Datasets and presets

Every Cortex Query Language (XQL) dataset query begins by identifying a data source that the query will run against. Each data source has a unique name, and a series of fields. Your query specifies the data source, and then provides stages that identify fields of interest and perform operations against those fields.

You can query against either datasets or Presets in a dataset query. XQL supports using different languages for dataset and field names. In addition, the dataset formats supported are dependent on the data retention offerings available in Cortex XSIAM according to whether you want to query hot storage (default) or cold storage. For more information, see XQL Language Structure.

Datasets

The standard, built-in data source that is available in every Cortex XSIAM instance is the xdr_data dataset. This is a very large dataset with many available fields. For more information about this dataset, see Cortex XQL Schema Reference Guide. Cortex Query Language (XQL) supports using different languages for dataset and field names. In addition, the dataset formats supported are dependent on the data retention offerings available in Cortex XSIAM according to whether you want to query hot storage (default) or cold storage. For more information, see XQL Language Structure.

This dataset is comprised of both raw Endpoint Detection and Response (EDR) events reported by the Cortex XSIAM agent, and of logs from different sources such as third-party logs. To help you investigate events more efficiently, Cortex XSIAM also stitches these logs and events together into common schemas called stories. These stories are available using the Cortex XSIAM Presets.

Building queries in XQL

When building queries in XQL, keep the following in mind about datasets:

  • Use the dataset keyword to specify a dataset on your query.
  • Create custom datasets using the target stage.
  • Dataset names can use uppercase characters, but in queries dataset names are always treated as if they are lowercase. In addition, dataset names are supported using different languages, numbers (0-9), and underscores (_). Yet, underscores cannot be the first character of the name.
  • Upon ingestion, all fields are retained even fields with a null value. You can also use XQL to query parsing rules for null values.
  • Schema changes to datasets may not be reflected in the autocomplete suggestions and definitions as you type in real time the XQL query and can appear with a slight delay.

Available datasets

Depending on your integrations, you can have the following datasets available for queries:

