- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-28-2022 12:07 AM
Hi All,
Is there a way to export all the alert data which appears below Causality chain like network connections, registry changes, etc ?
I don't see any download or export icon on the right-hand side of the pane.
Do we have any other way to export these data?
Thanks!!
07-31-2022 09:05 PM
You can run a XQL query to retrieve the information and export the data to pass to your n/w Ops team.
You can also leverage the Network Connections in Query Builder to identify connections.
The results can be downloaded in TSV format and shared across other teams.
07-28-2022 05:02 AM
Hi @MithunKT You would be able to retrieve alert data by selecting an existing alert only.
To retrieve the alert data follow the documentation here: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-respo...
See section Retrieve Additional Alert Details
In Step 2 - follow the Retrieve alert data section
Once in new tab(pivot to view Additional data) right click, then Download Files
07-28-2022 06:59 PM
Hi @MithunKT what is the use case you're trying to achieve by exporting the data? Is the end goal to ingest into a SIEM?
07-29-2022 01:25 AM
Hi @bbarmanroy it was for analysis and Investigation purposes. We got an incident from Analytics alert source stating internal scanning was observed, on checking the alert data we found multiple failed network connections from a single host towards multiple internal Destinations.
We just wanted to pass on this data (List of destinations, protocols) everything to the network team but exporting option was not available.
So how do we export the data in these scenarios? We can't give access to the XDR console to our network team but they should be given alert data in csv or tsv format.
Thanks!!
07-31-2022 09:05 PM
You can run a XQL query to retrieve the information and export the data to pass to your n/w Ops team.
You can also leverage the Network Connections in Query Builder to identify connections.
The results can be downloaded in TSV format and shared across other teams.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!