> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/overview-of-the-query-center.md).

# Overview of the Query Center

The **Query Center** displays information about all queries that were run on the tenant, and the queries that are currently **In Progress**. The **Query Center** displays the following tabs:

* **Query History**

  View and manage all completed Cortex Query Language (XQL) and Graph Search queries. On this tab you can view query results, re-run and adjust queries, and schedule when a query runs. You can also see details of cancelled queries, including the query type and source, and the name of the user who cancelled the query.
* **Active Queries**

  View and manage all queries that are currently **In Progress** on the tenant. You can view details about a running query, including the user who ran the query, the context from which it ran, the source of the query, and the amount of time that the query has been running. From this tab you can also cancel active queries.

{% hint style="info" %}

### Note

* Very short queries might not be listed.
* You cannot cancel correlation queries.
* The default retention period for historic queries is aligned with issue retention.
  {% endhint %}

**Edit and run queries in Query Center**

From the **Query Center** you can take action on the **Completed** and **In Progress** queries that are running on your tenant.

Right-click a query to see the available options, where some of the options differ depending on the type of query you've selected. The pivot (right-click) options described below are some of the ones that may require further explanation.

{% hint style="info" %}

### Note

If query limits are applied to your tenant, the number of concurrent running queries is limited per user. If query usage is reaching the defined limit, a system message warns you that a high query load is impacting performance. If you exceed the limit, new queries are blocked until query usage drops. You can view all active queries under **Query Center** → **Active Queries**, and cancel queries to reduce the load.
{% endhint %}

<details>

<summary>View the results of a query</summary>

You can view the original results of an XQL query when it was originally run in the Query Builder and added to the Query Center.

1. Select **Investigation & Response** → **Search** → **Query Center** → **Query History**.
2. Identify the XQL query by looking in the **Query Name** and **Query Description** columns.

   The **Query Description** column displays the parameters that were defined for a query. If necessary, use the filter on the column to reduce the number of queries displayed.

   Queries that were created from a Query Builder template are prefixed with the template name.
3. Right-click anywhere in the XQL query row and select **Show results**.

   You have the option to **Show results in new tab** or **Show results in same tab**.
4. (Optional) **Export to file** to export the results to a tab-separated values (TSV) file.
5. (Optional) Perform additional investigation on the issues.

   Right-click a value in the results table to see the options for further investigation.

</details>

<details>

<summary>Run a query</summary>

You can run a query for a Graph Search query.

1. Select **Investigation & Response** → **Search** → **Query Center** → **Query History**.
2. Identify the Graph Search query by looking in the **Query Name** and **Query Description** columns.

   The **Query Description** column displays the parameters that were defined for a query. If necessary, use the filter on the column to reduce the number of queries displayed.
3. Right-click anywhere in the Graph Search query row and select **Run query**.

   You have the option to **Run in same tab** or **Show in new tab**.
4. (Optional) The Graph Search results are displayed in a graph format by default. You can toggle to **Table** to view the results in a table format. In addition, you can always export the graph results using the icon at the top of the page to a PNG, SVG, or TSV file. Table results can only be exported to a TSV file.
5. (Optional) Perform additional investigation on the graph or table results.

   On the graph results, you can either hover or select different nodes for further investigation. While in the table results, you can select any cell in the table for further investigation.

</details>

<details>

<summary>Modify a query</summary>

After you view the query results of an XQL query or run a Graph Search query as explained in the tasks above, you can change your search parameters to refine the search results or correct a search parameter.

* For queries created in XQL, type your changes in the XQL query field where the original query is listed and the results are displayed in the **Query Results** tab. After modifying the query, you can run, schedule, or save the query.
* For queries created with a Query Builder template, the defined parameters are shown at the top of the **Results** page. Select **Back to edit** to modify the query with the template format or **Continue in XQL** to open the query in XQL.
* For Graph Search queries, the graph results are displayed. Click anywhere in the Graph Search query interface, where your existing query is defined, to display the complete query, update your query, and rerun the search.

</details>

<details>

<summary>Schedule a query to run</summary>

You can schedule an XQL query to run on or before a specific date. Cortex Cloud creates a new query in the **Query Center**, and when the query completes, it displays a notification in the notification bar.

How to schedule a query

1. Select **Investigation & Response** → **Search** → **Query Center** → **Query History**.
2. Right-click anywhere in the query and then select **Schedule**.
3. Choose a schedule option and the date and time that the query should run:
   * **Run one time query on a specific date**
   * **Run query by date and time**: Schedule a recurring query.
4. Click **OK** to schedule the query.

   Cortex Cloud creates a new query and schedules it to run on or by the selected date and time.
5. View the status of the scheduled query on the **Scheduled Queries** page.

   You can also make changes to the query, edit the frequency, view when the query will next run, or disable the query. For more information, see Manage scheduled queries.

