<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with timestamp_range_start and timestamp_range_end Dates in XSOAR Elasticsearch Integration Command in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/issue-with-timestamp-range-start-and-timestamp-range-end-dates/m-p/616072#M3750</link>
    <description>&lt;DIV class="p-rich_text_section"&gt;&lt;STRONG data-stringify-type="bold"&gt;Problem Description:&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG data-stringify-type="bold"&gt;The date filtering functionality for start and end dates in the Elasticsearch search command on XSOAR does not seem to be working correctly. The command used is as follows:&lt;/STRONG&gt;!es-search index="index-runtime-evts" query="queryTest" timestamp_range_start="-2y" timestamp_range_end="now"I also tried entering a specific timestamp, such as 2023-10-02T00:00:00Z in the timestamp_range_start field, but I keep getting an empty response.Additional Details:&lt;/DIV&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet p-rich_text_list--nested" data-stringify-type="unordered-list" data-list-tree="true" data-indent="0" data-border="0"&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;If I omit timestamp_range_start and timestamp_range_end in the War Room/playbook, I can retrieve all logs from the specified index (index-runtime-evts).&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;However, the goal is to filter the logs based on a 7-day range rather than retrieving the entire index history.&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Mon, 04 Nov 2024 14:07:16 GMT</pubDate>
    <dc:creator>MF762</dc:creator>
    <dc:date>2024-11-04T14:07:16Z</dc:date>
    <item>
      <title>Issue with timestamp_range_start and timestamp_range_end Dates in XSOAR Elasticsearch Integration Command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/issue-with-timestamp-range-start-and-timestamp-range-end-dates/m-p/616072#M3750</link>
      <description>&lt;DIV class="p-rich_text_section"&gt;&lt;STRONG data-stringify-type="bold"&gt;Problem Description:&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG data-stringify-type="bold"&gt;The date filtering functionality for start and end dates in the Elasticsearch search command on XSOAR does not seem to be working correctly. The command used is as follows:&lt;/STRONG&gt;!es-search index="index-runtime-evts" query="queryTest" timestamp_range_start="-2y" timestamp_range_end="now"I also tried entering a specific timestamp, such as 2023-10-02T00:00:00Z in the timestamp_range_start field, but I keep getting an empty response.Additional Details:&lt;/DIV&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet p-rich_text_list--nested" data-stringify-type="unordered-list" data-list-tree="true" data-indent="0" data-border="0"&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;If I omit timestamp_range_start and timestamp_range_end in the War Room/playbook, I can retrieve all logs from the specified index (index-runtime-evts).&lt;/LI&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;However, the goal is to filter the logs based on a 7-day range rather than retrieving the entire index history.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 04 Nov 2024 14:07:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/issue-with-timestamp-range-start-and-timestamp-range-end-dates/m-p/616072#M3750</guid>
      <dc:creator>MF762</dc:creator>
      <dc:date>2024-11-04T14:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with timestamp_range_start and timestamp_range_end Dates in XSOAR Elasticsearch Integration Command</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/issue-with-timestamp-range-start-and-timestamp-range-end-dates/m-p/616259#M3757</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I use two formats for my !es-search tasks:&lt;BR /&gt;1. exact time in format&amp;nbsp;2024-11-06T14:48:47.149000+00:00&lt;BR /&gt;2. key words like in Kibana filtering through time, like "24 hours ago", "3 months ago", etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2024 15:23:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/issue-with-timestamp-range-start-and-timestamp-range-end-dates/m-p/616259#M3757</guid>
      <dc:creator>JakubKostial</dc:creator>
      <dc:date>2024-11-06T15:23:04Z</dc:date>
    </item>
  </channel>
</rss>

