Create an Event Log Query
Create a query to investigate Windows event log attributes
and investigate event logs across endpoints.
From the
Query Builder
you
can search Windows event log attributes and investigate event logs
across endpoints with an Cortex XDR agent installed. 
Some examples
of event log queries you can run include:
- Critical level messages on specific endpoints.
- Message descriptions with specific keywords on specific endpoints.
To
build a file query:
- From Cortex XDR, select.INVESTIGATIONQuery Builder
- SelectEVENT LOG.
- Enter the search criteria for your Windows event log query.Define any event attributes for which you want to search. By default, Cortex XDR will return the events that match the attribute you specify. To exclude an attribute value, toggle the=option to=!. Attributes are:
- PROVIDER NAME—The provider of the event log.
- USERNAME—The username associated with the event.
- EVENT ID—The unique ID of the event.
- LEVEL—The event severity level.
- MESSAGE—The description of the event.
To specify an additional exception (match this value except), click the+to the right of the value and specify the exception value.
- (Optional) Limit the scope to an endpoint or endpoint attributes:Select
and specify one or more of the following attributes:
- HOST—HOST NAME,HOST IPaddress,HOST OS,HOST MAC ADDRESS, orINSTALLATION TYPE.INSTALLATION TYPEcan be either Cortex XDR agent or Data Collector.
- PROCESS—NAME,PATH,CMD,MD5,SHA256,USER NAME,SIGNATURE, orPID
Use a pipe (|) to separate multiple values. Use an asterisk (*) to match any string of characters. - Specify the time period for which you want to search for events.Options are:Last 24H(hours),Last 7D(days),Last 1M(month), or select aCustomtime period.
- Choose when to run the query.Select the calendar icon to schedule a query to run on or before a specific date,Run in backgroundto run the query as resources are available, orRunto run the query immediately and view the results in theQuery Center.
- When you are ready, View the Results of a Query.
- Specify the time period for which you want to search for events.Options are:Last 24H(hours),Last 7D(days),Last 1M(month), or select aCustomtime period.
- Choose when to run the query.Select the calendar icon to schedule a query to run on or before a specific date,Run in backgroundto run the query as resources are available, orRunto run the query immediately and view the results in theQuery Center.
- When you are ready, View the Results of a Query.
Recommended For You
Recommended Videos
Recommended videos not found.