<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Querying System Notifications in XSIAM/XDR in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/querying-system-notifications-in-xsiam-xdr/m-p/1249338#M366</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1363312887"&gt;@Lekshmi.gopinathannair&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="525" data-start="136"&gt;In Cortex XSIAM/XDR, infrastructure notifications and system-based alerts are distributed across different datasets depending on the specific type of event (e.g., hardware health vs. management status). The &lt;STRONG data-end="353" data-start="343"&gt;alerts&lt;/STRONG&gt; dataset primarily contains security-related signals and specific built-in health alerts, which is why it may not match the full history seen in the UI Notification Center.&lt;/P&gt;
&lt;P data-end="614" data-start="527"&gt;To track Broker VM disk space and connectivity, use the following datasets and queries:&lt;/P&gt;
&lt;H4 data-end="663" data-start="621"&gt;1. Broker VM Disk Space (Health Alerts):&lt;/H4&gt;
&lt;P data-end="892" data-start="665"&gt;Built-in system health alerts, such as a Broker VM reaching the 90% disk usage threshold, are stored in the &lt;STRONG data-end="783" data-start="773"&gt;alerts&lt;/STRONG&gt; dataset but are categorized under a specific domain. You must filter for the &lt;STRONG data-end="871" data-start="861"&gt;HEALTH&lt;/STRONG&gt; domain to find them.&lt;/P&gt;
&lt;H5 data-end="908" data-start="894"&gt;&lt;STRONG data-end="908" data-start="894"&gt;XQL Query:&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&lt;SPAN&gt;dataset &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; alerts&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN class="ͼ8"&gt;|&lt;/SPAN&gt;&lt;SPAN&gt; filter alert_domain contains &lt;/SPAN&gt;&lt;SPAN class="ͼc"&gt;"HEALTH"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;H4&gt;&lt;SPAN&gt;2. Connectivity and Status (Audit Logs):&lt;/SPAN&gt;&lt;/H4&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1141" data-start="1029"&gt;Infrastructure status changes, such as Broker VM disconnections, are primarily tracked in the auditing datasets.&lt;/P&gt;
&lt;H5 data-end="1166" data-start="1143"&gt;Management Auditing:&lt;/H5&gt;
&lt;P data-end="1331" data-start="1168"&gt;Use this dataset for official disconnection/reconnection status. A "Disconnect" log entry is typically generated only after 60 continuous minutes of disconnection.&lt;/P&gt;
&lt;P data-end="1331" data-start="1168"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1373" data-start="1333"&gt;&lt;STRONG data-end="1373" data-start="1333"&gt;Query to identify Broker VM actions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;dataset &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; managementauditing &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="ͼ8"&gt;|&lt;/SPAN&gt;&lt;SPAN&gt; filter configtype &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;=&lt;/SPAN&gt; &lt;SPAN class="ͼc"&gt;"Broker VMs"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H5 data-end="1480" data-start="1457"&gt;Collection Auditing:&lt;/H5&gt;
&lt;P data-end="1601" data-start="1482"&gt;This dataset is more effective for monitoring shorter outages or specific applet failures (e.g., Syslog or WEC issues).&lt;/P&gt;
&lt;P data-end="1601" data-start="1482"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5 data-end="1639" data-start="1603"&gt;&lt;STRONG data-end="1639" data-start="1603"&gt;Query for applet status changes:&lt;/STRONG&gt;&lt;/H5&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;dataset &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; collection_auditing &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="ͼ8"&gt;|&lt;/SPAN&gt;&lt;SPAN&gt; filter classification &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;in&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="ͼc"&gt;"error"&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="ͼc"&gt;"warning"&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;H5&gt;&lt;SPAN&gt;Why XQL May Not Match the UI Notification Center:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1885" data-start="1790"&gt;There are several reasons for discrepancies between XQL results and the UI Notification Center:&lt;/P&gt;
&lt;UL data-end="2574" data-start="1887"&gt;
