What is the difference between presets and datasets in XQL?
The difference between presets and datasets in XQL is that a dataset is a built-in or third-party data source, while a preset is a group of XDR data fields. A dataset is a collection of data that you can query and analyze using XQL. A dataset can be a Cortex data lake data source, such as endpoints, alerts, incidents, or network flows, or a third-party data source, such as AWS CloudTrail, Azure Activity Logs, or Google Cloud Audit Logs. A preset is a predefined set of XDR data fields that are relevant for a specific use case, such as process execution, file operations, or network activity. A preset can help you simplify and standardize your XQL queries by selecting the most important fields for your analysis. You can use presets with any Cortex data lake data source, but not with third-party data sources.Reference:
Eloisa
8 months agoUna
8 months agoAzzie
8 months agoAdaline
8 months agoUna
8 months agoErinn
8 months agoDona
8 months agoElke
8 months agoErinn
9 months agoDona
9 months agoErinn
10 months agoDino
10 months agoNelida
10 months agoSharee
10 months agoGeoffrey
10 months agoElvera
10 months agoShawnta
10 months agoCristal
10 months agoVesta
10 months agoMartina
10 months agoBernardine
10 months agoAliza
10 months ago