cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

L5 Sessionator

Hi @MayurLad ,

 

Incidents and alert data is not part of the XQL dataset to query upon. However, all of the events convert to XDR alerts and hence, you can navigate to alerts table to filter out all alerts from a particular hostname. 

 

You can use the filter as mentioned here: alert source=XDR Agent AND hostname="xxxx" Timestamp="<your choice of timestamp>"

 

Hope this helps!

View solution in original post

Who rated this post