&lt;LI data-end="2094" data-start="1887"&gt;
&lt;P data-end="2094" data-start="1889"&gt;&lt;STRONG data-end="1915" data-start="1889"&gt;UI-Only Notifications:&lt;/STRONG&gt; Certain operational notifications, such as “Broker VM requires a reboot” or “Update Available,” are designed as UI-only features and are not always exposed in queryable datasets.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2287" data-start="2098"&gt;
&lt;P data-end="2287" data-start="2100"&gt;&lt;STRONG data-end="2123" data-start="2100"&gt;Logging Thresholds:&lt;/STRONG&gt; Some status logs (such as disconnections in &lt;CODE data-end="2188" data-start="2168"&gt;managementauditing&lt;/CODE&gt;) have time-based thresholds that prevent them from appearing in XQL unless the condition persists.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2574" data-start="2289"&gt;
&lt;P data-end="2574" data-start="2291"&gt;&lt;STRONG data-end="2315" data-start="2291"&gt;Performance Metrics:&lt;/STRONG&gt; Historical resource utilization (CPU/RAM/Disk load over time) is not ingested into standard XQL datasets.&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2026 17:23:48 GMT</pubDate>
    <dc:creator>susekar</dc:creator>
    <dc:date>2026-03-03T17:23:48Z</dc:date>
    <item>
      <title>Querying System Notifications in XSIAM/XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/querying-system-notifications-in-xsiam-xdr/m-p/1249245#M365</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;DIV class="Y3BBE" data-complete="true" data-processed="true" data-hveid="CAEICRAA" data-sfc-cb="" data-sfc-cp=""&gt;Does anyone know the correct dataset to use for fetching system-based notifications? I need to track infrastructure alerts like Broker VM disk space and connectivity status via XQL.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE class="o8j0Mc" dir="ltr" data-sae="" data-complete="true" data-sfc-cb=""&gt;dataset = alerts&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;isn't showing the same history I see in my UI notification centre. Any tips?&lt;BUTTON class="rBl3me" tabindex="0" data-hveid="CAEICRAB" data-ved="2ahUKEwjal6m2qYKTAxVeSGcHHWEkNtkQye0OegYIAQgJEAE" data-wiz-attrbind="disabled=gVLb9b_1l/C5gNJc;aria-label=gVLb9b_1l/bOjMyf;class=gVLb9b_1l/UpSNec" aria-label="View related links" data-icl-uuid="f24b55c3-8ca4-4ad9-a226-2c3966968092" data-amic="true"&gt;&lt;/BUTTON&gt;&lt;/DIV&gt;
&lt;DIV class="Fsg96" data-processed="true" data-complete="true" data-sfc-cb="" data-sfc-cp=""&gt;Thanks&lt;/DIV&gt;</description>
      <pubDate>Mon, 02 Mar 2026 23:04:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/querying-system-notifications-in-xsiam-xdr/m-p/1249245#M365</guid>
      <dc:creator>Lekshmi.gopinathannair</dc:creator>
      <dc:date>2026-03-02T23:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Querying System Notifications in XSIAM/XDR</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/querying-system-notifications-in-xsiam-xdr/m-p/1249338#M366</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1363312887"&gt;@Lekshmi.gopinathannair&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="525" data-start="136"&gt;In Cortex XSIAM/XDR, infrastructure notifications and system-based alerts are distributed across different datasets depending on the specific type of event (e.g., hardware health vs. management status). The &lt;STRONG data-end="353" data-start="343"&gt;alerts&lt;/STRONG&gt; dataset primarily contains security-related signals and specific built-in health alerts, which is why it may not match the full history seen in the UI Notification Center.&lt;/P&gt;
&lt;P data-end="614" data-start="527"&gt;To track Broker VM disk space and connectivity, use the following datasets and queries:&lt;/P&gt;
&lt;H4 data-end="663" data-start="621"&gt;1. Broker VM Disk Space (Health Alerts):&lt;/H4&gt;
&lt;P data-end="892" data-start="665"&gt;Built-in system health alerts, such as a Broker VM reaching the 90% disk usage threshold, are stored in the &lt;STRONG data-end="783" data-start="773"&gt;alerts&lt;/STRONG&gt; dataset but are categorized under a specific domain. You must filter for the &lt;STRONG data-end="871" data-start="861"&gt;HEALTH&lt;/STRONG&gt; domain to find them.&lt;/P&gt;
