<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XQL Creation time filter in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-creation-time-filter/m-p/1225582#M8179</link>
    <description>&lt;P&gt;OK thank your reply. how can this apply to incident filter using XQL query for &lt;STRONG&gt;creation time.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = incidents&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 03 Apr 2025 13:03:30 GMT</pubDate>
    <dc:creator>Chamindu</dc:creator>
    <dc:date>2025-04-03T13:03:30Z</dc:date>
    <item>
      <title>XQL Creation time filter</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-creation-time-filter/m-p/1225425#M8176</link>
      <description>&lt;LI-CODE lang="markup"&gt;dataset = alerts&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;ARTICLE class="w-full text-token-text-primary" dir="auto" data-testid="conversation-turn-6" data-scroll-anchor="true"&gt;
&lt;DIV class="text-base my-auto mx-auto py-5 px-6"&gt;
&lt;DIV class="mx-auto flex flex-1 text-base gap-4 md:gap-5 lg:gap-6 md:max-w-3xl lg:max-w-[40rem] xl:max-w-[48rem] group/turn-messages focus-visible:outline-none" tabindex="-1"&gt;
&lt;DIV class="group/conversation-turn relative flex w-full min-w-0 flex-col agent-turn @xs/thread:px-0 @sm/thread:px-1.5 @md/thread:px-4"&gt;
&lt;DIV class="relative flex-col gap-1 md:gap-3"&gt;
&lt;DIV class="flex max-w-full flex-col flex-grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 whitespace-normal break-words text-start [.text-message+&amp;amp;]:mt-5" dir="auto" data-message-author-role="assistant" data-message-id="54903566-326a-41a0-8a45-69771bd6e6bd" data-message-model-slug="gpt-4o"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[3px]"&gt;
&lt;DIV class="markdown prose w-full break-words dark:prose-invert dark"&gt;
&lt;P class="" data-start="0" data-end="232"&gt;I need to filter alerts using XQL. However, when I use the above query in the usual format, it filters alerts based on the &lt;STRONG data-start="117" data-end="137"&gt;last update time&lt;/STRONG&gt;. What I actually need is to filter alerts based on their &lt;STRONG data-start="195" data-end="212"&gt;creation time&lt;/STRONG&gt;. How can I do that?&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/ARTICLE&gt;
&lt;DIV class="pointer-events-none h-px w-px" aria-hidden="true" data-edge="true"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Apr 2025 06:14:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-creation-time-filter/m-p/1225425#M8176</guid>
      <dc:creator>Chamindu</dc:creator>
      <dc:date>2025-04-02T06:14:31Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Creation time filter</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-creation-time-filter/m-p/1225561#M8178</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/320316"&gt;@Chamindu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In Alerts dataset, it doesn't&amp;nbsp;&lt;SPAN&gt;filters alerts based on the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG data-start="117" data-end="137"&gt;last update time.&amp;nbsp;&lt;/STRONG&gt;In Incidents dataset, _time refers to last updated time and in Alerts dataset it refers to Alert generation time on source origin. Please refer to below:&lt;/P&gt;
&lt;DIV id="message-list_1743668711.389729" class="c-virtual_list__item" tabindex="0" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1743668711.389729"&gt;
&lt;DIV class="c-message_kit__background p-message_pane_message__message c-message_kit__message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;_time: represents the timestamp of the actual event that triggered the alert.&lt;BR /&gt;&lt;I data-stringify-type="italic"&gt;event&lt;/I&gt;_timestamp:Also denotes the timestamp of the event related to the alert, typically mirroring the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="c-mrkdwn__code" data-stringify-type="code"&gt;_time&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field.&lt;BR /&gt;Arrival_time: Indicates the time when the alert was ingested into the Cortex XDR system.&lt;SPAN class="c-message__edited_label" data-sk="tooltip_parent"&gt;&amp;nbsp;(edited)&amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN class="c-message__edited_label" data-sk="tooltip_parent"&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Overview-of-the-Alerts-page" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Overview-of-the-Alerts-page&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN class="c-message__edited_label" data-sk="tooltip_parent"&gt;You can simply sort using _time field and you will get the alerts based on Creation time.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN class="c-message__edited_label" data-sk="tooltip_parent"&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking like and&amp;nbsp; on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV id="message-list_1743668835.568479" class="c-virtual_list__item" tabindex="-1" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1743668835.568479"&gt;
&lt;DIV class="c-message_kit__background p-message_pane_message__message c-message_kit__message" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__left" role="presentation"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 03 Apr 2025 09:37:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-creation-time-filter/m-p/1225561#M8178</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-04-03T09:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Creation time filter</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-creation-time-filter/m-p/1225582#M8179</link>
      <description>&lt;P&gt;OK thank your reply. how can this apply to incident filter using XQL query for &lt;STRONG&gt;creation time.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dataset = incidents&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 03 Apr 2025 13:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-creation-time-filter/m-p/1225582#M8179</guid>
      <dc:creator>Chamindu</dc:creator>
      <dc:date>2025-04-03T13:03:30Z</dc:date>
    </item>
  </channel>
</rss>

