- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-17-2024 10:56 AM
Wondering if there are plans to help build queries? Something as simple as looking for a file called "testfile" requires the query with the below code:
|preset = xdr_file
|filter action_file_name contains "testfile"
Another example that we are currently working on is a way to search for specific models of computers. As an example: "find all Latitude 7440" and show hostname, user, ip, last seen. We are assuming the information is hidden in a json file somewhere.
It makes it difficult to figure out what's needed when the easy way (builder) doesn't have certain forms and aspects to drill into. That leads to trial and error to find a solution. We tried converting Splunk queries using the convert to XQL slider which has yet to work for us.
Is there a user Library other than the official one which only has 1 in it?
Are there plans to add an AI helper to Cortex to help build queries?
SentinelONE has Purple, Crowdstrike has Charlotte, Sophos has it built into their platform as a few examples.
Thanks!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!