Data Dataset
Active Directory via Cloud Identity Engine <p>pan_dss_raw</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Note</p><p>To set up this Cloud Identity Engine (previously called Directory Sync Service (DSS)) dataset, you need to set up a Cloud Identity Engine. Otherwise, you will not have a pan_dss_raw dataset. For more information, see Set up Cloud Identity Engine.</p></div>
Asset groups <p>asset_groups
Provides metadata for asset groups. Use this dataset to retrieve the human-readable group name for use in queries, reports, and dashboards.</p>
Issues table in Cortex XSIAM <p>issues</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><ul><li>INFO issues are not included in this dataset.</li><li>This dataset includes issues from the Security and Health domains. For more information, see Overview of the Issues page.</li></ul></div>
Authentication logs (subset of xdr_data) <p>Authentication logs, such as Okta: auth_logs</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The fields contained in this dataset are a subset of the fields in the xdr_data dataset.</p></div>
AWS CloudTrail and Amazon CloudWatch <Vendor>_<Product>_raw
Azure Event Hub <ul><li>All logs: MSFT_Azure_raw</li><li>Normalize and enrich audit logs: cloud_audit_logs</li></ul>
Azure Network Watcher <ul><li>All logs: MSFT_Azure_raw</li><li>Normalize and enrich flow logs: xdr_dataset dataset with a preset called network_story</li></ul>
BeyondTrust Privilege Management Cloud beyondtrust_privilege_management_raw
Box <p>Events (admin_logs)</p><ul><li>box_admin_logs_raw</li></ul><p>Box Shield Alerts</p><ul><li>box_shield_alerts_raw</li></ul><p>Users</p><ul><li>box_users_raw</li></ul><p>Groups</p><ul><li>box_groups_raw</li></ul>
Checkpoint FW1/VPN1 <Vendor>_<Product>_raw
Cisco ASA <p>Cisco ASA firewalls or Cisco AnyConnect VPN</p><ul><li>cisco_asa_raw</li></ul>
Collector status change audit for collection integrations, custom collectors, and marketplace collectors. collection_auditing
Corelight Zeek corelight_zeek_raw
Correlation rule executions correlations_auditing
Cortex Data Lakes xdr_data
Cortex XDR Collectors panw_xdrc_raw
Cortex XSIAM Host Firewall enforcement events host_firewall_events
CrowdStrike FDR <ul><li>crowdstrike_falcon_incident_raw</li><li>crowdstrike_fdr_raw</li></ul>
CSV files in shared Windows directory Custom datasets: Select from pre-existing user-created datasets or add a new dataset.
Database data (MySQL, PostgreSQL, MSSQL, and Oracle) <Vendor>_<Product>_raw
Data ingestion health metrics <p>Datasets:</p><ul><li>data_ingestion_health</li></ul><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>IMPORTANT: This dataset will not be updated after June 2024. Use the health_alerts dataset instead.</p></div><ul><li>metrics_source</li></ul><p>Presets:</p><ul><li>data_ingestion_metrics (this preset will be deprecated in the next release and replaced by metrics_view).</li><li>metrics_view</li></ul>
Dropbox <p>Events</p><ul><li>dropbox_events_raw</li></ul><p>Member Devices</p><ul><li>dropbox_members_devices_raw</li></ul><p>Users</p><ul><li>dropbox_users_raw</li></ul><p>Groups</p><ul><li>dropbox_groups_raw</li></ul>
Elasticsearch Filebeat <Vendor>_<Product>_raw
Elasticsearch Winlogbeat <p><Vendor>_<Product>_raw</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>If the vendor and product are not specified in the Winlogbeat profile’s configuration file, Cortex XSIAM creates a default dataset called microsoft_windows_raw.</p></div>
Errors related to Parsing Rules and Data Model Rules parsing_rules_errors
Errors related to event forwarding event_forwarding_errors
Forcepoint DLP forcepoint_dlp_endpoint_raw
Fortinet Fortigate <Vendor>_<Product>_raw
GlobalProtect access authentication logs <p>xdr_data</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>To ensure GlobalProtect access authentication logs are sent to Cortex AgentiX, verify that your PANW firewall’s Log Settings for GlobalProtect has the Cortex Data Lake checkbox selected.</p></div>
Google Cloud Platform (GCP) logs <ul><li>All log types: google_cloud_logging_raw</li><li><p>Normalize and enrich audit and flow logs: cloud_audit_logs</p><ul><li>Audit logs: cloud_audit_logs</li><li>Network flow logs: xdr_dataset dataset with a preset called network_story</li></ul></li></ul>
Google Kubernetes Engine (GKE) <Vendor>_<Product>_raw
