<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GetIndicatorsByQuery command in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/getindicatorsbyquery-command/m-p/572893#M2993</link>
    <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The output of&amp;nbsp;&lt;SPAN&gt;GetIndicatorsByQuery is a file, so I'm not sure if that format is convenient. You can use SearchIndicators to retrieve additional fields into context for ex.&amp;nbsp;!SearchIndicator query=`8.8.8.8` add_fields_to_context=firstSeen,lastSeen&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Rahul Vijaydev&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jan 2024 18:49:30 GMT</pubDate>
    <dc:creator>RahulVijaydev</dc:creator>
    <dc:date>2024-01-12T18:49:30Z</dc:date>
    <item>
      <title>GetIndicatorsByQuery command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/getindicatorsbyquery-command/m-p/572842#M2990</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone knows how to retrieve the firstSeen/creation date of an indicator using the GetIndicatorsByQuery command?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are the only fields I know that can be returned so far but none of them is the firstSeen/creationDate of the indicator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;id,value,lastSeen,investigationIDs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm unable to have it populate every fields as well to look through the available data..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 07:57:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/getindicatorsbyquery-command/m-p/572842#M2990</guid>
      <dc:creator>LIEWS05</dc:creator>
      <dc:date>2024-01-12T07:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: GetIndicatorsByQuery command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/getindicatorsbyquery-command/m-p/572893#M2993</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The output of&amp;nbsp;&lt;SPAN&gt;GetIndicatorsByQuery is a file, so I'm not sure if that format is convenient. You can use SearchIndicators to retrieve additional fields into context for ex.&amp;nbsp;!SearchIndicator query=`8.8.8.8` add_fields_to_context=firstSeen,lastSeen&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Rahul Vijaydev&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 18:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/getindicatorsbyquery-command/m-p/572893#M2993</guid>
      <dc:creator>RahulVijaydev</dc:creator>
      <dc:date>2024-01-12T18:49:30Z</dc:date>
    </item>
  </channel>
</rss>

