="_self"&gt;the official one&lt;/A&gt; which only has 1 in it?&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;Are there plans to add an AI helper to Cortex to help build queries?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SentinelONE has Purple, Crowdstrike has&amp;nbsp;&lt;SPAN&gt;Charlotte, Sophos has it built into their platform as a few examples.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 17:56:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/606331#M7343</guid>
      <dc:creator>J.Suter</dc:creator>
      <dc:date>2024-10-17T17:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Help - Any AI tools, query library?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/610125#M7359</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/816046735"&gt;@J.Suter&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The XDR console has a built-in Query Library in the XQL Query designer with, for now, 90+ examples.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1729524023784.png" style="width: 642px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63144i45FBDABA9BAD9897/image-dimensions/642x239?v=v2" width="642" height="239" role="button" title="jmazzeo_0-1729524023784.png" alt="jmazzeo_0-1729524023784.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This list gets updated on each XDR Console new release, if there are important new queries to add.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have here in the LC this advanced XQL crash course than can help you to build some very specific use cases as the ones you mention:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-xql-use-cases-and-applications-crash-course/ta-p/544228" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-xql-use-cases-and-applications-crash-course/ta-p/544228&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the AI, we have &lt;A href="https://www.paloaltonetworks.com/resources/datasheets/cortex-copilot-ds" target="_self"&gt;Cortex Copilot&lt;/A&gt; for &lt;STRONG&gt;XSIAM&lt;/STRONG&gt; since the &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Release-Notes/September-2024" target="_self"&gt;last release&lt;/A&gt;, so is a matter of time that this will also be available for XDR.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 15:26:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/610125#M7359</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-10-21T15:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Help - Any AI tools, query library?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/612031#M7369</link>
      <description>&lt;P&gt;Crash course is nice, thank you, and the query library is helpful and has given us some templates to work with. That copilot will be needed in the CortexXDR Pro space, hopefully that comes sooner than later, appreciate the response!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 12:33:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/612031#M7369</guid>
      <dc:creator>J.Suter</dc:creator>
      <dc:date>2024-10-22T12:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Help - Any AI tools, query library?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/643806#M7454</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A id="link_33" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428" target="_self" aria-label="View Profile of jmazzeo"&gt;&lt;SPAN class=""&gt;jmazzeo&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Crash course is very nice. I watched whole videos. Thank you!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Elmir Jafarov. Cybersecurity Engineer.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 11:45:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/643806#M7454</guid>
      <dc:creator>E.Jafarov</dc:creator>
      <dc:date>2024-11-21T11:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Help - Any AI tools, query library?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/1237041#M8712</link>
      <description>&lt;P&gt;For the sake of completeness - none of the above mentioned things is really an answer on the original question.&lt;/P&gt;
&lt;P&gt;Employing an AI to ask "write me an XQL query to search for hosts with a file XYZ.exe, and output a table showing hostname, username, filepath, creation time" is something way more powerful and "accessible" than watching hours of training video or adapting, best-guessing and trial-and-erroring with a prebuilt query library,&amp;nbsp;&lt;BR /&gt;The Cortex Copilot in XSIAM is nowhere near what you get when you ask e.g. Microsoft Copilot or ChatGPT to write you e.g. a Splunk SPL query for the above, and these tools aren't even related to the "SIEM" manufacturer.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Sep 2025 11:59:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-any-ai-tools-query-library/m-p/1237041#M8712</guid>
      <dc:creator>MarekKreul</dc:creator>
      <dc:date>2025-09-01T11:59:10Z</dc:date>
    </item>
  </channel>
</rss>

