XQL Help - Any AI tools, query library?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

XQL Help - Any AI tools, query library?

L1 Bithead

Wondering if there are plans to help build queries? Something as simple as looking for a file called "testfile" requires the query with the below code:


|preset = xdr_file
|filter action_file_name contains "testfile"

Another example that we are currently working on is a way to search for specific models of computers. As an example: "find all Latitude 7440" and show hostname, user, ip, last seen. We are assuming the information is hidden in a json file somewhere.

 

It makes it difficult to figure out what's needed when the easy way (builder) doesn't have certain forms and aspects to drill into. That leads to trial and error to find a solution. We tried converting Splunk queries using the convert to XQL slider which has yet to work for us.


Is there a user Library other than the official one which only has 1 in it?

Are there plans to add an AI helper to Cortex to help build queries?

 

SentinelONE has Purple, Crowdstrike has Charlotte, Sophos has it built into their platform as a few examples.

 

Thanks!

Cortex XDR

0 REPLIES 0
  • 41 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!