- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-12-2023 12:27 AM
Hello Everyone,
We use below endpoint to collect the alerts:
06-13-2023 08:24 AM
Hi @sushant1601 ,
Happy to hear from you!
So a quick summary as below:
I hope that was helpful to you and answered your question, please let me know if any!
Thanks,
Z
06-13-2023 08:20 AM
Hi @sushant1601 ,
In a recent discussion you had here : https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-x...
It was mentioned that the local_insert_ts is the timestamp for the data ingestion for the alert event in XDR and you were also provided a reference for API documentation. The field in the API shows the same. However, if you would go down further in the same document, you should have been able to find the fields captured using the same API which clearly refers to the local_insert_ts which corresponds to the creation time for the alert in Cortex XDR.
I have attached screenshot of an excerpt out of the same and would request you to look into the documentation details in the response fields sample section.
06-13-2023 08:24 AM
Hi @sushant1601 ,
Happy to hear from you!
So a quick summary as below:
I hope that was helpful to you and answered your question, please let me know if any!
Thanks,
Z
06-13-2023 10:02 AM
Thank you for your response @neelrohit
In the recent discussion https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/detail-description-of-alert-log-fields-x... I asked about creation time and local_insert_time. The response there was clear about it, but what was not clear is that if server creation time is the local insert time. I couldn't find this link in documentation. I could able to see we can use server creation time, but my doubt was if the field in the logs for it is local insert time.
Anyways, thank you for your response.
06-13-2023 10:03 AM
Thank you so much @zarnous .
Appreciate the clarification.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!