Working with datasets in Cortex Cloud Identity Security.
Notice
This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM license that has the Cloud Posture Security or Cloud Runtime Security add-on.
Overview
Cortex Cloud Identity Security centralizes identity-related information into a list of datasets, providing the foundation for comprehensive security investigations. Using Cortex Query Language (XQL) , security practitioners can create custom queries to extract valuable insights from these data sources within your system. For more information, see Get started with XQL.
You can use the following identity-related datasets:
Dataset | Description |
|---|---|
ciem_permissions_with_last_access | Contains the permissions of each identity that is discovered in your environments, including the time of their last access when applicable. |
asset_inventory | Contains an inventory of all the assets that are discovered in your environments. For more information, see Inventory management. |
issues | Contains the issues that are related to the assets in your environments. For more information, see Issues. |
findings | Contains the findings that are associated with the assets that are found in your environments. For more information, see Findings and events. |
Investigate Cortex Cloud Identity Security
To run queries on your Cortex Cloud Identity Security datasets:
In Cortex XSIAM, in the navigation pane on the left, click Investigation & Response, then under Search, click XQL Search.
On the XQL Search screen, under XQL Query, in the text box, start typing your query. Alternatively, you can search for existing queries on the Query Library tab.
When you have finished entering your query, click Run. The results appear on the Query Results tab.
Note
For more information, see Build XQL queries.
Examples
Here are some examples of identity-related queries you can run in Cortex XSIAM to investigate your identity posture: