<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic A doubt with ElasticSearch Integration and EQL searches (es-eql-search) in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/a-doubt-with-elasticsearch-integration-and-eql-searches-es-eql/m-p/552050#M2437</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm currently working on how to make some EQL queries to my Elastic Instance from Cortex XSOAR. I'm using ElasticSearch integration, specifically the command "&lt;SPAN&gt;es-eql-search" which purposoe, I guess, is to make a EQL query to ElasticSearch API. However, regarding to the XSOAR documentation related to the Elastic's integrations, I can see that "Query" parameter has to be in Lucene Syntax... and that not makes sense because we "can't" transform an EQL query to a Lucene Query.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Im trying to make an EQL query like:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="programlisting prettyprint lang-eql prettyprinted"&gt;&lt;SPAN class="pln"&gt;process &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;where&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; process&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;name &lt;/SPAN&gt;&lt;SPAN class="pun"&gt;==&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"svchost.exe"&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN class="str"&gt;&lt;BR /&gt;But it seems that it not works and every parameters seems to be right.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="str"&gt;Any suggestions?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="str"&gt;Update: I confirm that my query runs ok. But there's a problem with the results. I cant load query hits to the context. If the output is too big, a file is returned...if not, the output is returned as a results that I can only view through another window. Is there a solution to load the output in the context? (Quiet mode: off) (I tried to ExtendContext too and it not works :S)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="str"&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Aug 2023 09:56:43 GMT</pubDate>
    <dc:creator>SergioPalacios</dc:creator>
    <dc:date>2023-08-02T09:56:43Z</dc:date>
    <item>
      <title>A doubt with ElasticSearch Integration and EQL searches (es-eql-search)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/a-doubt-with-elasticsearch-integration-and-eql-searches-es-eql/m-p/552050#M2437</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm currently working on how to make some EQL queries to my Elastic Instance from Cortex XSOAR. I'm using ElasticSearch integration, specifically the command "&lt;SPAN&gt;es-eql-search" which purposoe, I guess, is to make a EQL query to ElasticSearch API. However, regarding to the XSOAR documentation related to the Elastic's integrations, I can see that "Query" parameter has to be in Lucene Syntax... and that not makes sense because we "can't" transform an EQL query to a Lucene Query.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Im trying to make an EQL query like:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="programlisting prettyprint lang-eql prettyprinted"&gt;&lt;SPAN class="pln"&gt;process &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;where&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; process&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;name &lt;/SPAN&gt;&lt;SPAN class="pun"&gt;==&lt;/SPAN&gt; &lt;SPAN class="str"&gt;"svchost.exe"&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN class="str"&gt;&lt;BR /&gt;But it seems that it not works and every parameters seems to be right.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="str"&gt;Any suggestions?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="str"&gt;Update: I confirm that my query runs ok. But there's a problem with the results. I cant load query hits to the context. If the output is too big, a file is returned...if not, the output is returned as a results that I can only view through another window. Is there a solution to load the output in the context? (Quiet mode: off) (I tried to ExtendContext too and it not works :S)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="str"&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 09:56:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/a-doubt-with-elasticsearch-integration-and-eql-searches-es-eql/m-p/552050#M2437</guid>
      <dc:creator>SergioPalacios</dc:creator>
      <dc:date>2023-08-02T09:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: A doubt with ElasticSearch Integration and EQL searches (es-eql-search)</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/a-doubt-with-elasticsearch-integration-and-eql-searches-es-eql/m-p/552714#M2467</link>
      <description>&lt;P&gt;In this case, I would recommend maybe writing something custom using our API core that would make the call and put the result in the context or maybe even a file that could be used by the playbook.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Information about our API:&amp;nbsp;&lt;A href="https://cortex.marketplace.pan.dev/marketplace/details/DemistoRESTAPI/" target="_blank"&gt;https://cortex.marketplace.pan.dev/marketplace/details/DemistoRESTAPI/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 02:09:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/a-doubt-with-elasticsearch-integration-and-eql-searches-es-eql/m-p/552714#M2467</guid>
      <dc:creator>Ivetto</dc:creator>
      <dc:date>2023-08-07T02:09:14Z</dc:date>
    </item>
  </channel>
</rss>

