Skip to main content
After ingesting your telemetry data into Palo Alto Networks Cortex XCOR, you can query that data to surface information when you need it. This capability is especially useful during incident response when you’re trying to identify the source of an issue. How you query telemetry data in Cortex XCOR depends on the data type. Use these resources to learn how to query your data: To visualize the results of queries, add queries to dashboards from supported Explorers. You can also create links between telemetry types, such as linking to trace or log data from dashboards. Learn about using regular expressions and glob syntax in queries, including where they’re supported and how they differ. If you’re querying metric data, learn about Using PromQL in Cortex XCOR, including the most relevant features and syntax. To query your data without writing the query yourself, use query generation to produce a query from a description, or ask Operator a question and let it run the queries it needs across metrics, logs, traces, and change events.