<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto Cortex IIS API Query in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-cortex-iis-api-query/m-p/1226430#M8223</link>
    <description>&lt;P&gt;Hello Everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="75" data-end="401"&gt;We ingest IIS logs by querying Cortex using a custom-built sensor utility. Recently, we've started encountering a &lt;CODE data-start="189" data-end="211"&gt;NullPointerException&lt;/CODE&gt;. Upon investigating in our test environment, we found that the issue is related to a field in the query result that represents the API query cost, which we use internally for debug logging.&lt;/P&gt;
&lt;P class="" data-start="75" data-end="401"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="403" data-end="623"&gt;Previously, the field was returned as &lt;CODE data-start="441" data-end="453"&gt;query_cost&lt;/CODE&gt;, but it now appears to have been renamed to &lt;CODE data-start="498" data-end="518"&gt;query_cost_charged&lt;/CODE&gt;. Since our sensor still expects the original &lt;CODE data-start="564" data-end="576"&gt;query_cost&lt;/CODE&gt; field, it fails with a &lt;CODE data-start="600" data-end="622"&gt;NullPointerException&lt;/CODE&gt;.&lt;/P&gt;
&lt;P class="" data-start="403" data-end="623"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="625" data-end="782"&gt;Could someone please confirm if this field name change was made on the API side, and share any relevant documentation or release notes regarding this update?&lt;/P&gt;
&lt;P class="" data-start="625" data-end="782"&gt;Thank you in advance!&lt;/P&gt;
&lt;P class="" data-start="625" data-end="782"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="625" data-end="782"&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Apr 2025 12:53:03 GMT</pubDate>
    <dc:creator>sushant1601</dc:creator>
    <dc:date>2025-04-14T12:53:03Z</dc:date>
    <item>
      <title>Palo Alto Cortex IIS API Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-cortex-iis-api-query/m-p/1226430#M8223</link>
      <description>&lt;P&gt;Hello Everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="75" data-end="401"&gt;We ingest IIS logs by querying Cortex using a custom-built sensor utility. Recently, we've started encountering a &lt;CODE data-start="189" data-end="211"&gt;NullPointerException&lt;/CODE&gt;. Upon investigating in our test environment, we found that the issue is related to a field in the query result that represents the API query cost, which we use internally for debug logging.&lt;/P&gt;
&lt;P class="" data-start="75" data-end="401"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="403" data-end="623"&gt;Previously, the field was returned as &lt;CODE data-start="441" data-end="453"&gt;query_cost&lt;/CODE&gt;, but it now appears to have been renamed to &lt;CODE data-start="498" data-end="518"&gt;query_cost_charged&lt;/CODE&gt;. Since our sensor still expects the original &lt;CODE data-start="564" data-end="576"&gt;query_cost&lt;/CODE&gt; field, it fails with a &lt;CODE data-start="600" data-end="622"&gt;NullPointerException&lt;/CODE&gt;.&lt;/P&gt;
&lt;P class="" data-start="403" data-end="623"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="625" data-end="782"&gt;Could someone please confirm if this field name change was made on the API side, and share any relevant documentation or release notes regarding this update?&lt;/P&gt;
&lt;P class="" data-start="625" data-end="782"&gt;Thank you in advance!&lt;/P&gt;
&lt;P class="" data-start="625" data-end="782"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="625" data-end="782"&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2025 12:53:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-cortex-iis-api-query/m-p/1226430#M8223</guid>
      <dc:creator>sushant1601</dc:creator>
      <dc:date>2025-04-14T12:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Cortex IIS API Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-cortex-iis-api-query/m-p/1226801#M8236</link>
      <description>&lt;P&gt;​I understand you're seeking information about the query_cost_charged field in Cortex XDR. As of now, the official Cortex XDR documentation does not explicitly mention a field named query_cost_charged. The documentation refers to the "query cost" associated with each API query, which is displayed in the Get Query Results API. ​&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;It's possible that the field name query_cost_charged is used internally or has been introduced in recent updates without being reflected in the public documentation. To obtain the most accurate and up-to-date information, I recommend reaching out directly to Palo Alto Networks support or your account representative. They can provide clarification on the current field names and any recent changes to the API.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 07:13:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/palo-alto-cortex-iis-api-query/m-p/1226801#M8236</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-04-17T07:13:48Z</dc:date>
    </item>
  </channel>
</rss>

