Manage your personal query library
Cortex Cloud provides as part of the Query Library a personal library for saving and managing your own queries.
Cortex Cloud provides a Query Library for saving and managing your custom Cortex Query Language (XQL) queries. When creating a query in XQL or managing your queries from the Query Center, you can save them in the Query Library.
The Query Library contains a powerful search mechanism that enables you to search in any field related to the query, such as the query name, description, creator, query text, and labels. In addition, adding a label to your query enables you to search for these queries using these labels in the Query Library.
How to add a query to your personal query library
Save a query to your personal query library.
You can do this in two ways:
From the Query Builder
Select Investigation & Response → Search → Query Builder → XQL.
In the XQL query field, define the parameters of your query.
Select Save as → Query to Library.
From the Query Center
Select Investigation & Response → Search → Query Center.
Locate the query that you want to save to your personal query library.
Right-click anywhere in the query row, and select Save query to library.
Set these parameters.
Query Name: Specify a unique name for the query. Query names must be unique in both private and shared lists, which includes other people’s queries.
Query Description (Optional): Specify a descriptive name for your query.
Labels (Optional): Specify a label that is associated with your query. You can select a label from the list of predefined labels or add your label and then select Create Label. Adding a label to your query enables you to search for queries using this label in the Query Library.
Click Save.
The query is now listed in the Query Library as a Restricted query (visible only to you). To make the query available to other users, user groups, or API keys, you must configure its sharing settings.
Managing your queries
The visibility of saved queries in the Query Library is determined by access management. You can manage who can view (and run) or edit your queries by sharing them with specific users, user groups, or API keys. You can also view queries created and shared by others in your organization if they have granted you access or marked the query as Public.
The following icons in the Query Library table help you identify the sharing status of each query:
Use the following tools and the vertical ellipsis (⋮) menu to manage your saved queries:
Search and filter: Use the search field to find queries by metadata or content. Use the Show menu to filter by Owned by Me, Owned by Others, or Palo Alto Networks.
Save as new: Duplicate a query using the vertical ellipsis (⋮) menu.
Share/Manage Access: Once a query is saved to the library, the Owner (or an authorized Editor) can manage who else can interact with it using the vertical ellipsis (⋮) menu. The specific option available (Share or Manage Access) is determined by tenant-level settings.
Change owner: Administrators can use the vertical ellipsis (⋮) menu to change the query owner to a different user.
Delete: You can only delete queries that you Own. Palo Alto Networks system queries cannot be deleted.
Manage access to saved queries
Once a query is saved to the library, the Owner (or an authorized Editor) can manage who else can interact with it. The options available depend on the tenant-level settings configured by your administrator.
In the Query Library tab, locate the query you want to share in the table.
Click the three dot, vertical ellipsis (⋮) and select the available action:
Share: This option appears when Owners can Share objects they created is enabled in tenant-level settings. It allows you to manage both General access and specific principals (users, user groups, and API keys).
Manage Access: This option appears when Owners can Share objects they created is disabled in tenant-level settings. It only allows you to change the General access state.
(If sharing is enabled) To share with specific entities:
Search for the User, User Group, or API Key.
Assign the access level: Viewer (can run/view) or Editor (can modify and, if permitted by tenant-level settings, share).
Set the General access drop-down menu (if authorized by tenant-level settings):
Restricted: The query is private. It is only visible to the Owner and the specific principals added to the list.
Public: The query is visible to every user who has the Query Library enabled in their role.
Click Save.
Last updated
Was this helpful?
