<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XQL Incident Count Doesn’t Match UI Incident Count — Same Date Range in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-incident-count-doesn-t-match-ui-incident-count-same-date/m-p/1226915#M8240</link>
    <description>&lt;P class="" data-start="248" data-end="260"&gt;Hi everyone,&lt;/P&gt;
&lt;P class="" data-start="262" data-end="370"&gt;I’m working on a report using Cortex XQL to count incidents created between &lt;STRONG data-start="338" data-end="369"&gt;March 15 and March 31, 2025&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="" data-start="262" data-end="370"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="372" data-end="399"&gt;Here’s the query I’m using:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;config timeframe between "2025-03-15 00:00:00" and "2025-03-31 23:59:59"
| dataset = incidents
| filter creation_time &amp;gt;= "2025-03-15 00:00:00"
  and creation_time &amp;lt;  "2025-03-31 23:59:59"
| fields incident_id, creation_time
&lt;/LI-CODE&gt;
&lt;P class="" data-start="771" data-end="814"&gt;However, I’m getting &lt;STRONG data-start="792" data-end="813"&gt;different results&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL data-start="815" data-end="889"&gt;
&lt;LI class="" data-start="815" data-end="857"&gt;
&lt;P class="" data-start="817" data-end="857"&gt;&lt;STRONG data-start="817" data-end="839"&gt;XQL query returns:&lt;/STRONG&gt; &lt;SPAN&gt;2,293&lt;/SPAN&gt;&amp;nbsp;incidents&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="" data-start="858" data-end="889"&gt;
&lt;P class="" data-start="860" data-end="889"&gt;&lt;STRONG data-start="860" data-end="873"&gt;UI shows:&lt;/STRONG&gt; 2,347 incidents&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="" data-start="1118" data-end="1284"&gt;&lt;STRONG data-start="1120" data-end="1216"&gt;Why would the XQL return less incidents than the UI, even with the same creation time range?&lt;/STRONG&gt;&lt;BR data-start="1216" data-end="1219" /&gt;Are there hidden filters in the UI or something else I'm missing?&lt;/P&gt;
&lt;P class="" data-start="1286" data-end="1316"&gt;Any help would be appreciated!&lt;/P&gt;</description>
    <pubDate>Sun, 20 Apr 2025 10:02:07 GMT</pubDate>
    <dc:creator>Chamindu</dc:creator>
    <dc:date>2025-04-20T10:02:07Z</dc:date>
    <item>
      <title>XQL Incident Count Doesn’t Match UI Incident Count — Same Date Range</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-incident-count-doesn-t-match-ui-incident-count-same-date/m-p/1226915#M8240</link>
      <description>&lt;P class="" data-start="248" data-end="260"&gt;Hi everyone,&lt;/P&gt;
&lt;P class="" data-start="262" data-end="370"&gt;I’m working on a report using Cortex XQL to count incidents created between &lt;STRONG data-start="338" data-end="369"&gt;March 15 and March 31, 2025&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="" data-start="262" data-end="370"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="372" data-end="399"&gt;Here’s the query I’m using:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;config timeframe between "2025-03-15 00:00:00" and "2025-03-31 23:59:59"
| dataset = incidents
| filter creation_time &amp;gt;= "2025-03-15 00:00:00"
  and creation_time &amp;lt;  "2025-03-31 23:59:59"
| fields incident_id, creation_time
&lt;/LI-CODE&gt;
&lt;P class="" data-start="771" data-end="814"&gt;However, I’m getting &lt;STRONG data-start="792" data-end="813"&gt;different results&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL data-start="815" data-end="889"&gt;
&lt;LI class="" data-start="815" data-end="857"&gt;
&lt;P class="" data-start="817" data-end="857"&gt;&lt;STRONG data-start="817" data-end="839"&gt;XQL query returns:&lt;/STRONG&gt; &lt;SPAN&gt;2,293&lt;/SPAN&gt;&amp;nbsp;incidents&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="" data-start="858" data-end="889"&gt;
&lt;P class="" data-start="860" data-end="889"&gt;&lt;STRONG data-start="860" data-end="873"&gt;UI shows:&lt;/STRONG&gt; 2,347 incidents&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="" data-start="1118" data-end="1284"&gt;&lt;STRONG data-start="1120" data-end="1216"&gt;Why would the XQL return less incidents than the UI, even with the same creation time range?&lt;/STRONG&gt;&lt;BR data-start="1216" data-end="1219" /&gt;Are there hidden filters in the UI or something else I'm missing?&lt;/P&gt;
&lt;P class="" data-start="1286" data-end="1316"&gt;Any help would be appreciated!&lt;/P&gt;</description>
