- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-18-2024 08:50 AM
Hello,
I have been unable to confirm the following information in the online guidance I have been looking through.
How far back can we run an "All Actions" query in XQL? For example, can we search for file hashes going back 3 months or longer?
Also, what is the difference between running an "All Actions" query vs using the XQL Search option? Will All Actions search through and find the same information?
We also see 'max results' reached sometimes when we run queries, what is the number of max results when running queries?
11-19-2024 08:56 AM
Hi @Joe_Botelho, thanks for reaching us using the Live Community.
- You can go back as far as the retention period allows you to do. This comes from our documentation :
If the hash is part of an alert, you can have it up to 186 days back, if not, 31 days. You can purchase additional retention time for specific datasets if you need it.
You can go to Settings - Configurations - Data Management -> Dataset Management and check how many days of retention you have for every dataset.
- The "All actions" query using the visual interface shows the result only for the event types that are in the screen:
Running an XQL Query to the default dataset "dataset = xdr_data" will show more results as this includes all the event types supported by the XDR agent.
- The XQL result limit is 1.000.000.
I highly recommend you to take this XQL Crash Course, that goes from basic queries to the most advanced in the second part: https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-basic-xql-crash-course/ta-p...
If this post answers your question, please mark it as the solution.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!