> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/understand-graph-search-query-results.md).

# Understand Graph Search query results

{% hint style="warning" %}

### Prerequisite

Graph Search requires **View** or **View/Edit** RBAC permissions for **Graph Search** under **Investigation & Response** → **Search**.
{% endhint %}

Review the following topics:

* [How to build Graph Search queries?](/cortex-xdr-5.x/reference-and-developer-docs/graph-search/how-to-build-graph-search-queries.md)

Once the query is completed, you can search for your query results. The results displayed are dependent on your data.

You can view the Graph Search query results in two formats:

* **Graph** (default): Displays the paths on the graph that matched the node types and conditional attributes in the query. Each result is a full path of the matching query.
* **Table**: Displays the results in a table, where each row in the table represents a different path in the graph that goes through all the matching node types and attributes as they appear in the Graph Search query. Every asset and finding table shows different default columns. For more information, see [Table view columns](#UUID-071ed571-f10d-2f94-6df0-95eb5e0661c8_sidebar-idm234783840000212). You can view the full asset information of any cell in the table by clicking the cell.

You can export the Graph Search results as a PNG, SVG, or TSV file. You can always edit the query once the results are displayed, which means that the old results are discarded and the new results are displayed. In addition, you can save the results to the Query Library.

<details>

<summary>Graph output</summary>

The Graph Search resulting graph displays the paths according to the nodes and conditional attributes that you selected in your query. Here are a few things to keep in mind when viewing the graph results:

* There are two different types of nodes, where each node has its own unique shape, icon, and color:
  * **Asset nodes**: Each asset node is depicted as a circle in the resulting graph, where the color and icon displayed is dependent on the asset category and class types selected. There are multiple class types available for each asset node category selected. Once a class type is selected in the node picker dialog box and you hover over it, all the available asset types are listed according to the data collected. For more information, see [All assets](/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/all-assets.md).
  * **Finding nodes**: Each finding node is depicted as a diamond in the resulting graph, where the color and icon displayed is dependent on the finding type selected. There is only one category type available for each finding selected.
* In the resulting query, nodes are automatically grouped together to keep the graph looking cleaner and less busy. Nodes are grouped together when there are at least five nodes that meet the following conditions:

  * The node isn't a root node.
  * The path is identical.
  * For asset nodes, the nodes have the same class and category type.
  * For finding nodes, the nodes have the same category type.

  A grouped node icon is displayed as a duplicate node. For example, if it's a group node, the icon looks like two shapes, one on top of another. When you select the group node, a dialog box opens displaying all the nodes included in the group.
* When you select each node, or hover on it and select **More Info**, you'll see more information displayed in a dialog box. You can click **View Details** to drill down even further on the node to display more information on the node depending on the data collected for that asset or finding node selected.
* Vulnerability finding nodes automatically display under the node the breakdown of severity.
* Every Graph Search query returns a maximum of 50 paths with an indication displayed at the bottom of the page of the total number of results.
* On the right side of the graph results, there are different icons that can help you drilldown into your graph results:
  * **+** and **-** icons: Use the plus and minus icons to zoom in and out of the graph.
  * ![centering\_icon.png](/files/Bcns6dwdDktPVRv8ZImR): Use the diamond icon to center your graph after you've manipulated the output.
  * ![layers\_icon.png](/files/8D4gO1k5ibXLtEnHNF2j): Use the layers icon to easily add or remove additional information to the graph without having to define these parameters in your Graph Search query. You can decide when to include these built-in layers, as needed. The following are available:

    * **Public Exposure to the Internet**: Tracks the asset nodes with internet exposure that could be targeted for external surface attacks by displaying the exposure path. A Globe node called **Internet** is added to the graph, which links all exposed asset nodes to this Globe node. You can expand this connection by clicking the **+** icon to reveal the full internet path to include, for example, the NIC, Subnet, and Gateway. In the exposure path, you can select each node, or hover on it and select **More Info**, you'll see more information displayed in a dialog box. You can click **View Details** to drill down even further on the asset node to display more information on the node depending on the data collected for that asset node selected. Internet paths are collapsed by default.
    * **Related Cases**: Displays the number of related Cases for each asset node with a breakdown by severity.
    * **Runtime Events**: Adds 100 most recent runtime events to the graph results, which are refreshed every hour. This enables you to investigate real-time activity and identify critical events, such as access to sensitive information typically contained in a storage bucket, which generate issues and cases. All the bucket nodes in the path include a runtime icon ![runtime\_icon.png](/files/Knk1H0fAg0k7fzzIpxsx) underneath and run an animation on all the bucket and virtual machine nodes. You can click the runtime icon to reveal more info, such as connection details and runtime events. Click **Show Recent Events** to display the **Runtime Events** table with more details on the last 100 events.

