<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR Query for USB/External Drive Usage in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-for-usb-external-drive-usage/m-p/1222336#M7987</link>
    <description>&lt;P&gt;Hi Family&amp;nbsp;&lt;/P&gt;
&lt;P data-start="106" data-end="121"&gt;Good morning.&lt;/P&gt;
&lt;P data-start="123" data-end="321"&gt;I am trying to filter the timeframe when a user last connected a USB flash drive or external hard drive using a Cortex XDR query. However, the following query did not return the expected results:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"&gt;
&lt;DIV class="flex items-center text-token-text-secondary px-4 py-2 text-xs font-sans justify-between rounded-t-[5px] h-9 bg-token-sidebar-surface-primary dark:bg-token-main-surface-secondary select-none"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="!whitespace-pre language-sql"&gt;&lt;SPAN&gt;dataset &lt;SPAN class="hljs-operator"&gt;=&lt;/SPAN&gt; xdr_data  
&lt;SPAN class="hljs-operator"&gt;|&lt;/SPAN&gt; &lt;SPAN class="hljs-keyword"&gt;filter&lt;/SPAN&gt; event_type &lt;SPAN class="hljs-operator"&gt;=&lt;/SPAN&gt; device &lt;SPAN class="hljs-keyword"&gt;and&lt;/SPAN&gt; event_sub_type &lt;SPAN class="hljs-operator"&gt;=&lt;/SPAN&gt; DEVICE_PLUG  &lt;BR /&gt;
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P data-start="420" data-end="588"&gt;I would like to retrieve details such as the user, vendor, timestamp, and device name. Could you please assist me in refining the query to achieve the desired output?&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Endpoint Protection" id="Endpoint_Protection"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 02 Mar 2025 02:59:31 GMT</pubDate>
    <dc:creator>Prashanta</dc:creator>
    <dc:date>2025-03-02T02:59:31Z</dc:date>
    <item>
      <title>Cortex XDR Query for USB/External Drive Usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-for-usb-external-drive-usage/m-p/1222336#M7987</link>
      <description>&lt;P&gt;Hi Family&amp;nbsp;&lt;/P&gt;
&lt;P data-start="106" data-end="121"&gt;Good morning.&lt;/P&gt;
&lt;P data-start="123" data-end="321"&gt;I am trying to filter the timeframe when a user last connected a USB flash drive or external hard drive using a Cortex XDR query. However, the following query did not return the expected results:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary dark:bg-gray-950"&gt;
&lt;DIV class="flex items-center text-token-text-secondary px-4 py-2 text-xs font-sans justify-between rounded-t-[5px] h-9 bg-token-sidebar-surface-primary dark:bg-token-main-surface-secondary select-none"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="!whitespace-pre language-sql"&gt;&lt;SPAN&gt;dataset &lt;SPAN class="hljs-operator"&gt;=&lt;/SPAN&gt; xdr_data  
&lt;SPAN class="hljs-operator"&gt;|&lt;/SPAN&gt; &lt;SPAN class="hljs-keyword"&gt;filter&lt;/SPAN&gt; event_type &lt;SPAN class="hljs-operator"&gt;=&lt;/SPAN&gt; device &lt;SPAN class="hljs-keyword"&gt;and&lt;/SPAN&gt; event_sub_type &lt;SPAN class="hljs-operator"&gt;=&lt;/SPAN&gt; DEVICE_PLUG  &lt;BR /&gt;
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P data-start="420" data-end="588"&gt;I would like to retrieve details such as the user, vendor, timestamp, and device name. Could you please assist me in refining the query to achieve the desired output?&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Endpoint Protection" id="Endpoint_Protection"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Mar 2025 02:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-for-usb-external-drive-usage/m-p/1222336#M7987</guid>
      <dc:creator>Prashanta</dc:creator>
      <dc:date>2025-03-02T02:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Query for USB/External Drive Usage</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-for-usb-external-drive-usage/m-p/1222364#M7989</link>
      <description>&lt;P&gt;FYI, I used this to retrive filename from USB drive&lt;/P&gt;
&lt;P&gt;Hope this helps&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;dataset = xdr_data // Using the xdr dataset&lt;BR /&gt;| filter event_type = ENUM.FILE and event_sub_type = ENUM.FILE_CREATE_NEW // Looking for file creation events&lt;BR /&gt;| alter Drive_Type = json_extract(to_json_string(action_file_device_info),"$.storage_device_drive_type"), Filesystem = json_extract_scalar(to_json_string(action_file_device_info),"$.storage_device_filesystem"), Drive_Letter = json_extract_scalar(to_json_string(action_file_device_info),"$.storage_device_mount_point"), Device_Serial_Number = json_extract_scalar(to_json_string(action_file_device_info),"$.storage_device_serial_number") // Getting details about the device a file was created on&lt;BR /&gt;| filter drive_type = "2" // Filtering by drive type 2 which is 'Removable Media'&lt;BR /&gt;| fields action_file_path as File_Path, actor_effective_username as Username, Filesystem, Drive_Letter, Device_Serial_Number, event_type, event_sub_type // Selecting the relevant fields&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 03:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-query-for-usb-external-drive-usage/m-p/1222364#M7989</guid>
      <dc:creator>SeanDeHarris</dc:creator>
      <dc:date>2025-03-03T03:01:56Z</dc:date>
    </item>
  </channel>
</rss>

