<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with Conditional Task Not Matching XQL Output in Cortex XSIAM Playbook in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1243280#M284</link>
    <description>&lt;P&gt;Which is why I recommended using either of the commands I noted in my first post. Both create consistent results in context.&lt;/P&gt;</description>
    <pubDate>Sat, 06 Dec 2025 19:09:17 GMT</pubDate>
    <dc:creator>jorandall</dc:creator>
    <dc:date>2025-12-06T19:09:17Z</dc:date>
    <item>
      <title>Problem with Conditional Task Not Matching XQL Output in Cortex XSIAM Playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1242422#M279</link>
      <description>&lt;P data-start="513" data-end="540"&gt;Hello everyone,&lt;/P&gt;
&lt;P data-start="542" data-end="704"&gt;I am building a simple playbook in Cortex XSIAM to check whether an endpoint is &lt;STRONG data-start="622" data-end="635"&gt;CONNECTED&lt;/STRONG&gt; or &lt;STRONG data-start="639" data-end="655"&gt;DISCONNECTED&lt;/STRONG&gt; using an XQL query on the &lt;STRONG data-start="682" data-end="695"&gt;endpoints&lt;/STRONG&gt; dataset.&lt;/P&gt;
&lt;P data-start="706" data-end="768"&gt;The XQL query works correctly and returns the expected output:&lt;/P&gt;
&lt;P data-start="706" data-end="768"&gt;&lt;STRONG&gt;{&lt;BR /&gt;"results": [&lt;BR /&gt;{&lt;BR /&gt;"endpoint_name": "ENDPOINT_089",&lt;BR /&gt;"endpoint_status": "DISCONNECTED"&lt;BR /&gt;}&lt;BR /&gt;],&lt;BR /&gt;"status": "SUCCESS"&lt;BR /&gt;}&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="706" data-end="768"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="921" data-end="976"&gt;However, in my conditional task I am trying to compare:&lt;/P&gt;
&lt;P data-start="980" data-end="1010"&gt;&lt;CODE data-start="980" data-end="1010"&gt;endpoint_status == CONNECTED&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-start="1013" data-end="1046"&gt;&lt;CODE data-start="1013" data-end="1046"&gt;endpoint_status == DISCONNECTED &lt;BR /&gt;&lt;/CODE&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P data-start="1013" data-end="1046"&gt;Query is&amp;nbsp; "dataset = endpoints&lt;BR /&gt;| filter endpoint_name = "${inputs.EndpointName}"&lt;BR /&gt;| fields endpoint_name, endpoint_status"&lt;/P&gt;
&lt;P data-start="1013" data-end="1046"&gt;-&lt;/P&gt;
&lt;P data-start="1013" data-end="1046"&gt;I suspect the issue is that I do not know the &lt;STRONG data-start="1187" data-end="1218"&gt;correct context object name&lt;/STRONG&gt; produced by the script &lt;CODE data-start="1242" data-end="1265"&gt;xdr-xql-generic-query&lt;/CODE&gt;.&amp;nbsp;I couldn't find the correct path to reference the output of the &lt;CODE data-start="160" data-end="183"&gt;xdr-xql-generic-query&lt;/CODE&gt; script inside the Conditional task.&lt;/P&gt;
&lt;P data-start="1013" data-end="1046"&gt;What is the correct output object name for &lt;CODE data-start="1512" data-end="1535"&gt;xdr-xql-generic-query&lt;/CODE&gt; in Cortex XSIAM so I can reference &lt;CODE data-start="1571" data-end="1610"&gt;results[1].results[0].endpoint_status&lt;/CODE&gt; inside the conditional&lt;/P&gt;
&lt;P data-start="1013" data-end="1046"&gt;task?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AAliyev094633_0-1763915838126.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69904iB9F77C3A298194DF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AAliyev094633_0-1763915838126.png" alt="AAliyev094633_0-1763915838126.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AAliyev094633_1-1763915877982.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69905i8E82E358FF1F6AD7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AAliyev094633_1-1763915877982.png" alt="AAliyev094633_1-1763915877982.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AAliyev094633_2-1763915894257.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69906iCEEBAB5B24CB6F65/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AAliyev094633_2-1763915894257.png" alt="AAliyev094633_2-1763915894257.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AAliyev094633_3-1763915924145.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69907i42AA56D160D4749B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AAliyev094633_3-1763915924145.png" alt="AAliyev094633_3-1763915924145.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P data-start="1013" data-end="1046"&gt;&lt;CODE data-start="1013" data-end="1046"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P data-start="1013" data-end="1046"&gt;&lt;CODE data-start="1013" data-end="1046"&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Nov 2025 16:46:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1242422#M279</guid>
