How to Get All Filter Parameters for Cortex XDR Incident or Alerts URL?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to Get All Filter Parameters for Cortex XDR Incident or Alerts URL?

L0 Member

Hi Community,

 

I'm currently working on building deep links for Cortex XDR to directly access filtered incident views via URLs like the one below:

https://<tenant>.paloaltonetworks.com/incidents/assets_and_artifacts?severity=SEV_040_HIGH&mode=all

 

I’m trying to understand:

  1. What are all the supported query parameters that can be used in this URL (e.g., severity, status, assigned_user, alert_source, etc.)?

  2. Is there a list of allowed enum values (e.g., SEV_040_HIGH, STATUS_NEW, etc.) for each of these parameters?

  3. Is this functionality officially supported or documented somewhere by Palo Alto Networks?

I’ve explored the browser developer tools and manually captured some parameters via network traffic, but it would be extremely helpful to have an official or complete list, especially for automation and dashboard integration purposes.

Actually, I need this info to execute some drilldown on custom widgets and for the same I need the exact name of parameter that are supported.

 

Any insights, documentation links, or tips from the community would be greatly appreciated!

 

Thank you in advance,

M.Singh

2 REPLIES 2

L4 Transporter

Hi m.singh972233 , 

 

For incident filtering, please check the attached image (I have circled in red all important items mentioned down bae) for how to apply filters in XDR tenant at incident page

  1. You can apply filters in the filter bar/options so that you can select the incidents you are interested in. 
  2. They you save the filter clicking on the floppy disk icon. 
  3. When saving the filter you can check the box to share the filter with your team mates
  4. On the 3 vertical dots menu at the top right corner of the screen you can unfold and select from the filter menu any filter you had created before to automatically select the incidents you want

We do not use incident filtering by manipulating URLs since there is an easy and very powerful way to filter using "and" "or" operators at the filtering area in the tenant. This is applicable in many windows as endpoint listing, alerts, incidents, etc.. 

For widgets, you have also very powerful tools at the XDR tenant, with easy drag and drop feature to create your dashboards, create widgets from XQL queries that you can later incorporate to your dashboards. Predefined dashboards and widget library ... 
Documentation is in the link: 

https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Manage-your-Widget-Li...

I hope this answers your questions and solves your problem. 

Please feel free to click on like the answer and mark the discussion as resolved


KR,

Luis 

 

Thanks, Eluis for providing the information. However, I am more interested in exploring how we can use URL for filtering alerts and incidents table. It is possible to do the same using XQL query as per documentation.

  • 205 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!