Query using Federated Search - Query distributed data sources using external datasets and join with ingested data. - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Documentation

Product
Cortex XSIAM
Creation date
2024-03-06
Last date published
2025-12-29
Category
Administrator Guide
Abstract

Query distributed data sources using external datasets and join with ingested data.

To query using Federated search, navigate to Incident ResponseInvestigationQuery Builder and select XQL.

You can build queries across external datasets and ingested datasets, giving you a powerful tool.

In its current version, Federated Search enables only ad-hoc queries via the query builder. You can search, filter and use JOIN operations.

Note

The following aren't available in Federated Search and remain exclusive to fully ingested data.

  • Complex, cross-source analytical functions, for example correlations, widgets, dashboards, and APIs

  • search, target and view XQL stages