Perform advanced Identity Security investigations using XQL - Working with datasets in Cortex Cloud Identity Security. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM 3.x Documentation

Product
Cortex XSIAM
Creation date
2025-07-15
Last date published
2026-06-11
Category
Administrator Guide
Abstract

Working with datasets in Cortex Cloud Identity Security.

Notice

This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that has the Cloud Posture Security or Cloud Runtime Security add-on.

Overview

Cortex Cloud Identity Security centralizes identity-related information into a list of datasets, providing the foundation for comprehensive security investigations. Using Cortex Query Language (XQL) , security practitioners can create custom queries to extract valuable insights from these data sources within your system. For more information, see Get started with XQL.

You can use the following identity-related datasets:

Dataset

Description

ciem_permissions_with_last_access

Contains the permissions of each identity that is discovered in your environments, including the time of their last access when applicable.

asset_inventory

Contains an inventory of all the assets that are discovered in your environments. For more information, see Inventory management.Inventory management

issues

Contains the issues that are related to the assets in your environments. For more information, see Issues.Issues

findings

Contains the findings that are associated with the assets that are found in your environments. For more information, see Findings and events.

Investigate Cortex Cloud Identity Security

To run queries on your Cortex Cloud Identity Security datasets:

  1. In Cortex XSIAM, in the navigation pane on the left, click Investigation & Response, then under Search, click XQL Search.

  2. On the XQL Search screen, under XQL Query, in the text box, start typing your query. Alternatively, you can search for existing queries on the Query Library tab.

  3. When you have finished entering your query, click Run. The results appear on the Query Results tab.

Note

For more information, see Build XQL queries.Build XQL queries

Examples

Here are some examples of identity-related queries you can run in Cortex XSIAM to investigate your identity posture: