Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Exporting alert related data

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Exporting alert related data

L2 Linker

Hi All,

 

Is there a way to export all the alert data which appears below Causality chain like network connections, registry changes, etc ?

 

I don't see any download or export icon on the right-hand side of the pane. 

 

Do we have any other way to export these data?

 

Thanks!!

Cortex XDR 



Please note you are posting a public message where community members and experts can provide assistance. Sharing private information such as serial numbers or company information is not recommended.
1 accepted solution

Accepted Solutions

You can run a XQL query to retrieve the information and export the data to pass to your n/w Ops team.

bbarmanroy_0-1659326605613.png

 

 

You can also leverage the Network Connections in Query Builder to identify connections.

bbarmanroy_2-1659326711085.png

 

bbarmanroy_1-1659326653295.png

 

The results can be downloaded in TSV format and shared across other teams.

View solution in original post

4 REPLIES 4

L3 Networker

Hi @MithunKT You would be able to retrieve alert data by selecting an existing alert only.

To retrieve the alert data follow the documentation here: https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-respo...
See section Retrieve Additional Alert Details
In Step 2 - follow the Retrieve alert data section
Once in new tab(pivot to view Additional data) right click, then Download Files

L5 Sessionator

Hi @MithunKT what is the use case you're trying to achieve by exporting the data? Is the end goal to ingest into a SIEM?

Hi @bbarmanroy it was for analysis and Investigation purposes. We got an incident from Analytics alert source stating internal scanning was observed, on checking the alert data we found multiple failed network connections from a single host towards multiple internal Destinations.

We just wanted to pass on this data (List of destinations, protocols) everything to the network team but exporting option was not available.

So how do we export the data in these scenarios?  We can't give access to the XDR console to our network team but they should be given alert data in csv or tsv format.

 

Thanks!!

 

You can run a XQL query to retrieve the information and export the data to pass to your n/w Ops team.

bbarmanroy_0-1659326605613.png

 

 

You can also leverage the Network Connections in Query Builder to identify connections.

bbarmanroy_2-1659326711085.png

 

bbarmanroy_1-1659326653295.png

 

The results can be downloaded in TSV format and shared across other teams.

  • 1 accepted solution
  • 3597 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!