<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BIOC with IPV6 in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-with-ipv6/m-p/1244952#M8947</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please open a case with Palo alto Networks Tech support.&lt;/P&gt;
&lt;P&gt;Please mark the solution as accepted ,if it helps.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jan 2026 11:37:24 GMT</pubDate>
    <dc:creator>ssingh32</dc:creator>
    <dc:date>2026-01-06T11:37:24Z</dc:date>
    <item>
      <title>BIOC with IPV6</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-with-ipv6/m-p/1244806#M8945</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't create BIOC with IPV6 query, please any idea?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bouzeghoub_0-1767525775172.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70247i5975405687F46A59/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bouzeghoub_0-1767525775172.png" alt="Bouzeghoub_0-1767525775172.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;BR&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jan 2026 11:23:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-with-ipv6/m-p/1244806#M8945</guid>
      <dc:creator>Bouzeghoub</dc:creator>
      <dc:date>2026-01-04T11:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC with IPV6</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-with-ipv6/m-p/1244952#M8947</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please open a case with Palo alto Networks Tech support.&lt;/P&gt;
&lt;P&gt;Please mark the solution as accepted ,if it helps.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 11:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-with-ipv6/m-p/1244952#M8947</guid>
      <dc:creator>ssingh32</dc:creator>
      <dc:date>2026-01-06T11:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: BIOC with IPV6</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-with-ipv6/m-p/1244977#M8957</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1161122151"&gt;@Bouzeghoub&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="154" data-end="413"&gt;The error &lt;STRONG data-start="164" data-end="211"&gt;“Query failed due to invalid query pattern”&lt;/STRONG&gt; when attempting to create a &lt;STRONG data-start="240" data-end="248"&gt;BIOC&lt;/STRONG&gt; with an IPv6 query typically occurs because IPv6 fields are not fully supported in the standard BIOC GUI builder, even if those fields appear as selectable options.&lt;/P&gt;
&lt;P data-start="415" data-end="617"&gt;While IPv6 support for &lt;STRONG data-start="438" data-end="446"&gt;IOCs&lt;/STRONG&gt; (Indicators of Compromise) and &lt;STRONG data-start="478" data-end="486"&gt;EDLs&lt;/STRONG&gt; (External Dynamic Lists) is currently limited, IPv6 &lt;STRONG data-start="539" data-end="616"&gt;is supported in BIOC rules when you create them using a direct XQL query&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-start="415" data-end="617"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="619" data-end="683"&gt;To successfully create your BIOC, follow the requirements below:&lt;/P&gt;
&lt;HR data-start="685" data-end="688" /&gt;
&lt;H4 data-start="690" data-end="721"&gt;1. Use the XQL Query Builder&lt;/H4&gt;
&lt;P data-start="723" data-end="909"&gt;Instead of the GUI-based &lt;STRONG data-start="748" data-end="760"&gt;Behavior&lt;/STRONG&gt; section, use the &lt;STRONG data-start="778" data-end="785"&gt;XQL&lt;/STRONG&gt; option to define your rule. Complex patterns and specific network fields such as IPv6 often require XQL to pass validation.&lt;/P&gt;
&lt;H4 data-start="916" data-end="947"&gt;2. Include Mandatory Filters&lt;/H4&gt;
&lt;P data-start="949" data-end="1057"&gt;For a query to be valid for BIOC creation, it must include an explicit filter on the &lt;STRONG data-start="1034" data-end="1050"&gt;&lt;CODE data-start="1036" data-end="1048"&gt;event_type&lt;/CODE&gt;&lt;/STRONG&gt; field.&lt;/P&gt;
&lt;P data-start="1059" data-end="1101"&gt;For network-related IPv6 queries, include:&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre! language-xql"&gt;&lt;SPAN&gt;| filter event_type = NETWORK&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-start="1145" data-end="1148" /&gt;
&lt;H4 data-start="1150" data-end="1179"&gt;3. Use Correct IPv6 Syntax&lt;/H4&gt;
&lt;P data-start="1181" data-end="1389"&gt;When filtering for IPv6 addresses in XQL, ensure you are using supported operators and valid IPv6 formats. For CIDR matching, use the appropriate IPv6 CIDR functions (for example, &lt;CODE data-start="1361" data-end="1370"&gt;incidr6&lt;/CODE&gt; where applicable).&lt;/P&gt;
&lt;H4 data-start="1391" data-end="1438"&gt;Example of a valid IPv6 BIOC XQL structure:&lt;/H4&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre! language-xql"&gt;&lt;SPAN&gt;dataset = xdr_data
| filter event_type = NETWORK
| filter action_remote_ip_v6 = "2001:db8::1"   // Replace with your target IPv6&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-start="1581" data-end="1584" /&gt;
&lt;H4 data-start="1586" data-end="1613"&gt;4. Troubleshooting Steps&lt;/H4&gt;
&lt;UL data-start="1615" data-end="2138"&gt;
&lt;LI data-start="1615" data-end="1809"&gt;
&lt;P data-start="1617" data-end="1809"&gt;&lt;STRONG data-start="1617" data-end="1640"&gt;Verify field names:&lt;/STRONG&gt; Ensure you are using fields specifically designated for IPv6 (such as &lt;CODE data-start="1711" data-end="1732"&gt;action_remote_ip_v6&lt;/CODE&gt;), or confirm that the IP fields in your dataset version support IPv6 values.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1810" data-end="1963"&gt;
&lt;P data-start="1812" data-end="1963"&gt;&lt;STRONG data-start="1812" data-end="1841"&gt;Test in XQL Search first:&lt;/STRONG&gt; Always run the query in the &lt;STRONG data-start="1870" data-end="1884"&gt;XQL Search&lt;/STRONG&gt; tab before saving it as a BIOC. If it fails there, it will not work as a BIOC.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1964" data-end="2138"&gt;
&lt;P data-start="1966" data-end="2138"&gt;&lt;STRONG data-start="1966" data-end="1995"&gt;Avoid prohibited clauses:&lt;/STRONG&gt; Do not include unsupported commands such as &lt;CODE data-start="2040" data-end="2050"&gt;| fields&lt;/CODE&gt;, &lt;CODE data-start="2052" data-end="2061"&gt;| dedup&lt;/CODE&gt;, &lt;CODE data-start="2063" data-end="2072"&gt;| limit&lt;/CODE&gt;, or &lt;CODE data-start="2077" data-end="2089"&gt;| group by&lt;/CODE&gt;, as these are incompatible with the BIOC engine.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;------------------&lt;/P&gt;
&lt;P&gt;If this fails or if further confirmation of the behavior is required, please create a &lt;STRONG data-start="141" data-end="153"&gt;TAC case&lt;/STRONG&gt; so it can be reviewed with them or escalated to the &lt;STRONG data-start="206" data-end="234"&gt;backend engineering team&lt;/STRONG&gt; for validation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution"&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy New year!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jan 2026 15:44:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/bioc-with-ipv6/m-p/1244977#M8957</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-01-06T15:44:41Z</dc:date>
    </item>
  </channel>
</rss>

