<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Configure XQL to detect logs not reporting rule in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/how-to-configure-xql-to-detect-logs-not-reporting-rule/m-p/1247178#M315</link>
    <description>&lt;P&gt;Folks,&lt;BR /&gt;&lt;BR /&gt;Awaiting for your valuable feedback&lt;/P&gt;</description>
    <pubDate>Mon, 02 Feb 2026 08:13:46 GMT</pubDate>
    <dc:creator>H.Pachpande430929</dc:creator>
    <dc:date>2026-02-02T08:13:46Z</dc:date>
    <item>
      <title>How to Configure XQL to detect logs not reporting rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/how-to-configure-xql-to-detect-logs-not-reporting-rule/m-p/1245910#M305</link>
      <description>&lt;P&gt;I am able to retrieve logs successfully using XQL in Cortex XSIAM.&lt;BR data-start="468" data-end="471" /&gt;&lt;BR /&gt;However, &lt;BR /&gt;I need to &lt;STRONG data-start="490" data-end="588"&gt;configure an analytics rule that triggers when &lt;EM data-start="539" data-end="586"&gt;any single expected source stops sending logs&lt;/EM&gt;&lt;/STRONG&gt; (for 10 minute,1 hours,4 hours).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-start="736" data-end="796"&gt;
&lt;P data-start="738" data-end="796"&gt;Detect when &lt;STRONG data-start="750" data-end="775"&gt;any one host / source&lt;/STRONG&gt; stops reporting logs&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="797" data-end="844"&gt;
&lt;P data-start="799" data-end="844"&gt;Alert should be raised &lt;STRONG data-start="822" data-end="844"&gt;per missing entity&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="845" data-end="893"&gt;
&lt;P data-start="847" data-end="893"&gt;Should work with &lt;STRONG data-start="864" data-end="893"&gt;Scheduled Analytics Rules&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 13:15:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/how-to-configure-xql-to-detect-logs-not-reporting-rule/m-p/1245910#M305</guid>
      <dc:creator>H.Pachpande430929</dc:creator>
      <dc:date>2026-01-19T13:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure XQL to detect logs not reporting rule</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/how-to-configure-xql-to-detect-logs-not-reporting-rule/m-p/1247178#M315</link>
      <description>&lt;P&gt;Folks,&lt;BR /&gt;&lt;BR /&gt;Awaiting for your valuable feedback&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 08:13:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/how-to-configure-xql-to-detect-logs-not-reporting-rule/m-p/1247178#M315</guid>
      <dc:creator>H.Pachpande430929</dc:creator>
      <dc:date>2026-02-02T08:13:46Z</dc:date>
    </item>
  </channel>
</rss>

