Overview of the Query Center - View information about the In Progress and Completed queries that that were run on the tenant. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 3.x Documentation

Product
Cortex XDR
License
Prevent
Pro
Creation date
2024-03-06
Last date published
2025-12-15
Category
Administrator Guide
Abstract

View information about the In Progress and Completed queries that that were run on the tenant.

The Query Center displays information about all queries that were run on the tenant, and the queries that are currently In Progress. The Query Center displays the following tabs:

  • Query History

    View and manage all completed Cortex Query Language (XQL) and Graph Search queries. On this tab you can view query results, re-run and adjust queries, and schedule when a query runs. You can also see details of cancelled queries, including the query type and source, and the name of the user who cancelled the query.

  • Active Queries

    View and manage all queries and correlations that are currently In Progress on the tenant. You can view details about a running query, including the user who ran the query, the context from which it ran, the source of the query, and the amount of time that the query has been running. From this tab you can also cancel active queries.

Note

  • Very short queries might not be listed. 

  • The default retention period for historic queries is aligned with issue retention.