<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Shorten returned values  in query in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/558832#M2659</link>
    <description>&lt;P&gt;I'm creating a widget so I can have a report run returning certain Managment Audit log information.&amp;nbsp; One of the fields, "Management_Auditing_type" has values that are quite long that I would like to truncate.&amp;nbsp; For example, have "MANAGEMENT_AUDIT_ACTION_CENTER" changed to "Action Center", and "Management_Audit_Policy_Profiles" changed to just "Policy Profiles".&amp;nbsp; The same goes for the fields for the results and severity.&amp;nbsp; They all start with "Management_Audit_......".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been able to change the field names but I can't figure out how to change the values that get returned.&lt;/P&gt;
&lt;P&gt;-------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;EM&gt;&lt;STRONG&gt;dataset = management_auditing &lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;EM&gt;&lt;STRONG&gt;|Fields timestamp, user_name as username, management_auditing_type as type, subtype, management_auditing_result as result, management_auditing_severity as severity, description&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;EM&gt;&lt;STRONG&gt;| filter (type in (MANAGEMENT_AUDIT_ACTION_CENTER, MANAGEMENT_AUDIT_AGENT_EXCEPTION_RULES, MANAGEMENT_AUDIT_ENDPOINT_ADMINISTRATION, MANAGEMENT_AUDIT_LICENSING, MANAGEMENT_AUDIT_POLICY_PROFILES, MANAGEMENT_AUDIT_RESPONSE))&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;-------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2023 14:55:55 GMT</pubDate>
    <dc:creator>barnettml</dc:creator>
    <dc:date>2023-09-20T14:55:55Z</dc:date>
    <item>
      <title>Shorten returned values  in query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/558832#M2659</link>
      <description>&lt;P&gt;I'm creating a widget so I can have a report run returning certain Managment Audit log information.&amp;nbsp; One of the fields, "Management_Auditing_type" has values that are quite long that I would like to truncate.&amp;nbsp; For example, have "MANAGEMENT_AUDIT_ACTION_CENTER" changed to "Action Center", and "Management_Audit_Policy_Profiles" changed to just "Policy Profiles".&amp;nbsp; The same goes for the fields for the results and severity.&amp;nbsp; They all start with "Management_Audit_......".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been able to change the field names but I can't figure out how to change the values that get returned.&lt;/P&gt;
&lt;P&gt;-------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;&lt;EM&gt;&lt;STRONG&gt;dataset = management_auditing &lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;EM&gt;&lt;STRONG&gt;|Fields timestamp, user_name as username, management_auditing_type as type, subtype, management_auditing_result as result, management_auditing_severity as severity, description&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT size="3"&gt;&lt;EM&gt;&lt;STRONG&gt;| filter (type in (MANAGEMENT_AUDIT_ACTION_CENTER, MANAGEMENT_AUDIT_AGENT_EXCEPTION_RULES, MANAGEMENT_AUDIT_ENDPOINT_ADMINISTRATION, MANAGEMENT_AUDIT_LICENSING, MANAGEMENT_AUDIT_POLICY_PROFILES, MANAGEMENT_AUDIT_RESPONSE))&lt;/STRONG&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;-------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2023 14:55:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/558832#M2659</guid>
      <dc:creator>barnettml</dc:creator>
      <dc:date>2023-09-20T14:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Shorten returned values  in query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/559937#M2664</link>
      <description>&lt;P&gt;Hi Barnettml,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Happy to assist! I'm trying to replicate your issue, but I'm trying to understand what widget type you are editing to use that filter. Additionally, if you could provide all the steps you've taken so far to try and accomplish this so I can follow your flow better.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;My understanding is that you have data in the&amp;nbsp;Management Audit Log that you are trying to expose in a report using a custom widget. Knowing the widget type in the report that you are using and the field you're inputing those filters into would help as well. Lastly, I'm assuming you are using XSOAR 8 since you're using the Management Audit Log.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and have a great day!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 21:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/559937#M2664</guid>
      <dc:creator>amenendez</dc:creator>
      <dc:date>2023-09-28T21:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Shorten returned values  in query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/559976#M2665</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/222904"&gt;@barnettml&lt;/a&gt;, That might not be possible through the basic widget. You will need to build your own script based widget, modify the data as required then return the data is widget type format.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer -&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.12/Cortex-XSOAR-Administrator-Guide/Create-a-Custom-Widget-Using-an-Automation-Script" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.12/Cortex-XSOAR-Administrator-Guide/Create-a-Custom-Widget-Using-an-Automation-Script&lt;/A&gt;&amp;nbsp;for more information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 04:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/559976#M2665</guid>
      <dc:creator>jfernandes1</dc:creator>
      <dc:date>2023-09-29T04:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Shorten returned values  in query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/560024#M2669</link>
      <description>&lt;P&gt;o I had initially put this under "General Discussion".....not sure how it ended up under XSOAR but I am in Cortex XDR.....we do not have XSOAR......yet......&amp;nbsp; &amp;nbsp;As far as how it was created I simply went to create a custom XQL widget and created the code shown above.&amp;nbsp; The problem is that I'm not sure how in XQL to change how VALUES appear.&amp;nbsp;You can see in the screenshot here that the data in the results is quite large.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="barnettml_0-1695983495678.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54069iF4E1A817980245D9/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="barnettml_0-1695983495678.png" alt="barnettml_0-1695983495678.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know this information in the data can be shortened because I see it when&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I go to settings --&amp;gt;management audit logs as seen to the right.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="barnettml_1-1695983790847.png" style="width: 200px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54070i3B70011883EC32C1/image-size/small/is-moderation-mode/true?v=v2&amp;amp;px=200" role="button" title="barnettml_1-1695983790847.png" alt="barnettml_1-1695983790847.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;My reasoning for creating this widget is so that I can have it on my dashboard as well as I've created a weekly report based off of the widget but it is truncated because these values are so big.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this explanation helps.&amp;nbsp; I just need help getting the XQL right&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 10:40:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/shorten-returned-values-in-query/m-p/560024#M2669</guid>
      <dc:creator>barnettml</dc:creator>
      <dc:date>2023-09-29T10:40:07Z</dc:date>
    </item>
  </channel>
</rss>

