<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in validating XQL query to identify suspicious MFA registration from new GEO location + new device in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/need-help-in-validating-xql-query-to-identify-suspicious-mfa/m-p/1265781#M485</link>
    <description>&lt;P&gt;just to add few pointers, the above query is successfully running by changing below bold&lt;BR /&gt;&lt;SPAN&gt;dataset = okta_sso_raw&lt;BR /&gt;| filter (debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE") &lt;U&gt;&lt;STRONG&gt;and&lt;/STRONG&gt;&lt;/U&gt; (eventType in("user.mfa.factor.activate", "user.lifecycle.create", "system.import.user.create"))&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Challenge: Query is successfully running with results but when add it in correlation use-case, &lt;U&gt;the count of the cases and events are not same.&lt;/U&gt;&amp;nbsp;&lt;BR /&gt;Use-case condition, query should run every 1hr to look for last 4hrs of events, no suppression is enabled as we don't see duplicate cases.&lt;BR /&gt;Appreciate the response. thank you.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Oct 2026 16:49:48 GMT</pubDate>
    <dc:creator>MohanrajaE</dc:creator>
    <dc:date>2026-10-07T16:49:48Z</dc:date>
    <item>
      <title>Need help in validating XQL query to identify suspicious MFA registration from new GEO location + new device</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/need-help-in-validating-xql-query-to-identify-suspicious-mfa/m-p/1265717#M484</link>
      <description>&lt;P&gt;dataset = okta_sso_raw&lt;BR /&gt;| filter (debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE") and (eventType in("user.mfa.factor.activate", "user.lifecycle.create", "system.import.user.create"))&lt;BR /&gt;| alter user_id = if(eventType = "user.lifecycle.create" or eventType = "system.import.user.create", json_extract_scalar(`target`, "$.0.alternateId"), json_extract_scalar(actor, "$.alternateId")), user_name = json_extract_scalar(actor, "$.displayName"), TIME = _time&lt;BR /&gt;| alter &lt;BR /&gt;suspicious_login_time = if(debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE", _time, null),&lt;BR /&gt;suspicious_login_ip = if(debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE", json_extract_scalar(client, "$.ipAddress"), null),&lt;BR /&gt;suspicious_login_city = if(debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE", json_extract_scalar(client, "$.geographicalContext.city"),null),&lt;BR /&gt;suspicious_login_state = if(debugContext contains "New Geo-Location=POSITIVE"and debugContext contains "New Device=POSITIVE",json_extract_scalar(client, "$.geographicalContext.state"),null),&lt;BR /&gt;suspicious_login_country = if(debugContext contains "New Geo-Location=POSITIVE"and debugContext contains "New Device=POSITIVE", json_extract_scalar(client, "$.geographicalContext.country"), null),&lt;BR /&gt;suspicious_login_device = if(debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE",json_extract_scalar(client, "$.device"),null),&lt;BR /&gt;suspicious_login_os = if(debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE",json_extract_scalar(client, "$.userAgent.os"),null),&lt;BR /&gt;suspicious_login_browser = if(debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE", json_extract_scalar(client, "$.userAgent.browser"),null),&lt;BR /&gt;suspicious_login_user_agent = if(debugContext contains "New Geo-Location=POSITIVE"and debugContext contains "New Device=POSITIVE",json_extract_scalar(client, "$.userAgent.rawUserAgent"),null),&lt;BR /&gt;mfa_activation_time = if(eventType = "user.mfa.factor.activate", _time,null),&lt;BR /&gt;mfa_factor = if(eventType = "user.mfa.factor.activate",json_extract_scalar(debugContext,"$.debugData.factor"),null),&lt;BR /&gt;mfa_factor_type = if(eventType = "user.mfa.factor.activate",json_extract_scalar(debugContext,"$.debugData.factorType"),null),&lt;BR /&gt;mfa_device_name = if(eventType = "user.mfa.factor.activate",json_extract_scalar(debugContext,"$.debugData.deviceName"),null),&lt;BR /&gt;account_creation_time = if(eventType = "user.lifecycle.create" or eventType = "system.import.user.create", _time,null)&lt;BR /&gt;| windowcomp max(suspicious_login_time) by user_id sort asc _time between null and -1 as previous_suspicious_login,&lt;BR /&gt;last_value(suspicious_login_ip) by user_id sort asc _time between null and -1 as previous_suspicious_login_ip,&lt;BR /&gt;last_value(suspicious_login_city) by user_id sort asc _time between null and -1 as previous_suspicious_login_city,&lt;BR /&gt;last_value(suspicious_login_state) by user_id sort asc _time between null and -1 as previous_suspicious_login_state,&lt;BR /&gt;last_value(suspicious_login_country) by user_id sort asc _time between null and -1 as previous_suspicious_login_country,&lt;BR /&gt;last_value(suspicious_login_device) by user_id sort asc _time between null and -1 as previous_suspicious_login_device,&lt;BR /&gt;last_value(suspicious_login_os) by user_id sort asc _time between null and -1 as previous_suspicious_login_os,&lt;BR /&gt;last_value(suspicious_login_browser) by user_id sort asc _time between null and -1 as previous_suspicious_login_browser,&lt;BR /&gt;last_value(suspicious_login_user_agent) by user_id sort asc _time between null and -1 as previous_suspicious_login_user_agent,&lt;BR /&gt;min(account_creation_time) by user_id as first_account_creation&lt;BR /&gt;| filter mfa_activation_time != null&lt;BR /&gt;| filter previous_suspicious_login != null&lt;BR /&gt;| filter timestamp_diff(previous_suspicious_login, mfa_activation_time,"HOUR") &amp;gt;= 0 and timestamp_diff(previous_suspicious_login,mfa_activation_time,"HOUR") &amp;lt;= 4&lt;BR /&gt;| filter first_account_creation = null or timestamp_diff(first_account_creation,previous_suspicious_login,"DAY") &amp;gt; 30&lt;BR /&gt;| dedup user_id, previous_suspicious_login, mfa_activation_time&lt;BR /&gt;| fields user_id, user_name, previous_suspicious_login, previous_suspicious_login_ip, previous_suspicious_login_city, previous_suspicious_login_state, previous_suspicious_login_country, previous_suspicious_login_device, previous_suspicious_login_os, previous_suspicious_login_browser, previous_suspicious_login_user_agent, mfa_activation_time, mfa_device_name, mfa_factor, mfa_factor_type, first_account_creation&lt;BR /&gt;| sort desc mfa_activation_time&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2026 17:55:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/need-help-in-validating-xql-query-to-identify-suspicious-mfa/m-p/1265717#M484</guid>
      <dc:creator>MohanrajaE</dc:creator>
      <dc:date>2026-10-06T17:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in validating XQL query to identify suspicious MFA registration from new GEO location + new device</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/need-help-in-validating-xql-query-to-identify-suspicious-mfa/m-p/1265781#M485</link>
      <description>&lt;P&gt;just to add few pointers, the above query is successfully running by changing below bold&lt;BR /&gt;&lt;SPAN&gt;dataset = okta_sso_raw&lt;BR /&gt;| filter (debugContext contains "New Geo-Location=POSITIVE" and debugContext contains "New Device=POSITIVE") &lt;U&gt;&lt;STRONG&gt;and&lt;/STRONG&gt;&lt;/U&gt; (eventType in("user.mfa.factor.activate", "user.lifecycle.create", "system.import.user.create"))&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Challenge: Query is successfully running with results but when add it in correlation use-case, &lt;U&gt;the count of the cases and events are not same.&lt;/U&gt;&amp;nbsp;&lt;BR /&gt;Use-case condition, query should run every 1hr to look for last 4hrs of events, no suppression is enabled as we don't see duplicate cases.&lt;BR /&gt;Appreciate the response. thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2026 16:49:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/need-help-in-validating-xql-query-to-identify-suspicious-mfa/m-p/1265781#M485</guid>
      <dc:creator>MohanrajaE</dc:creator>
      <dc:date>2026-10-07T16:49:48Z</dc:date>
    </item>
  </channel>
</rss>

