Abstract
Learn more about some important information before getting started with XQL queries.
Before you begin running XQL queries, consider the following information:
Use the interface to help you build queries
Cortex Cloud offers features in the XQL search interface to help you build queries. For more information, see Useful XQL user interface features.
Understand query defaults and limitations
Before you run a query, review this list to better understand query behavior and results. For more information, see Expected results when querying fields.
Translate Splunk queries to XQL
If you have existing Splunk queries, you can translate them to XQL. For more information, see Translate to XQL.