Descriptions of the fields in the Query Center table.
The table below lists the common fields in the Query Center, where the options differ for an XQL query versus a Graph Search query.
Note
Certain fields are exposed and hidden by default. An asterisk (*) is beside every field that is exposed by default.
Field | Description |
|---|---|
BQL | Indicates whether the Cortex Query Language (XQL) query was created by the native search. Native search has been deprecated; this field allows you to view data for XQL queries performed before deprecation. |
COMPUTE UNIT USAGE | For XQL queries, indicates the number of query units that were used to execute the API query and Cold Storage query. |
ISSUED BY * | For XQL queries, indicates the user who ran or scheduled the query. For Graph Search queries, indicates the user who ran the query. |
DURATION (SEC) | Number of seconds it took to execute the XQL query. |
EXECUTION ID | Unique identifier of XQL and Graph Search queries in the tenant. The identifier ID generated for queries executed in Cortex XDR and XQL query API. |
NUM OF RESULTS* | Number of results returned by the query. |
PUBLIC API | Whether the source executing the XQL query was an XQL query API. |
QUERY DESCRIPTION* | Query parameters used to run the query. |
QUERY ID | Unique identifier of the query. |
QUERY NAME* |
|
QUERY STATUS* | Status of the query, where the options differ based on the query type:
|
QUERY SYNTAX | The exact syntax used to write the query. |
RESULTS SAVED* | For XQL queries, you can choose whether to save the query results, so the output of the field is either Yes or No. Yet, for Graph Search queries, the results can't be saved and must be run each time again, so the field is always No. |
SIMULATED COMPUTE UNITS | Number of XQL query units that were used to execute the Hot Storage query. |
Source | Source from which the query was run, for example Playbook, Report, or Investigation. |
Source ID | ID of the source from where the query was run. |
Source Name | Name of the source from where the query was run. |
TIMESTAMP* | Date and time the query was created. |
XQL | Indicates whether the XQL query was created by an XQL search. |