<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: xql query for process in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-process/m-p/1241053#M8839</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1602113155"&gt;@T.Nurmi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im not sure what you mean here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you looking for parent/child process ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two different independent processes ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per your question if those processes happen, I can tell you that if you get data from a process in a query, this means that the logs are there so the process was present there&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 31 Oct 2025 10:05:55 GMT</pubDate>
    <dc:creator>eluis</dc:creator>
    <dc:date>2025-10-31T10:05:55Z</dc:date>
    <item>
      <title>xql query for process</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-process/m-p/1240646#M8826</link>
      <description>&lt;P&gt;Hi. i just try to do some basic threat hunting.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dataset = xdr_data&lt;BR /&gt;| filter action_process_image_name in ("a.exe", "b.exe")&lt;BR /&gt;| fields agent_hostname, actor_effective_username, action_process_image_name, action_process_image_command_line , _time&lt;BR /&gt;| sort desc _time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so i try to identfied two different process is happening at same endpoints. how to do that . current query just collect all process and i just want fiter that if those process happen&amp;gt; then i got event&amp;gt; example Process chrome start some other process&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 09:59:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-process/m-p/1240646#M8826</guid>
      <dc:creator>T.Nurmi</dc:creator>
      <dc:date>2025-10-24T09:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: xql query for process</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-process/m-p/1241053#M8839</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1602113155"&gt;@T.Nurmi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Im not sure what you mean here.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you looking for parent/child process ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two different independent processes ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per your question if those processes happen, I can tell you that if you get data from a process in a query, this means that the logs are there so the process was present there&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Luis&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 10:05:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-query-for-process/m-p/1241053#M8839</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-10-31T10:05:55Z</dc:date>
    </item>
  </channel>
</rss>

