> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/query-case-and-issue-data.md).

# Query case and issue data

Cortex XDR uses Cortex Query Language (XQL) as the primary language for searching, analyzing, and transforming security data. XQL allows for highly efficient querying across vast amounts of security telemetry, such as:

* Threat hunting: Proactively search your entire environment for malicious activity, anomalies, and indicators of compromise (IOCs). Formulate queries to look for specific patterns of behavior that might indicate an ongoing attack, even if no alert has been triggered.
* Investigation: When a case or issue is generated, XQL allows security analysts to drill down into the underlying data, understand the full scope of an attack, identify affected assets, and trace the attacker's actions.
* Forensics: Extract detailed information about past events for post-incident analysis and compliance audits.
* Reports and dashboards: Create custom reports and dashboards to visualize security posture, track key metrics, and communicate insights to stakeholders.

To view and use sample investigative queries, such as the **Top Unresolved High Severity Cases** query, go to **Investigation & Response** → **Search** → **Query Builder** → **XQL** → **Query Library**. For more information about using XQL, see [Cortex XDR XQL](/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-xql.md).

You can query case and issue data in the `cases` and `issues` datasets. When using the `issues` dataset, keep in mind the following:

* Informational issues are not included in this dataset.
* Issue fields are limited to certain fields available in the API. For the full list, see [Cortex XDR API Reference](/cortex-xdr-5.x/reference-and-developer-docs/cortex-xdr-api-reference.md).

The `issues` dataset is categorized by domain. To query only security issues, use the following XQL:

```programlisting
dataset = issues | filter issue_domain = "SECURITY"
```

To query only posture issues, use the following XQL:

```programlisting
dataset = issues | filter issue_domain = "POSTURE"
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/investigate-and-respond-to-cases/investigate-issues/issue-investigation-actions/query-case-and-issue-data.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