</details>

<details>

<summary>Cancel a query</summary>

{% hint style="info" %}

### Note

You can cancel your own queries. To cancel queries run by other users, you must have **View/Edit** permissions for **Configurations** → **Query Management**. By default, Instance administrators have **View/Edit** permission.
{% endhint %}

On the **Active Queries** tab you can cancel one or more **In Progress** queries. You might want to cancel long-running queries, or cancel queries to reduce tenant consumption. If query limits are applied to your tenant and you exceed the defined limit of concurrent running queries, new queries are blocked until the number of active queries falls below the threshold. Canceling active queries allows you to unblock and run new queries.

How to cancel a query

1. Select **Investigation & Response** → **Search** → **Query Center** → **Active Queries**.
2. Select one or more queries and click **Cancel Selected Queries**.

{% hint style="info" %}

### Note

* Cancelled queries show a Canceled status. You can see details of all canceled queries in the Query History tab.
* You cannot cancel correlation rule queries.
* If you cancel a scheduled query, only the current query is cancelled. Future recurrences of the scheduled query are not affected.
  {% endhint %}

</details>

**Query Center reference information**

The table below lists the common fields in the Query Center, where the options differ for an XQL query versus a Graph Search query.

{% hint style="info" %}

### Note

Certain fields are exposed and hidden by default. An asterisk (\*) is beside every field that is exposed by default.
{% endhint %}

<details>

<summary>Query Center table</summary>

| Field                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **BQL**                     | <p>Indicates whether the Cortex Query Language (XQL) query was created by the native search.</p><p>Native search has been deprecated; this field allows you to view data for XQL queries performed before deprecation.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **COMPUTE UNIT USAGE**      | For XQL queries, indicates the number of query units that were used to execute the API query and Cold Storage query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **ISSUED BY** \*            | For XQL queries, indicates the user who ran or scheduled the query. For Graph Search queries, indicates the user who ran the query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **DURATION (SEC)**          | Number of seconds it took to execute the XQL query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **EXECUTION ID**            | Unique identifier of XQL and Graph Search queries in the tenant. The identifier ID generated for queries executed in Cortex Cloud and XQL query API.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **NUM OF RESULTS**\*        | Number of results returned by the query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **PUBLIC API**              | Whether the source executing the XQL query was an XQL query API.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **QUERY DESCRIPTION**\*     | Query parameters used to run the query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **QUERY ID**                | Unique identifier of the query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **QUERY NAME**\*            | <ul><li><p>For saved queries, the <strong>Query Name</strong> identifies the query specified according to a randomly generated number.</p><ul><li>XQL queries use the format <strong>XQL-QUERY-\<number></strong>, such as <strong>XQL-QUERY-12</strong>.</li><li>Graph Search queries use the format <strong>Graph-Query-\<number></strong>, such as <strong>Graph-Query-1247</strong>.</li></ul></li><li>For scheduled queries, the <strong>Query Name</strong> identifies the auto-generated name of the parent XQL query. Scheduled queries also display an icon to the left of the name to indicate that the XQL query is recurring.</li></ul><p><img src="/files/8R7o6RZkndpQBt9kpLKe" alt="query-scheduled.png" data-size="original"></p>                                                                                                                                                                                                                                                      |
| **QUERY STATUS**\*          | <p>Status of the query, where the options differ based on the query type:</p><ul><li><p>XQL queries:</p><ul><li><strong>Queued</strong>: The query is queued and will run when there is an available slot.</li><li><strong>Running</strong></li><li><strong>Failed</strong></li><li><strong>Partially completed</strong>: The query was stopped after exceeding the maximum number of permitted results. The default results for any query is a maximum of 1,000,000 results, when no limit is explicitly stated in the query. Queries based on XQL query entities are limited to 10,000 results. To reduce the number of results returned, you can adjust the query settings and rerun.</li><li><strong>Stopped</strong>: The query was stopped by an administrator.</li><li><strong>Completed</strong></li><li><strong>Deleted</strong>: The query was pruned.</li></ul></li><li><p>Graph Search queries:</p><ul><li><strong>Failed</strong></li><li><strong>Completed</strong></li></ul></li></ul> |
| **QUERY SYNTAX**            | The exact syntax used to write the query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **RESULTS SAVED**\*         | For XQL queries, you can choose whether to save the query results, so the output of the field is either **Yes** or **No**. Yet, for Graph Search queries, the results can't be saved and must be run each time again, so the field is always **No**.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **SIMULATED COMPUTE UNITS** | Number of XQL query units that were used to execute the Hot Storage query.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Source**                  | Source from which the query was run, for example Playbook, Report, or Investigation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Source ID**               | ID of the source from where the query was run.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Source Name**             | Name of the source from where the query was run.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **TIMESTAMP**\*             | Date and time the query was created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **XQL**                     | Indicates whether the XQL query was created by an XQL search.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-posture-management/cortex-cloud-xql/build-xql-queries/overview-of-the-query-center.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
