<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex Data Lake - Windows 11 Build &amp;amp; Enablement(?) Info in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-data-lake-windows-11-build-amp-enablement-info/m-p/1241614#M8861</link>
    <description>&lt;P&gt;Windows 11 (and 10 presumably) has a series of numbers which, together, identify the build and patch level of the OS.&amp;nbsp; This would be a combination of Version: &lt;SPAN&gt;Windows 11 and/or Build Number: 10.0.22631.&amp;nbsp; The Patch Level (or Enablement Level) is shown by an additional 4 digit number at the end of the Build Number like Windows Build 10.0.22631.&lt;STRONG&gt;4317&lt;/STRONG&gt;.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;In the Cortex Data Lake I can find all this, in the Operating System and OS Version fields, &lt;STRONG&gt;except&lt;/STRONG&gt;&amp;nbsp;for the Patch/Enablement 4 digit number.&amp;nbsp;Does this exist in the Cortex Data Lake and, if so, how would I get it?&lt;/P&gt;</description>
    <pubDate>Wed, 12 Nov 2025 00:15:50 GMT</pubDate>
    <dc:creator>kenlacrosse</dc:creator>
    <dc:date>2025-11-12T00:15:50Z</dc:date>
    <item>
      <title>Cortex Data Lake - Windows 11 Build &amp; Enablement(?) Info</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-data-lake-windows-11-build-amp-enablement-info/m-p/1241614#M8861</link>
      <description>&lt;P&gt;Windows 11 (and 10 presumably) has a series of numbers which, together, identify the build and patch level of the OS.&amp;nbsp; This would be a combination of Version: &lt;SPAN&gt;Windows 11 and/or Build Number: 10.0.22631.&amp;nbsp; The Patch Level (or Enablement Level) is shown by an additional 4 digit number at the end of the Build Number like Windows Build 10.0.22631.&lt;STRONG&gt;4317&lt;/STRONG&gt;.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;In the Cortex Data Lake I can find all this, in the Operating System and OS Version fields, &lt;STRONG&gt;except&lt;/STRONG&gt;&amp;nbsp;for the Patch/Enablement 4 digit number.&amp;nbsp;Does this exist in the Cortex Data Lake and, if so, how would I get it?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2025 00:15:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-data-lake-windows-11-build-amp-enablement-info/m-p/1241614#M8861</guid>
      <dc:creator>kenlacrosse</dc:creator>
      <dc:date>2025-11-12T00:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex Data Lake - Windows 11 Build &amp; Enablement(?) Info</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-data-lake-windows-11-build-amp-enablement-info/m-p/1249062#M9174</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/102416"&gt;@kenlacrosse&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="flex flex-col text-sm"&gt;
&lt;ARTICLE class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" tabindex="-1" data-turn="assistant" data-scroll-anchor="true" data-testid="conversation-turn-12" data-turn-id="request-WEB:58004001-668f-4d2f-a1df-26fe28b221e7-5"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:--spacing(4)] @w-sm/main:[--thread-content-margin:--spacing(6)] @w-lg/main:[--thread-content-margin:--spacing(16)] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" tabindex="-1"&gt;
&lt;DIV class="flex max-w-full flex-col grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;amp;]:mt-1" dir="auto" data-message-model-slug="gpt-5-2" data-message-id="a1a1c919-3d8c-4a78-80b5-64734cb92e75" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden first:pt-[1px]"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word light markdown-new-styling"&gt;
&lt;P data-end="277" data-start="0"&gt;The detailed 4-digit Windows patch level (known as the &lt;STRONG data-end="86" data-start="55"&gt;Update Build Revision (UBR)&lt;/STRONG&gt;) is not natively available as a standard, indexed field within the Cortex XDR/XSIAM management console or within standard Cortex Data Lake datasets (such as &lt;CODE data-end="255" data-start="244"&gt;endpoints&lt;/CODE&gt; or &lt;CODE data-end="275" data-start="259"&gt;host_inventory&lt;/CODE&gt;).&lt;/P&gt;
&lt;P data-end="277" data-start="0"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="488" data-start="279"&gt;By design, the platform synchronizes only the major OS build number (for example, &lt;CODE data-end="373" data-start="361"&gt;10.0.22631&lt;/CODE&gt;). The granular revision string changes frequently and is not considered critical for standard security monitoring.&lt;/P&gt;
&lt;P data-end="488" data-start="279"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="533" data-start="495"&gt;How to Retrieve the Full Patch Level:&lt;/H4&gt;
&lt;H5 data-end="602" data-start="535"&gt;1. On-Demand Collection via Action Center (Recommended for Bulk):&lt;/H5&gt;
&lt;P data-end="727" data-start="604"&gt;You can use the Action Center to run a remote command that gathers the full Windows version string from selected endpoints.&lt;/P&gt;
&lt;H5 data-end="739" data-start="729"&gt;Steps:&lt;/H5&gt;
&lt;OL data-end="1010" data-start="741"&gt;
&lt;LI data-end="814" data-start="741"&gt;
&lt;P data-end="814" data-start="744"&gt;Navigate to:&lt;BR data-end="759" data-start="756" /&gt;&lt;STRONG data-end="814" data-start="762"&gt;Incident and Response &amp;gt; Response &amp;gt; Action Center&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="878" data-start="816"&gt;
