> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate queries using natural language

> Learn how to generate and refine queries from natural language prompts.

Palo Alto Networks Cortex XCOR provides
[generative artificial intelligence](/overview/generative-ai) (AI) tools to generate
[PromQL](/investigate/querying/promql) or [logs](/investigate/querying/query-logs)
queries from natural language prompts. You can generate queries when querying data
in an explorer, when editing a [dashboard panel](/observe/dashboards/panels) query,
or when defining the query for a [monitor](/investigate/alerts/monitors) or
[service level objective](/observe/slo) (SLO).

Prompt AI with natural language that reflects what you want Cortex XCOR
to query, and Cortex XCOR generates queries that return relevant data
based on those prompts. You can converse with AI to provide more context, refine
the generated query, and ask questions that could be answered by new queries.

Cortex XCOR uses [semantic search](#semantic-metric-search) to identify
the most relevant metrics for your prompt, so you don't need to know exact metric
names to generate accurate queries.

Query generation produces a single query in the field you're editing. To ask
questions about your telemetry, run queries across data types, or edit the
resource you're viewing, use [Operator](/navigate/operator) instead.

<Warning>
  Generative AI features can produce incorrect results, hallucinate data, and deliver
  inaccurate analysis. Use generative AI features with care, and independently verify
  all information produced by generative AI tools before applying it.

  Certain prompts, data, or other inputs might produce irrelevant content. Don't rely on
  generative AI features or responses for any uses that exceed their designed scope.
</Warning>

## Generate queries from natural language prompts

You can generate queries from natural language in
[Metrics Explorer](/investigate/querying/metrics/explorer),
[Logs Explorer](/investigate/querying/query-logs), and when defining the query for
a [monitor](/investigate/alerts/monitors#create-a-monitor) or [SLO](/observe/slo).
Fields that support natural language queries include an **Edit with AI** button.

1. Open [Metrics Explorer](/investigate/querying/metrics/explorer) to query metrics,
   open [Logs Explorer](/investigate/querying/query-logs) to query logs, or open the
   **Query** section of a monitor or SLO indicator to generate queries for alerting.
2. In the query field, click **Edit with AI** to open the natural language prompt
   field. You can also click or focus on the query field and use the keyboard shortcut
   <kbd>Control+I</kbd> (<kbd>Command+I</kbd> on macOS) to open the prompt field.
3. In the **Describe your query** prompt field that appears, write your query as
   a [natural language prompt](#write-effective-natural-language-prompts).
4. Click **<Icon icon="circle-fading-arrow-up" /> Generate** or press <kbd>Enter</kbd>
   (<kbd>Return</kbd> on macOS) to submit your prompt.
5. Optional: To cancel a prompt being processed, click **<Icon icon="circle-stop" /> Stop**.

<Note>
  Prompts must be related to monitoring or relevant observability data, and must
  also be specific about the services, metrics, or logs being queried. If you submit
  a prompt that doesn't appear to be related to monitoring or lacks specificity,
  Cortex XCOR notifies you or requests more information.
</Note>

Cortex XCOR populates the query field with its generated query and presents
actions that you can take with the generated query.

* To immediately run the generated query, click **Accept and run** or press <kbd>Control+Enter</kbd>
  (<kbd>Cmd+Return</kbd> on macOS).
* To accept the generated query without running it, click **Accept** or press <kbd>Tab</kbd>.
* To revert the query field to its previous state, click **Reject** or press <kbd>Esc</kbd>.

You can also manually edit the generated query and
[refine it with additional prompts](#refine-your-query-with-additional-prompts).

## Generate a PromQL query for a dashboard panel

When editing a [dashboard panel](/observe/dashboards/panels), you can generate a PromQL
query from a natural language prompt. Dashboard panel query generation uses the same
**Edit with AI** workflow, [refinement](#refine-your-query-with-additional-prompts), and
[semantic metric search](#semantic-metric-search) as Metrics Explorer, and is aware
of any [dashboard variables](/observe/dashboards/customization/dashboard-variables)
configured on the dashboard.

To generate a PromQL query in a dashboard panel:

1. Open the dashboard and click **Edit**.
2. Click **Edit** on the panel you want to update.
3. In the **Edit panel** interface, select the **Query** tab.
4. Set **Datasource** to **Metrics (Prometheus)**.
5. In the query field, click **Edit with AI**, or press <kbd>Command+I</kbd> (macOS)
   or <kbd>Control+I</kbd> (Windows/Linux), to open the prompt field.
6. In the **Describe a query that you're interested in** prompt field, write your
   query as a [natural language prompt](#write-effective-natural-language-prompts).
7. Click **<Icon icon="sparkles" alt="AI generation icon" /> Generate** or press
   <kbd>Enter</kbd> (<kbd>Return</kbd> on macOS) to
   submit your prompt. Cortex XCOR searches for relevant metrics and
   generates a PromQL query.
8. Review the generated query, then take one of the following actions:
   * To immediately run the query, click **Accept and run** or press
     <kbd>Control+Enter</kbd> (<kbd>Command+Return</kbd> on macOS).
   * To accept the query without running it, click **Accept** or press <kbd>Tab</kbd>.
   * To discard the generated query and restore the previous query, click **Reject**
     or press <kbd>Esc</kbd>.