&lt;H5 data-end="908" data-start="894"&gt;&lt;STRONG data-end="908" data-start="894"&gt;XQL Query:&lt;/STRONG&gt;&lt;/H5&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&lt;SPAN&gt;dataset &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; alerts&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN class="ͼ8"&gt;|&lt;/SPAN&gt;&lt;SPAN&gt; filter alert_domain contains &lt;/SPAN&gt;&lt;SPAN class="ͼc"&gt;"HEALTH"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;H4&gt;&lt;SPAN&gt;2. Connectivity and Status (Audit Logs):&lt;/SPAN&gt;&lt;/H4&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1141" data-start="1029"&gt;Infrastructure status changes, such as Broker VM disconnections, are primarily tracked in the auditing datasets.&lt;/P&gt;
&lt;H5 data-end="1166" data-start="1143"&gt;Management Auditing:&lt;/H5&gt;
&lt;P data-end="1331" data-start="1168"&gt;Use this dataset for official disconnection/reconnection status. A "Disconnect" log entry is typically generated only after 60 continuous minutes of disconnection.&lt;/P&gt;
&lt;P data-end="1331" data-start="1168"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-end="1373" data-start="1333"&gt;&lt;STRONG data-end="1373" data-start="1333"&gt;Query to identify Broker VM actions:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;dataset &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; managementauditing &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="ͼ8"&gt;|&lt;/SPAN&gt;&lt;SPAN&gt; filter configtype &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;=&lt;/SPAN&gt; &lt;SPAN class="ͼc"&gt;"Broker VMs"&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H5 data-end="1480" data-start="1457"&gt;Collection Auditing:&lt;/H5&gt;
&lt;P data-end="1601" data-start="1482"&gt;This dataset is more effective for monitoring shorter outages or specific applet failures (e.g., Syslog or WEC issues).&lt;/P&gt;
&lt;P data-end="1601" data-start="1482"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H5 data-end="1639" data-start="1603"&gt;&lt;STRONG data-end="1639" data-start="1603"&gt;Query for applet status changes:&lt;/STRONG&gt;&lt;/H5&gt;
&lt;DIV class="relative w-full my-4"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼ5 ͼj" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;dataset &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;=&lt;/SPAN&gt;&lt;SPAN&gt; collection_auditing &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class="ͼ8"&gt;|&lt;/SPAN&gt;&lt;SPAN&gt; filter classification &lt;/SPAN&gt;&lt;SPAN class="ͼ8"&gt;in&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="ͼc"&gt;"error"&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="ͼc"&gt;"warning"&lt;/SPAN&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;H5&gt;&lt;SPAN&gt;Why XQL May Not Match the UI Notification Center:&lt;/SPAN&gt;&lt;/H5&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1885" data-start="1790"&gt;There are several reasons for discrepancies between XQL results and the UI Notification Center:&lt;/P&gt;
&lt;UL data-end="2574" data-start="1887"&gt;
&lt;LI data-end="2094" data-start="1887"&gt;
&lt;P data-end="2094" data-start="1889"&gt;&lt;STRONG data-end="1915" data-start="1889"&gt;UI-Only Notifications:&lt;/STRONG&gt; Certain operational notifications, such as “Broker VM requires a reboot” or “Update Available,” are designed as UI-only features and are not always exposed in queryable datasets.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2287" data-start="2098"&gt;
&lt;P data-end="2287" data-start="2100"&gt;&lt;STRONG data-end="2123" data-start="2100"&gt;Logging Thresholds:&lt;/STRONG&gt; Some status logs (such as disconnections in &lt;CODE data-end="2188" data-start="2168"&gt;managementauditing&lt;/CODE&gt;) have time-based thresholds that prevent them from appearing in XQL unless the condition persists.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2574" data-start="2289"&gt;
&lt;P data-end="2574" data-start="2291"&gt;&lt;STRONG data-end="2315" data-start="2291"&gt;Performance Metrics:&lt;/STRONG&gt; Historical resource utilization (CPU/RAM/Disk load over time) is not ingested into standard XQL datasets.&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 17:23:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/querying-system-notifications-in-xsiam-xdr/m-p/1249338#M366</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-03-03T17:23:48Z</dc:date>
    </item>
  </channel>
</rss>

