<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XQL: Anyone has working example of building analytics on XQL query? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-anyone-has-working-example-of-building-analytics-on-xql/m-p/1000022#M7653</link>
    <description>&lt;P&gt;We want to build analytics using XQL where we could find or create an alert if certain behavior has occurred for the first time on endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently, we use external help where we run XQL schedule query and then retrieve results and run python script based on our use case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestion will be helpful.&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jan 2025 03:22:40 GMT</pubDate>
    <dc:creator>KanwarSingh01</dc:creator>
    <dc:date>2025-01-03T03:22:40Z</dc:date>
    <item>
      <title>XQL: Anyone has working example of building analytics on XQL query?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-anyone-has-working-example-of-building-analytics-on-xql/m-p/1000022#M7653</link>
      <description>&lt;P&gt;We want to build analytics using XQL where we could find or create an alert if certain behavior has occurred for the first time on endpoint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently, we use external help where we run XQL schedule query and then retrieve results and run python script based on our use case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestion will be helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 03:22:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-anyone-has-working-example-of-building-analytics-on-xql/m-p/1000022#M7653</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2025-01-03T03:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: XQL: Anyone has working example of building analytics on XQL query?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-anyone-has-working-example-of-building-analytics-on-xql/m-p/1085591#M7730</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/163390"&gt;@KanwarSingh01&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for reaching out on LiveCommunity!&lt;/P&gt;
&lt;P&gt;You can use correlation rules which will help you analyse correlations of multi-events from multiple sources by using the Cortex Query Language (XQL) based engine for creating scheduled rules. Alerts can then be triggered based on these correlation rules with a defined time frame and set schedule, including every X minutes, once a day, once a week, or a custom time.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-correlation-rule" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Create-a-correlation-rule&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Then you can create automation rules to respond with endpoint scripts as per your use case.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Automation-rule-actions?tocId=Nju8rTlaDtpJAGTzhJwIBw" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Automation-rule-actions?tocId=Nju8rTlaDtpJAGTzhJwIBw&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please c&lt;SPAN&gt;lick&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Accept as Solution&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;to acknowledge that the answer to your question has been provided.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 15:08:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-anyone-has-working-example-of-building-analytics-on-xql/m-p/1085591#M7730</guid>
      <dc:creator>nsinghvirk</dc:creator>
      <dc:date>2025-01-15T15:08:43Z</dc:date>
    </item>
  </channel>
</rss>