Google Workspace <ul><li>Google Chrome: google_workspace_chrome_raw</li><li>Admin Console: google_workspace_admin_console_raw</li><li>Google Chat: google_workspace_chat_raw</li><li>Enterprise Groups: google_workspace_enterprise_groups_raw</li><li>Login: google_workspace_login_raw</li><li>Rules: google_workspace_rules_raw</li><li>Google drive: google_workspace_drive_raw</li><li>Token: google_workspace_token_raw</li><li>User Accounts: google_workspace_user_accounts_raw</li><li>SAML: google_workspace_saml_raw</li><li>Alerts: google_workspace_alerts_raw</li><li>Emails: google_gmail_raw</li></ul>
Host Inventory and Vulnerability Assessment <ul><li><p>Datasets</p><ul><li>host_inventory</li><li>va_cves</li><li>va_endpoints</li></ul></li><li><p>Presets</p><ul><li>host_inventory</li><li>host_inventory_accessibility</li><li>host_inventory_applications</li><li>host_inventory_auto_runs</li><li>host_inventory_cpus</li><li>host_inventory_daemons</li><li>host_inventory_disks</li><li>host_inventory_drivers</li><li>host_inventory_endpoints</li><li>host_inventory_extensions</li><li>host_inventory_groups</li><li>host_inventory_kbs</li><li>host_inventory_mounts</li><li>host_inventory_services</li><li>host_inventory_shares</li><li>host_inventory_users</li><li>host_inventory_volumes</li><li>host_inventory_vss</li></ul></li></ul>
Cases table in Cortex XSIAM cases
Indicators indicators
IT performance metrics it_metrics
JSON or text logs from third-party source over HTTP <Vendor>_<Product>_raw
Login logs (subset of xdr_data) <p>Login logs, such as WEC: login_logs</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The fields contained in this dataset are a subset of the fields in the xdr_data dataset.</p></div>
Logs from third party source over FTP, FTPS, or SFTP <Vendor>_<Product>_raw
Microsoft Defender for Endpoint msft_defender_raw
Microsoft 365 (email) <ul><li>msft_o365_emails_raw</li><li>msft_o365_users_raw</li><li>msft_o365_groups_raw</li><li>msft_o365_devices_raw</li><li>msft_o365_mailboxes_raw</li><li>msft_o365_rules_raw</li><li>msft_o365_contacts_raw</li></ul>
Microsoft Office 365 <ul><li><p>Microsoft Office 365 audit events from Management Activity API:</p><ul><li>Azure AD Activity Logs: msft_o365_azure_ad_raw</li><li>Exchange Online: msft_o365_exchange_online_raw</li><li>Sharepoint Online: msft_o365_sharepoint_online_raw</li><li>DLP: msft_o365_dlp_raw</li><li>General: msft_o365_general_raw</li></ul></li><li>Microsoft Office 365 emails via Microsoft’s Graph API: msft_o365_emails_raw</li><li>Azure AD authentication events from Microsoft Graph API: msft_azure_ad_raw</li><li>Azure AD audit events from Microsoft Graph API: msft_azure_ad_audit_raw</li><li>Alerts from Microsoft Graph Security API: msft_graph_security_alerts_raw</li></ul>
NetFlow <ul><li>ip_flow_ip_flow_raw (default)</li><li>When configured, uses the format <Vendor>_<Product>_raw</li></ul>
Network Share logs <Vendor>_<Product>_raw
Okta okta_sso_raw
OneLogin <p>Log collection</p><ul><li>onelogin_events_raw</li></ul><p>Directory</p><ul><li>onelogin_users_raw</li><li>onelogin_groups_raw</li><li>onelogin_apps_raw</li></ul>
PANW EDR xdr_data
PANW IOT Security <p>Alerts</p><ul><li>panw_iot_security_alerts_raw</li></ul><p>Devices</p><ul><li>panw_iot_security_devices_raw</li></ul>
PANW NGFW <p>panw_ngfw__raw</p><p>Supports the following logs.</p><ul><li>Authentication Logs: panw_ngfw_auth_raw</li><li><p>Configuration Logs: panw_ngfw_config_raw</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Prisma Access firewalls do not send configuration logs to the Structured Log Storage (SLS).</p></div></li><li>File Data Logs: panw_ngfw_filedata_raw</li><li>Global Protect Logs: panw_ngfw_globalprotect_raw</li><li>Hipmatch Logs: panw_ngfw_hipmatch_raw</li><li>System Logs: panw_ngfw_system_raw</li><li>Threat Logs: panw_ngfw_threat_raw</li><li>Traffic Logs: panw_ngfw_traffic_raw</li><li>URL Logs: panw_ngfw_url_raw</li><li>User ID Logs: panw_ngfw_userid_raw</li><li>Tunnel Logs: panw_ngfw_tunnel_raw</li><li>Configuration Logs: panw_ngfw_config_raw</li></ul><p>These datasets use the query field names as described in the Cortex schema documentation.</p>
PingFederate ping_identity_pingfederate_raw
PingOne for Enterprise pingone_sso_raw
Playbook runs playbook_runs
Playbook tasks playbook_tasks
Prisma Browser panw_prisma_access_browser_raw
Prisma Cloud prisma_cloud_raw
Prisma Cloud Compute prisma_cloud_compute_raw
Proofpoint Targeted Attack Protection proofpoint_tap_raw
Scripts and commands metrics scripts_and_commands_metrics
SentinelOne DeepVisibility sentinelone_deep_visibility_raw
ServiceNow CMDB A ServiceNow CMDB dataset is created for each table configured for data collection using the format servicenow_cmdb_<table name>_raw.
Salesforce.com <ul><li>salesforce_connectedapplication_raw</li><li>salesforce_permissionset_raw</li><li>salesforce_profile_raw</li><li>salesforce_groupmember_raw</li><li>salesforce_group_raw</li><li>salesforce_user_raw</li><li>salesforce_userrole_raw</li><li>salesforce_document_raw</li><li>salesforce_contentfolder_raw</li><li>salesforce_attachment_raw</li><li>salesforce_contentdistribution_raw</li><li>salesforce_tenantsecuritylogin_raw</li><li>salesforce_useraccountteammember_raw</li><li>salesforce_tenantsecurityuserperm_raw</li><li>salesforce_account_raw</li><li>salesforce_audit_raw</li><li>salesforce_login_raw</li><li>salesforce_eventlogfile_raw</li></ul>
Syslog/CEF <CEFVendor>_<CEFProduct>_raw
USB devices connect and disconnect events reported by the agent <p>xdr_data</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><ul><li>You can query in XQL for this data and build widgets based on the xdr_data dataset or using the preset device_control.</li><li>To view in an XQL query these events, the Device Configuration of the endpoint profile must be set to Block. Otherwise, the USB events are not captured. The events are also captured when a group of device types are blocked on the endpoints with a permanent or temporary exception in place. For more information, see Ingest Connect and Disconnect Events of USB Devices.</li></ul></div>
VPN logs (subset of xdr_data) <p>VPN logs, such as GlobalProtect: vpn_logs</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>The fields contained in this dataset are a subset of the fields in the xdr_data dataset.</p></div>
Windows Endpoints using Cortex XDR Forensics Add-on <ul><li>forensics_amcache</li><li>forensics_application_resource_usage</li><li>forensics_arp_cache</li><li>forensics_background_activity_monitor</li><li>forensics_chrome_history</li><li>forensics_cid_size_mru</li><li>forensics_command_history</li><li>forensics_dns_cache</li><li>forensics_edge_anaheim_history</li><li>forensics_edge_spartan_history</li><li>forensics_event_log</li><li>forensics_file_access</li><li>forensics_file_listing</li><li>forensics_firefox_history</li><li>forensics_handles</li><li>forensics_hosts_file</li><li>forensics_internet_explorer_history</li><li>forensics_jumplist</li><li>forensics_last_visited_pidl_mru</li><li>forensics_log_me_in</li><li>forensics_net_sessions</li><li>forensics_network</li><li>forensics_network_connectivity_usage</li><li>forensics_network_data_usage</li><li>forensics_open_save_pidl_mru</li><li>forensics_port_listing</li><li>forensics_prefetch</li><li>forensics_process_execution</li><li>forensics_process_listing</li><li>forensics_psreadline</li><li>forensics_recent_files</li><li>forensics_recentfilecache</li><li>forensics_recycle_bin</li><li>forensics_registry</li><li>forensics_remote_access</li><li>forensics_seven_zip_folder_history</li><li>forensics_shellbags</li><li>forensics_shimcache</li><li>forensics_team_viewer</li><li>forensics_typed_paths</li><li>forensics_typed_urls</li><li>forensics_user_access_logging</li><li>forensics_user_assist</li><li>forensics_windows_activities</li><li>forensics_winrar_arc_history</li><li>forensics_word_wheel_query</li></ul>
Windows event logs via Cortex XDR Windows agents microsoft_windows_raw
Windows Event Collector (WEC) <ul><li>xdr_data</li><li>microsoft_windows_raw</li></ul>
Windows DHCP using Elasticsearch Filebeat microsoft_dhcp_raw
Windows DNS Debug using Elasticsearch Filebeat <p>Raw Data</p><ul><li>microsoft_dns_raw</li></ul><p>Normalized Stories</p><ul><li>xdr_data with the preset called network_story.</li></ul>
Workday workday_workday_raw
Zscaler Cloud Firewall <p>ZIA</p><ul><li>Firewall logs: zscaler_nssfwlog_raw</li><li>Web logs: zscalar_nssweblog_raw</li></ul><p>ZPA</p><ul><li>zscaler_zpa_raw</li></ul>

Presets

Presets offer groupings of xdr_data fields that are useful for analyzing specific areas of network and endpoint activity. All of the fields available for a preset are also available on the larger xdr_data dataset, but by using the preset your query can run more efficiently. Presets are sorted at random by the first one million results found.

Two of the available presets are stories. These contain information stitched together from Cortex XSIAM agent events and log files to form a common schema. They are authentication_story and network_story.

You use the preset keyword to specify a dataset in your query.