General Cortex XQL questions

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

General Cortex XQL questions

L1 Bithead

Hello, 

I have been unable to confirm the following information in the online guidance I have been looking through.

 

How far back can we run an "All Actions" query in XQL? For example, can we search for file hashes going back 3 months or longer?

Also, what is the difference between running an "All Actions" query vs using the XQL Search option? Will All Actions search through and find the same information?

We also see 'max results' reached sometimes when we run queries, what is the number of max results when running queries?

1 REPLY 1

L5 Sessionator

Hi @Joe_Botelho, thanks for reaching us using the Live Community.

 

- You can go back as far as the retention period allows you to do. This comes from our documentation :

 

 

jmazzeo_0-1732028284409.png

 

If the hash is part of an alert, you can have it up to 186 days back, if not, 31 days. You can purchase additional retention time for specific datasets if you need it.

You can go to Settings - Configurations - Data Management -> Dataset Management and check how many days of retention you have for every dataset.

 

- The "All actions" query using the visual interface shows the result only for the event types that are in the screen:

jmazzeo_2-1732028770673.png

 

Running an XQL Query to the default dataset "dataset = xdr_data" will show more results as this includes all the event types supported by the XDR agent.

 

jmazzeo_3-1732028929905.png

 

- The XQL result limit is 1.000.000.

 

I highly recommend you to take this XQL Crash Course, that goes from basic queries to the most advanced in the second part: https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-basic-xql-crash-course/ta-p...

 

If this post answers your question, please mark it as the solution.

 

JM
  • 280 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!