<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic General Cortex XQL questions in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/general-cortex-xql-questions/m-p/623534#M7439</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been unable to confirm the following information in the online guidance I have been looking through.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How far back can we run an "All Actions" query in XQL? For example, can we search for file hashes going back 3 months or longer?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Also, what is the difference between running an "All Actions" query vs using the XQL Search option? Will All Actions search through and find the same information?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We also see 'max results' reached sometimes when we run queries, what is the number of max results when running queries?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Nov 2024 16:50:21 GMT</pubDate>
    <dc:creator>Joe_Botelho</dc:creator>
    <dc:date>2024-11-18T16:50:21Z</dc:date>
    <item>
      <title>General Cortex XQL questions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/general-cortex-xql-questions/m-p/623534#M7439</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been unable to confirm the following information in the online guidance I have been looking through.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;How far back can we run an "All Actions" query in XQL? For example, can we search for file hashes going back 3 months or longer?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Also, what is the difference between running an "All Actions" query vs using the XQL Search option? Will All Actions search through and find the same information?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We also see 'max results' reached sometimes when we run queries, what is the number of max results when running queries?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 16:50:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/general-cortex-xql-questions/m-p/623534#M7439</guid>
      <dc:creator>Joe_Botelho</dc:creator>
      <dc:date>2024-11-18T16:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: General Cortex XQL questions</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/general-cortex-xql-questions/m-p/627668#M7444</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/171707"&gt;@Joe_Botelho&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- You can go back as far as the retention period allows you to do. This comes from &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/License-retention-in-Cortex-XDR" target="_self"&gt;our documentation&lt;/A&gt;&amp;nbsp;:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="itemizedlist"&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_0-1732028284409.png" style="width: 1051px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64097i4D34AFA4278F6E76/image-dimensions/1051x416?v=v2" width="1051" height="416" role="button" title="jmazzeo_0-1732028284409.png" alt="jmazzeo_0-1732028284409.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the hash is part of an alert, you can have it up to 186 days back, if not, 31 days. You can purchase additional retention time for specific datasets if you need it.&lt;/P&gt;
&lt;P&gt;You can go to&amp;nbsp;&lt;STRONG&gt;Settings - Configurations - Data Management -&amp;gt; Dataset Management&lt;/STRONG&gt; and check how many days of retention you have for every dataset.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- The "All actions" query using the visual interface shows the result only for the event types that are in the screen:&lt;/P&gt;
&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_2-1732028770673.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64099i99BD29444A9C67EB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jmazzeo_2-1732028770673.png" alt="jmazzeo_2-1732028770673.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
Running an XQL Query to the default dataset "dataset = xdr_data" will show more results as this includes all the event types supported by the XDR agent.&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV class="itemizedlist"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jmazzeo_3-1732028929905.png" style="width: 476px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/64100i8AD7A5499AEBB8CC/image-dimensions/476x394?v=v2" width="476" height="394" role="button" title="jmazzeo_3-1732028929905.png" alt="jmazzeo_3-1732028929905.png" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- The XQL &lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/XQL-Query-best-practices?tocId=sxI~BRnpWqUf3g6D4TpZMQ" target="_self"&gt;result limit&lt;/A&gt; is 1.000.000.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I highly recommend you to take this XQL Crash Course, that goes from basic queries to the most advanced in the second part:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-basic-xql-crash-course/ta-p/544056" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-basic-xql-crash-course/ta-p/544056&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 19 Nov 2024 16:56:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/general-cortex-xql-questions/m-p/627668#M7444</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-11-19T16:56:35Z</dc:date>
    </item>
  </channel>
</rss>

