Cortex XDR 3.x
Query Center reference information
Descriptions of the fields in the Query Center table.
Last updated
Was this helpful?
Descriptions of the fields in the Query Center table.
Building Cortex Query Language (XQL) queries in the Query Builder requires a Cortex XDR Pro license.
The table below lists the common fields in the Query Center.
Certain fields are exposed and hidden by default. An asterisk (*) is beside every field that is exposed by default.
BQL
Whether the query was created by the native search.
Native search has been deprecated; this field allows you to view data for queries performed before deprecation.
COMPUTE UNIT USAGE
Number of query units that were used to execute the API query and Cold Storage query.
ISSUED BY *
User who ran or scheduled the query.
DURATION (SEC)
Number of seconds it took to execute the query.
EXECUTION ID
Unique identifier of Cortex Query Language (XQL) queries in the tenant. The identifier ID generated for queries executed in Cortex XDR and XQL query API.
NUM OF RESULTS*
Number of results returned by the query.
PUBLIC API
Whether the source executing the query was an XQL query API.
QUERY DESCRIPTION*
Query parameters used to run the query.
QUERY ID
Unique identifier of the query.
QUERY NAME*
For saved queries, the Query Name identifies the query specified by the administrator.
For scheduled queries, the Query Name identifies the auto-generated name of the parent query. Scheduled queries also display an icon to the left of the name to indicate that the query is recurring.

QUERY STATUS*
Status of the query:
Queued: The query is queued and will run when there is an available slot.
Running
Failed
Partially completed: The query was stopped after exceeding the maximum number of permitted results. The default results for any query is a maximum of 1,000,000 results, when no limit is explicitly stated in the query. Queries based on XQL query entities are limited to 10,000 results. To reduce the number of results returned, you can adjust the query settings and rerun.
Stopped: The query was stopped by an administrator.
Completed
Deleted: The query was pruned.
QUERY SYNTAX
The exact syntax used to write the query.
RESULTS SAVED*
Yes or No.
SIMULATED COMPUTE UNITS
Number of XQL query units that were used to execute the Hot Storage query.
TENANT
List of tenants on which an XQL query were executed.
TIMESTAMP*
Date and time the query was created.
XQL
Whether the query was created by an XQL search.
Last updated
Was this helpful?
Was this helpful?
