I am trying to write an XQL query that will only focus on the endpoints that I have defined in my endpoint groups and not all endpoints in the xdr_data dataset.
How can I filter the xdr_data dataset by endpoint groups?
Cortex XDR allows you to rapidly detect and respond to threats across your networks, endpoints, and clouds. It assists SOC analysts by allowing them to view ALL the alerts from all PANW products in one place, telling the full story of what actually happened in seconds and allows seamless response.
Please note: All postings in LIVEcommunity are visible to other users; please keep your network secure by refraining from posting live IP address’s or domain names here. Contact your Customer Success team for network-specific questions.