Supported operators
Cortex Query Language supports specific comparison, boolean, and set operators in Cortex Cloud.
Cortex Query Language (XQL) queries support the following comparison, boolean, string, range, and add operators.
Operator
Description
Comparison operators
=, !=
Equal, Not equal
<, <=
Less than, Less than or equal to
>, >=
Greater than, Greater than or equal to
Boolean operators
and
Boolean and
or
Boolean or
not
Boolean not
String and range operators
IN, NOT IN
Returns true if the integer or string field value is one of the options specified. For example:
action_local_port in(5900,5999)
For string field values, wildcards are supported. In this example a wildcard (*) is used to search if the value contains the strings "word_1" or "word_2" anywhere in the output, or exactly matches the string "word":
str_field in ("*word_1*", "*word_2*", "word")
CONTAINS, NOT CONTAINS
Performs a search for an integer or string. Returns true if the specified string is contained in the field. Contains and Not Contains are also supported within arrays for integers and strings.
Example:
lowercase(actor_process_image_name) contains "psexec"~=
Matches a regular expression.
Example:
action_process_image_name ~= ".*?[.](?:pdf|docx)[.]exe"INCIDR, NOT INCIDR
Performs a search for an IPv4 address or IPv4 range using CIDR notation, and returns true if the address is in range.
Example:
action_remote_ip incidr "192.1.1.1/24"Multiple CIDRs use comma-separated syntax. The logical OR applies between ranges.
Example:
action_remote_ip incidr "192.168.0.0/24, 1.168.0.0/24"IPv4 addresses and ranges can be quoted strings or string fields.
INCIDR6, NOT INCIDR6
Performs a search for an IPv6 address or IPv6 range using CIDR notation, and returns true if the address is in range.
Example:
action_remote_ip incidr6 "3031:3233:3435:3637:0000:0000:0000:0000/64"Multiple CIDRs use comma-separated syntax. The logical OR applies between ranges.
Example:
action_remote_ip incidr6 "2001:0db8:85a3:0000:0000:8a2e:0000:0000/64, fe80::/10"IPv6 addresses and ranges can be quoted strings or string fields.
Add operator for tagging
add
The add operator adds one or more tags to a field.
Example:
Adding a single tag
dataset = xdr_data | tag add "test"Adding a list of tags
dataset = xdr_data | tag add "test1", "test2", "test3"
Last updated
Was this helpful?