      <dc:creator>A.Aliyev094633</dc:creator>
      <dc:date>2025-11-23T16:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Conditional Task Not Matching XQL Output in Cortex XSIAM Playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1242481#M280</link>
      <description>&lt;P&gt;Theres a better and easier way to get this data without burning your Compute Units on XQL queries in playbooks. The&amp;nbsp;Investigation &amp;amp; Response integration from the Cortex Core marketplace pack includes a number of commands and scripts for interacting with your XDR endpoints, specifically the `core-get-endpoints` command,&amp;nbsp;which will return information about your XDR endpoint agents, and the `endpoint` command,&amp;nbsp;which will return information from &lt;U&gt;any&lt;/U&gt; endpoint integration you have enabled (XDR, MSFT, CRWD, etc).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jorandall_0-1764004343046.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69915i222ACD8DD28F9DB7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jorandall_0-1764004343046.png" alt="jorandall_0-1764004343046.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jorandall_1-1764004368992.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/69916i42517AE0E3561545/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jorandall_1-1764004368992.png" alt="jorandall_1-1764004368992.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Nov 2025 17:13:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1242481#M280</guid>
      <dc:creator>jorandall</dc:creator>
      <dc:date>2025-11-24T17:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Conditional Task Not Matching XQL Output in Cortex XSIAM Playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1243211#M283</link>
      <description>&lt;P&gt;Hi, yes you’re right but my issue isn’t about the XQL query itself.&lt;BR /&gt;The problem is that I cannot find a stable field/object name in the playbook output.&lt;/P&gt;
&lt;P&gt;The task output keeps changing:&amp;nbsp;&lt;SPAN&gt;I couldn't find the correct path to reference the output of the&amp;nbsp;&lt;/SPAN&gt;&lt;CODE data-start="160" data-end="183"&gt;xdr-xql-generic-query&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;script inside the Conditional task. it's not about query.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-start="696" data-end="728"&gt;That’s what I’m trying to solve.&lt;/P&gt;
&lt;P&gt;Thank you for trying to help, I really appreciate it&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2025 07:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1243211#M283</guid>
      <dc:creator>A.Aliyev094633</dc:creator>
      <dc:date>2025-12-05T07:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Conditional Task Not Matching XQL Output in Cortex XSIAM Playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1243280#M284</link>
      <description>&lt;P&gt;Which is why I recommended using either of the commands I noted in my first post. Both create consistent results in context.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Dec 2025 19:09:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1243280#M284</guid>
      <dc:creator>jorandall</dc:creator>
      <dc:date>2025-12-06T19:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Conditional Task Not Matching XQL Output in Cortex XSIAM Playbook</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1245071#M298</link>
      <description>&lt;P&gt;If you would like to catch the output from XQL in the script and compare in the conditional task, you should have a similar input:&lt;BR /&gt;&lt;BR /&gt;${PaloAltoNetworksXQL.GenericQuery.results.[0].YOUR_VALUE}&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my case, we compare the parameter first_seen, and depends on the XQL results, we have auto-resolve or additional escalation.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 11:27:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/problem-with-conditional-task-not-matching-xql-output-in-cortex/m-p/1245071#M298</guid>
      <dc:creator>MDovirak</dc:creator>
      <dc:date>2026-01-07T11:27:01Z</dc:date>
    </item>
  </channel>
</rss>

