<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XSIAM in Cortex XSIAM Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555137#M5</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please provide guidance on locating the raw log within the Cortex XSIAM tenant?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Anupama D.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2023 19:00:42 GMT</pubDate>
    <dc:creator>AnupamaD</dc:creator>
    <dc:date>2023-08-24T19:00:42Z</dc:date>
    <item>
      <title>Cortex XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555137#M5</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please provide guidance on locating the raw log within the Cortex XSIAM tenant?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Anupama D.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 19:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555137#M5</guid>
      <dc:creator>AnupamaD</dc:creator>
      <dc:date>2023-08-24T19:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555340#M6</link>
      <description>&lt;P&gt;Hi AnupamaD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please clarify, what do you mean by "locating the raw log"?&amp;nbsp; Are you asking how to query log data that you are bringing in to XSIAM?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2023 19:17:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555340#M6</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2023-08-25T19:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555472#M8</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/219403"&gt;@afurze&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've attached a sample log message view, which is the view that I want to see in XSIAM. &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Log View.jpeg" style="width: 315px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53201i6D639F4EDE53A9A8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Log View.jpeg" alt="Log View.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 05:21:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555472#M8</guid>
      <dc:creator>AnupamaD</dc:creator>
      <dc:date>2023-08-28T05:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XSIAM</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555522#M9</link>
      <description>&lt;P&gt;Hi AnupamaD,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want to query raw logs outside of an incident or alert context, you can use the Query Builder (Incident Response -&amp;gt; Query Builder).&amp;nbsp; You can pick one of the 'wizard' style query builders, Basic, Identity, Endpoint, Network, or Cloud, which all search using the&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-XQL-Language-Reference/Cortex-Data-Model" target="_self"&gt;Cortex Data Model&lt;/A&gt;.&amp;nbsp; If you want to write more complex queries or have more control over filtering and such, you can construct your own queries using XQL, either against a specific dataset, or, more commonly, using the same data model.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Aug 2023 13:58:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsiam-discussions/cortex-xsiam/m-p/555522#M9</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2023-08-28T13:58:06Z</dc:date>
    </item>
  </channel>
</rss>