&lt;P data-end="878" data-start="819"&gt;Click &lt;STRONG data-end="841" data-start="825"&gt;+ New Action&lt;/STRONG&gt; and select &lt;STRONG data-end="877" data-start="853"&gt;Run Endpoint Scripts&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="937" data-start="880"&gt;
&lt;P data-end="937" data-start="883"&gt;Search for and select the &lt;STRONG data-end="929" data-start="909"&gt;execute_commands&lt;/STRONG&gt; script.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1010" data-start="939"&gt;
&lt;P data-end="1010" data-start="942"&gt;In the &lt;STRONG data-end="969" data-start="949"&gt;Script Parameter&lt;/STRONG&gt; field, enter the native Windows command:&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;ver&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL start="5" data-end="1241" data-start="1025"&gt;
&lt;LI data-end="1071" data-start="1025"&gt;
&lt;P data-end="1071" data-start="1028"&gt;Select your target hosts and click &lt;STRONG data-end="1070" data-start="1063"&gt;Run&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1241" data-start="1073"&gt;
&lt;P data-end="1241" data-start="1076"&gt;After execution completes, the full version string (for example:&lt;BR data-end="1143" data-start="1140" /&gt;&lt;CODE data-end="1191" data-start="1146"&gt;Microsoft Windows [Version 10.0.22631.4317]&lt;/CODE&gt;) will appear in the Action Center results column.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1285" data-start="1248"&gt;2. Live Terminal (Single Endpoint):&lt;/H4&gt;
&lt;P data-end="1382" data-start="1287"&gt;For an individual endpoint, you can use Live Terminal and run the following PowerShell command:&lt;/P&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border corner-superellipse/1.1 border-token-border-light bg-token-bg-elevated-secondary rounded-3xl"&gt;
&lt;DIV class="corner-superellipse/1.1 rounded-3xl bg-token-bg-elevated-secondary"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Get-ComputerInfo -Property WindowsProductName, WindowsVersion, OsHardwareAbstractionLayer&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1552" data-start="1483"&gt;This returns detailed OS version properties directly from the system.&lt;/P&gt;
&lt;P data-end="1552" data-start="1483"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-end="1608" data-start="1559"&gt;3. Agent Log Analysis (Troubleshooting Method):&lt;/H4&gt;
&lt;P data-end="1768" data-start="1610"&gt;The revision number is also captured locally by the agent. It can be found in the &lt;CODE data-end="1716" data-start="1692"&gt;cortex-xdr-payload.log&lt;/CODE&gt; file under the &lt;STRONG data-end="1763" data-start="1732"&gt;UBR (Update Build Revision)&lt;/STRONG&gt; key.&lt;/P&gt;
&lt;P data-end="1792" data-start="1770"&gt;Typical file location:&lt;/P&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border corner-superellipse/1.1 border-token-border-light bg-token-bg-elevated-secondary rounded-3xl"&gt;
&lt;DIV class="corner-superellipse/1.1 rounded-3xl bg-token-bg-elevated-secondary"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;C:\ProgramData\Cyvera\Logs\SandboxService\ClassificationEngine\cortex-xdr-payload.log&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="2095" data-start="1889"&gt;Note: Accessing this file requires either manual retrieval from the endpoint or generating a &lt;STRONG data-end="2009" data-start="1982"&gt;Tech Support File (TSF)&lt;/STRONG&gt;. This method is generally used for troubleshooting rather than large-scale reporting.&lt;/P&gt;
&lt;P data-end="2095" data-start="1889"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="2095" data-start="1889"&gt;&lt;STRONG&gt;Summary&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL data-is-only-node="" data-is-last-node="" data-end="2430" data-start="2115"&gt;
&lt;LI data-end="2182" data-start="2115"&gt;
&lt;P data-end="2182" data-start="2117"&gt;The 4-digit Windows UBR is &lt;STRONG data-end="2159" data-start="2144"&gt;not indexed&lt;/STRONG&gt; in XDR/XSIAM datasets.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2240" data-start="2183"&gt;
&lt;P data-end="2240" data-start="2185"&gt;Only the major build number is synchronized by default.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-is-last-node="" data-end="2430" data-start="2241"&gt;
&lt;P data-end="2279" data-start="2243"&gt;To obtain the full patch level, use:&lt;/P&gt;
&lt;UL data-is-last-node="" data-end="2430" data-start="2282"&gt;
&lt;LI data-end="2338" data-start="2282"&gt;
&lt;P data-end="2338" data-start="2284"&gt;&lt;STRONG data-end="2338" data-start="2284"&gt;Action Center (recommended for multiple endpoints)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2378" data-start="2341"&gt;
&lt;P data-end="2378" data-start="2343"&gt;&lt;STRONG data-end="2378" data-start="2343"&gt;Live Terminal (single endpoint)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-is-last-node="" data-end="2430" data-start="2381"&gt;
&lt;P data-is-last-node="" data-end="2430" data-start="2383"&gt;&lt;STRONG data-is-last-node="" data-end="2430" data-start="2383"&gt;Agent log review (advanced troubleshooting)&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/ARTICLE&gt;
&lt;/DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2026 14:04:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-data-lake-windows-11-build-amp-enablement-info/m-p/1249062#M9174</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-26T14:04:43Z</dc:date>
    </item>
  </channel>
</rss>

