The Legacy Query Builder - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Cortex XSIAM
Creation date
Last date published
Administrator Guide

Explains the entities in the Legacy Query Builder.


We recommend using the Query Builder in New mode to take advantage of the Query Builder templates and ability to search the full XDM Data Model.

In Legacy mode, the Query Builder searches predefined datasets only. To search the full XDM, switch to New mode or select XQL Search.

The Legacy Query Builder provides queries for the following types of entities:

  • Process—Search on process execution and injection by process name, hash, path, command line arguments, and more. See Create a Process Query.

  • File—Search on file creation and modification activity by file name and path. See Create a File Query.

  • Network—Search network activity by IP address, port, host name, protocol, and more. See Create a Network Query.

  • Registry—Search on registry creation and modification activity by key, key value, path, and data. See Create a Registry Query.

  • Event Log—Search Windows event logs and Linux system authentication logs by username, log event ID (Windows only), log level, and message. See Create an Event Log Query.

  • Network Connections—Search security event logs by firewall logs, endpoint raw data over your network. See Create a Network Connections Query.

  • All Actions—Search across all network, registry, file, and process activity by endpoint or process. See Query Across All Entities.

The Query Builder also provides flexibility for both on-demand query generation and scheduled queries.