1. Home
Location
    Techdocs Logo Techdocs Logo
    • Documentation Home
    • Palo Alto Networks
    • Support
    • Live Community
    • Knowledge Base
    1. Home
    2. Security Operations
    3. Cortex XDR
    4. Cortex XDR™ XQL Language Reference
    PDF Cover Image
    Download PDF
    Last Updated:
    May 19, 2022

    Table of Contents


    Search the Table of Contents
    copyright
    copyright
    Get Started with XQL
    XQL Language Features
    XQL Language Structure
    Supported Operators
    Datasets and Presets
    About Examples
    Stages Commands Reference
    Alter
    Arrayexpand
    Bin
    Comp
    avg
    count
    count_distinct
    earliest
    first
    last
    latest
    list
    max
    min
    sum
    values
    Config
    case_sensitive
    timeframe
    Dedup
    Fields
    Filter
    Join
    Iploc
    Limit
    Replacenull
    Sort
    Target
    Union
    View
    XQL Functions Reference
    add
    arrayconcat
    arraycreate
    arraydistinct
    arrayfilter
    arrayindex
    arrayindexof
    array_length
    arraymap
    arraymerge
    arrayrange
    arraystring
    coalesce
    concat
    current_time
    divide
    extract_time
    format_string
    format_timestamp
    floor
    if
    incidr
    incidrlist
    json_extract
    json_extract_array
    json_extract_scalar
    len
    lowercase
    multiply
    object_create
    parse_timestamp
    pow
    regextract
    replace
    replex
    round
    split
    string_count
    subtract
    timestamp_diff
    timestamp_seconds
    to_boolean
    to_float
    to_integer
    to_json_string
    to_number
    to_string
    to_timestamp
    trim
    uppercase
    • copyright
      • copyright
    • Get Started with XQL
      • XQL Language Features
      • XQL Language Structure
      • Supported Operators
      • Datasets and Presets
      • About Examples
    • Stages Commands Reference
      • Alter
      • Arrayexpand
      • Bin
      • Comp
        • avg
        • count
        • count_distinct
        • earliest
        • first
        • last
        • latest
        • list
        • max
        • min
        • sum
        • values
      • Config
        • case_sensitive
        • timeframe
      • Dedup
      • Fields
      • Filter
      • Join
      • Iploc
      • Limit
      • Replacenull
      • Sort
      • Target
      • Union
      • View
    • XQL Functions Reference
      • add
      • arrayconcat
      • arraycreate
      • arraydistinct
      • arrayfilter
      • arrayindex
      • arrayindexof
      • array_length
      • arraymap
      • arraymerge
      • arrayrange
      • arraystring
      • coalesce
      • concat
      • current_time
      • divide
      • extract_time
      • format_string
      • format_timestamp
      • floor
      • if
      • incidr
      • incidrlist
      • json_extract
      • json_extract_array
      • json_extract_scalar
      • len
      • lowercase
      • multiply
      • object_create
      • parse_timestamp
      • pow
      • regextract
      • replace
      • replex
      • round
      • split
      • string_count
      • subtract
      • timestamp_diff
      • timestamp_seconds
      • to_boolean
      • to_float
      • to_integer
      • to_json_string
      • to_number
      • to_string
      • to_timestamp
      • trim
      • uppercase

    Cortex XDR™ XQL Language Reference


    PDF Cover Image
    Download PDF
    Last Updated:
    May 19, 2022

    Table of Contents


    Search the Table of Contents
    copyright
    copyright
    Get Started with XQL
    XQL Language Features
    XQL Language Structure
    Supported Operators
    Datasets and Presets
    About Examples
    Stages Commands Reference
    Alter
    Arrayexpand
    Bin
    Comp
    avg
    count
    count_distinct
    earliest
    first
    last
    latest
    list
    max
    min
    sum
    values
    Config
    case_sensitive
    timeframe
    Dedup
    Fields
    Filter
    Join
    Iploc
    Limit
    Replacenull
    Sort
    Target
    Union
    View
    XQL Functions Reference
    add
    arrayconcat
    arraycreate
    arraydistinct
    arrayfilter
    arrayindex
    arrayindexof
    array_length
    arraymap
    arraymerge
    arrayrange
    arraystring
    coalesce
    concat
    current_time
    divide
    extract_time
    format_string
    format_timestamp
    floor
    if
    incidr
    incidrlist
    json_extract
    json_extract_array
    json_extract_scalar
    len
    lowercase
    multiply
    object_create
    parse_timestamp
    pow
    regextract
    replace
    replex
    round
    split
    string_count
    subtract
    timestamp_diff
    timestamp_seconds
    to_boolean
    to_float
    to_integer
    to_json_string
    to_number
    to_string
    to_timestamp
    trim
    uppercase
    • copyright
      • copyright
    • Get Started with XQL
      • XQL Language Features
      • XQL Language Structure
      • Supported Operators
      • Datasets and Presets
      • About Examples
    • Stages Commands Reference
      • Alter
      • Arrayexpand
      • Bin
      • Comp
        • avg
        • count
        • count_distinct
        • earliest
        • first
        • last
        • latest
        • list
        • max
        • min
        • sum
        • values
      • Config
        • case_sensitive
        • timeframe
      • Dedup
      • Fields
      • Filter
      • Join
      • Iploc
      • Limit
      • Replacenull
      • Sort
      • Target
      • Union
      • View
    • XQL Functions Reference
      • add
      • arrayconcat
      • arraycreate
      • arraydistinct
      • arrayfilter
      • arrayindex
      • arrayindexof
      • array_length
      • arraymap
      • arraymerge
      • arrayrange
      • arraystring
      • coalesce
      • concat
      • current_time
      • divide
      • extract_time
      • format_string
      • format_timestamp
      • floor
      • if
      • incidr
      • incidrlist
      • json_extract
      • json_extract_array
      • json_extract_scalar
      • len
      • lowercase
      • multiply
      • object_create
      • parse_timestamp
      • pow
      • regextract
      • replace
      • replex
      • round
      • split
      • string_count
      • subtract
      • timestamp_diff
      • timestamp_seconds
      • to_boolean
      • to_float
      • to_integer
      • to_json_string
      • to_number
      • to_string
      • to_timestamp
      • trim
      • uppercase

    © 2022 Palo Alto Networks, Inc. All rights reserved.

    Techdocs Logo