<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR Dataset - Total Days Stored in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-dataset-total-days-stored/m-p/1234368#M8571</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;for clarifying! The login_logs dataset continues to increase to the hot retention period of 31 total days stored. I am unsure if there was a problem with the capturing of such login events, or if the other possibility of no one logging in for a period of time occurred. I will post back here with any new findings.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jul 2025 14:20:22 GMT</pubDate>
    <dc:creator>nohash4u</dc:creator>
    <dc:date>2025-07-21T14:20:22Z</dc:date>
    <item>
      <title>Cortex XDR Dataset - Total Days Stored</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-dataset-total-days-stored/m-p/1234046#M8550</link>
      <description>&lt;P&gt;Hello All,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone explain as to why a dataset that is a subset of the xdr_data dataset may have a total days stored value less than the xdr_data dataset?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my case the total days stored of the login_logs dataset is less than that of the parent dataset xdr_data:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nohash4u_0-1752590429578.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68485iC3C45B91F9EE5EC1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nohash4u_0-1752590429578.png" alt="nohash4u_0-1752590429578.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is not a new configuration, so I am curious as to why there is a difference between the two.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The hot storage license for the tenant is:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nohash4u_1-1752590520611.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/68486i61F7310D93324786/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nohash4u_1-1752590520611.png" alt="nohash4u_1-1752590520611.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Cortex Data Lake" id="Cortex_Data_Lake"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 14:45:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-dataset-total-days-stored/m-p/1234046#M8550</guid>
      <dc:creator>nohash4u</dc:creator>
      <dc:date>2025-07-15T14:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Dataset - Total Days Stored</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-dataset-total-days-stored/m-p/1234261#M8561</link>
      <description>&lt;P&gt;Hi Nohash4u,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The logins_log dataset incorporates login logs from xdr agent and other login logs from other products (Global Protect VPN, Firewall....),&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XDR_dataset has much more types of different events.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;According with what I see in the pic you sent, I see that login_logs dataset has data from 22nd Jun to 12th Jul which means that there was no login events captured before and after those dates respectively&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same explanation from xdr_dataset, which contains much more types of events so different types of events than logins were captured before and after the login events in the previous dataset.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you believe that some login logs might have been missed or lost, please feel free to open a TAC support case to investigate it further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does it make sense ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 13:28:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-dataset-total-days-stored/m-p/1234261#M8561</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-07-17T13:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Dataset - Total Days Stored</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-dataset-total-days-stored/m-p/1234368#M8571</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;for clarifying! The login_logs dataset continues to increase to the hot retention period of 31 total days stored. I am unsure if there was a problem with the capturing of such login events, or if the other possibility of no one logging in for a period of time occurred. I will post back here with any new findings.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 14:20:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-dataset-total-days-stored/m-p/1234368#M8571</guid>
      <dc:creator>nohash4u</dc:creator>
      <dc:date>2025-07-21T14:20:22Z</dc:date>
    </item>
  </channel>
</rss>