    The results from the different layers are displayed in tabs in the node dialog box, which enables you to quickly switch from one layer to the other.
  * ![Group\_nodes\_icon.png](/files/I94vkQS7yX3dgGiOKEpF): Use the Group nodes icon to group by the Cloud Provider, Cloud Account, or Cloud Region. Selecting one of these grouping enables you to view the graph results in an aggregated format, providing a clearer and more organized perspective of the data. This feature also helps to Identify patterns and trends more easily in your data by grouping similar entities together. In the future, the Group nodes feature will be expanded to enable additional groupings.

</details>

<details>

<summary>Show me an example of Graph Search results with general tips and tricks</summary>

![Understand\_Graph\_Search\_results\_with\_general\_tips\_and\_tricks\_July\_doc.gif](/files/XIJDn3s2dwZDtai3KDi4)

</details>

<details>

<summary>Show me how to use the layers and group node icons in the Graph Search results</summary>

This example focuses on using the layers icon to add or remove additional information to the graph and how to group information together using the Group node icon.

![Understand\_Graph\_Search\_query\_results\_July\_Layers\_and\_Group\_Nodes.gif](/files/a8afWAptpPVVjNSPd9ba)

</details>

<details>

<summary>Table view columns</summary>

Below is a list of the different columns displayed by default in the assets and findings tables.

[Asset table](#UUID-071ed571-f10d-2f94-6df0-95eb5e0661c8_sidebar-idm234783856099861_body)

Below is a list of the default columns that are displayed within any asset table, where the names of the columns can change slightly depending on the asset selected. In addition, some assets have additional columns.

* All assets tables:
  * Asset Name
  * Asset Type
  * Asset Category
  * Asset Provider
  * Asset Realm
* All assets additional columns:
  * \<name of asset> ID
* Identity finding additional columns:
  * Identity Account Access
  * Identity Admin Permissions
  * Identity Cloud Region
  * Identity Empty
  * Identity Excessive
  * Identity Guest
  * Identity Has MFA
  * Identity Last Login
  * Identity Last Used

[Finding table](#UUID-071ed571-f10d-2f94-6df0-95eb5e0661c8_sidebar-idm234783857616426_body)

Below is a list of the default columns that are displayed with in any finding table, where the names of the columns can change slightly depending on the finding selected. In addition, some findings have additional columns.

* All findings tables:
  * Finding Name
  * Finding Category
* Vulnerability finding additional columns:
  * Vulnerability Finding Package ID
  * Vulnerability Finding CVE ID
  * Vulnerability Finding Severity
  * Vulnerability Finding Fix Versions
  * Vulnerability EPSS Score
  * Vulnerability Package ID
  * Vulnerability Exploitable
  * Vulnerability Affected Versions
  * Vulnerability Status
  * Vulnerability CVE Vendor Link
  * Vulnerability Fix Date
  * Vulnerability Publish Date
  * Vulnerability Derived from Base Image
  * Vulnerability CVSS Score
  * Vulnerability CVSS Vector
  * Vulnerability Has a Fix
  * Vulnerability Fix Versions
  * Vulnerability Severity
  * Vulnerability CVE ID
* Malware finding additional columns:
  * Malware Finding File Path
  * Malware Finding SHA256
  * File Permissions
  * File Name
  * File Size
  * File Path
  * File Last Modified Time
  * Verdict
  * SHA256
* Data finding additional columns:
  * Data Finding Secret Location
  * Data Finding Secret Snippet
  * Secret Snippet
  * Secret Location
  * File Path
  * File Code Line

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/reference-and-developer-docs/graph-search/understand-graph-search-query-results.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