You can also [refine the generated query](#refine-your-query-with-additional-prompts)
with additional prompts before accepting it.

## Refine your query with additional prompts

When you enter a prompt while editing with AI, Cortex XCOR generates
a query based on it. If you've generated a query, manually entered a query, or
opened a query in an explorer from elsewhere in Cortex XCOR, you can
also refine that query using AI.

To provide additional prompts, click the natural language prompt field, now named
**Refine your query**, and enter a new prompt.

Cortex XCOR adjusts the query with this new context and presents it
as a diff. The original prompt is listed first with a red indicator, followed by
the new suggestion with a green indicator.

After each iterative prompt, Cortex XCOR either presents the same **Accept and run**,
**Accept**, and **Reject** options, or notifies you of issues with your prompt.

## Generate queries for SLO indicators

You can generate PromQL queries from natural language when you define the indicator
for an [SLO](/observe/slo). SLO query generation uses the same **Edit with AI** workflow,
[refinement](#refine-your-query-with-additional-prompts), and
[semantic metric search](#semantic-metric-search) as Metrics Explorer.

For more information, see [Service level objectives](/observe/slo).

## Generate queries for monitors

You can generate queries from natural language when you define the query for a
[monitor](/investigate/alerts/monitors). Monitor query generation uses the same
**Edit with AI** workflow, [refinement](#refine-your-query-with-additional-prompts),
and [semantic metric search](#semantic-metric-search) as the explorers, and produces
queries that are valid for alerting.

Query generation is available for monitors that use **Prometheus** (PromQL) and
**Logs** data sources.

For more information, see [Monitors](/investigate/alerts/monitors).

## Semantic metric search

When you generate a PromQL query from a natural language prompt, Cortex XCOR uses
semantic search to find the metrics most relevant to your prompt.
Semantic search matches the intent of your prompt against metric names and
descriptions, rather than relying on exact keyword matches.

For example, if you submit a prompt with "show me CPU usage across my cluster," semantic
search identifies metrics like `container_cpu_usage_seconds_total` or
`node_cpu_utilization` even though your prompt doesn't mention those metric names
directly. This means you can describe what you want to observe in plain language,
and Cortex XCOR selects the appropriate metrics to query.

Semantic search runs automatically as part of the natural language query generation
workflow. You don't need to configure or enable it separately.

## Write effective natural language prompts

You might not have enough information to write effective prompts when you begin
using AI to generate a query. However, you can iterate by repeatedly
[refining your query](#refine-your-query-with-additional-prompts) with a goal of
providing enough context to generate a query tailored to your issue.

The guidance in this section covers query generation. For guidance that applies to
every generative AI feature in Cortex XCOR, see
[Write effective prompts](/overview/generative-ai#write-effective-prompts).

To write effective prompts for queries:

* Write the goal of the query you want to generate as a specific and concise statement.
* Provide relevant context that you already have, such as metric or label names.
  [Semantic search](#semantic-metric-search) can find relevant metrics even without
  exact names, but include them when you know them improves results.
* State the form of data you want, such as a count, rate, or histogram.
* Avoid overly terse, vague, ambiguous, or irrelevant prompts.

For example, an overly terse prompt is unlikely to provide enough context to generate
a sufficiently precise query, and might not provide enough information to generate
any query:

> downtime

A vague and imprecise prompt with unnecessary information is less likely to generate
an actionable query:

> Tell me why I'm getting so many downtime alerts this week.

While this might produce a query, you can iterate on the result to focus on more
specific issues.

A more concise and precise prompt helps the large language model generate a more
focused query:

> Which shopping cart service alerts were triggered in the last 7 days, and why?

Providing more information or refining your criteria can further focus the result:

> Show success rates versus failures for requests to the shopping cart service in
> the last 7 days.

Once you begin generating relevant queries, you can engage more conversationally
with the AI as you continue iterating. The editor retains past context as you continue
prompting to refine your query.

### Troubleshoot generated queries

Confirm that the [time range selector](/navigate/time-ranges) is set to a relevant
span of time for your prompt.

To investigate the query and identify any errors or unexpected results, click
**Debug**. You can copy and paste any reported errors as prompts that
[refine the query](#refine-your-query-with-additional-prompts).

Remember that the resulting query represents the large language model's hypothesis,
and isn't a definitive answer to your question. For example, it might not select
the most relevant telemetry data for your request. Critically review the generated
query and manually edit when necessary. Cortex XCOR incorporates your
edits in subsequent prompts to guide further refinements or changes to the generated
query.

## Close the natural language query field

To close the natural language query field, click **X** or press <kbd>Control+I</kbd>
(<kbd>Command+I</kbd> on macOS).


## Related topics

- [Metrics Explorer](/investigate/querying/metrics/explorer.md)
- [Search and filter log data](/investigate/querying/query-logs.md)
- [Understanding generative AI features](/overview/generative-ai.md)
- [Respond to incidents](/overview/guides/incident-response.md)
- [Use monitors to generate alerts and notifications](/investigate/alerts/monitors.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.