      <pubDate>Sun, 20 Apr 2025 10:02:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-incident-count-doesn-t-match-ui-incident-count-same-date/m-p/1226915#M8240</guid>
      <dc:creator>Chamindu</dc:creator>
      <dc:date>2025-04-20T10:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: XQL Incident Count Doesn’t Match UI Incident Count — Same Date Range</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-incident-count-doesn-t-match-ui-incident-count-same-date/m-p/1227537#M8263</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/320316"&gt;@Chamindu&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;UL data-start="166" data-end="375"&gt;
&lt;LI class="" data-start="166" data-end="266"&gt;
&lt;P class="" data-start="168" data-end="266"&gt;&lt;STRONG data-start="168" data-end="183"&gt;UI Behavior&lt;/STRONG&gt;: &lt;SPAN class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"&gt;The Cortex XDR UI filters incidents based on the &lt;CODE data-start="49" data-end="56"&gt;_time&lt;/CODE&gt; field, which represents the last update time of an incident. This means that incidents created before your specified date range but updated within it will still appear in the UI results.&lt;/SPAN&gt;​&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="" data-start="268" data-end="375"&gt;
&lt;P class="" data-start="270" data-end="375"&gt;&lt;STRONG data-start="270" data-end="292"&gt;XQL Query Behavior&lt;/STRONG&gt;: &lt;SPAN class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"&gt;Your XQL query filters incidents based on the &lt;CODE data-start="46" data-end="61"&gt;creation_time&lt;/CODE&gt; field, capturing only those incidents that were created within the specified timeframe. This approach excludes incidents that were created earlier but updated during your date range.&lt;/SPAN&gt;​&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="" data-start="526" data-end="570"&gt;To align your XQL query results with the UI:&lt;/P&gt;
&lt;OL data-start="572" data-end="1064"&gt;
&lt;LI class="" data-start="572" data-end="938"&gt;
&lt;P class="" data-start="575" data-end="688"&gt;&lt;STRONG data-start="575" data-end="601"&gt;Adjust the Time Filter&lt;/STRONG&gt;: &lt;SPAN class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"&gt;Modify your XQL query to filter based on the &lt;CODE data-start="45" data-end="52"&gt;_time&lt;/CODE&gt; field instead of &lt;CODE data-start="70" data-end="85"&gt;creation_time&lt;/CODE&gt;. This change will include incidents that were updated within your specified date range, matching the UI behavior.&lt;/SPAN&gt;​&lt;/P&gt;
&lt;P class="" data-start="693" data-end="711"&gt;&lt;STRONG data-start="693" data-end="710"&gt;Updated Query&lt;/STRONG&gt;:&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-md border-[0.5px] border-token-border-medium relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="flex items-center text-token-text-secondary px-4 py-2 text-xs font-sans justify-between h-9 bg-token-sidebar-surface-primary dark:bg-token-main-surface-secondary select-none rounded-t-[5px]"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre! language-xql"&gt;&lt;SPAN&gt;config timeframe between "2025-03-15 00:00:00" and "2025-03-31 23:59:59"
| dataset = incidents
| filter _time &amp;gt;= "2025-03-15 00:00:00" and _time &amp;lt;= "2025-03-31 23:59:59"
| fields incident_id, _time
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI class="" data-start="940" data-end="1064"&gt;
&lt;P class="" data-start="943" data-end="1064"&gt;&lt;STRONG data-start="943" data-end="977"&gt;Clarify Reporting Requirements&lt;/STRONG&gt;: &lt;SPAN class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"&gt;If your reporting needs specifically require incidents based on their creation time, continue using the &lt;CODE data-start="104" data-end="119"&gt;creation_time&lt;/CODE&gt; filter. However, be aware that this will result in a lower count compared to the UI, which includes updated incidents.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="relative -mx-px my-[-0.2rem] rounded px-px py-[0.2rem] transition-colors duration-100 ease-in-out"&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking like and&amp;nbsp; on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 09:53:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-incident-count-doesn-t-match-ui-incident-count-same-date/m-p/1227537#M8263</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-04-28T09:53:25Z</dc:date>
    </item>
  </channel>
</rss>

