<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Querying Users Who Changed Incident Status to &amp;quot;Action Required&amp;quot; in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/querying-users-who-changed-incident-status-to-quot-action/m-p/1228483#M186</link>
    <description>&lt;P class="" data-start="197" data-end="205"&gt;Hi Team,&lt;/P&gt;
&lt;P class="" data-start="207" data-end="509"&gt;We have a process where a user works on an incident and updates its status to &lt;STRONG data-start="285" data-end="306"&gt;"Action Required"&lt;/STRONG&gt; for further investigation. While we can see the identity of the user who made this change in the &lt;STRONG data-start="404" data-end="416"&gt;Timeline&lt;/STRONG&gt; tab of each incident, reviewing this individually for &lt;STRONG data-start="471" data-end="492"&gt;500–800 incidents&lt;/STRONG&gt; is not feasible.&lt;/P&gt;
&lt;P class="" data-start="511" data-end="709"&gt;We would like to know if there is a way to &lt;STRONG data-start="554" data-end="581"&gt;filter or export a list&lt;/STRONG&gt; of incidents along with the users who changed the status to &lt;STRONG data-start="642" data-end="663"&gt;"Action Required"&lt;/STRONG&gt;, ideally through a query or report in XSIAM.&lt;/P&gt;
&lt;P class="" data-start="711" data-end="835"&gt;Is there a method (e.g., using XQL, audit logs, or another feature) that can help us &lt;STRONG data-start="796" data-end="834"&gt;retrieve this information at scale&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P class="" data-start="837" data-end="861"&gt;&lt;BR /&gt;Thank you&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2025 12:38:17 GMT</pubDate>
    <dc:creator>AvinashAddala</dc:creator>
    <dc:date>2025-05-08T12:38:17Z</dc:date>
    <item>
      <title>Querying Users Who Changed Incident Status to "Action Required"</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/querying-users-who-changed-incident-status-to-quot-action/m-p/1228483#M186</link>
      <description>&lt;P class="" data-start="197" data-end="205"&gt;Hi Team,&lt;/P&gt;
&lt;P class="" data-start="207" data-end="509"&gt;We have a process where a user works on an incident and updates its status to &lt;STRONG data-start="285" data-end="306"&gt;"Action Required"&lt;/STRONG&gt; for further investigation. While we can see the identity of the user who made this change in the &lt;STRONG data-start="404" data-end="416"&gt;Timeline&lt;/STRONG&gt; tab of each incident, reviewing this individually for &lt;STRONG data-start="471" data-end="492"&gt;500–800 incidents&lt;/STRONG&gt; is not feasible.&lt;/P&gt;
&lt;P class="" data-start="511" data-end="709"&gt;We would like to know if there is a way to &lt;STRONG data-start="554" data-end="581"&gt;filter or export a list&lt;/STRONG&gt; of incidents along with the users who changed the status to &lt;STRONG data-start="642" data-end="663"&gt;"Action Required"&lt;/STRONG&gt;, ideally through a query or report in XSIAM.&lt;/P&gt;
&lt;P class="" data-start="711" data-end="835"&gt;Is there a method (e.g., using XQL, audit logs, or another feature) that can help us &lt;STRONG data-start="796" data-end="834"&gt;retrieve this information at scale&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P class="" data-start="837" data-end="861"&gt;&lt;BR /&gt;Thank you&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 12:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/querying-users-who-changed-incident-status-to-quot-action/m-p/1228483#M186</guid>
      <dc:creator>AvinashAddala</dc:creator>
      <dc:date>2025-05-08T12:38:17Z</dc:date>
    </item>
  </channel>
</rss>

