Palo_Alto_Networks
PCSAE · Question #122
An XSOAR engineer has been tasked with exporting all indicators from the production environment in the last 90 days. The final report needs to be in CSV format containing all indicator fields. How…
The correct answer is C. In the Threat Intel page, add query firstSeen:>="90 days ago", select All columns in Table View. https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.12/Cortex-XSOAR-Administrator- Guide/Export-Indicators
Operations and Monitoring
Question
An XSOAR engineer has been tasked with exporting all indicators from the production environment in the last 90 days. The final report needs to be in CSV format containing all indicator fields. How can this task be achieved?
Options
- ARun the command !GetIndicatorsByQuery in CLI with its default arguments and export all
- BSSH into the server and copy the indicator's database.
- CIn the Threat Intel page, add query firstSeen:>="90 days ago", select All columns in Table View,
- DRun the command !findIndicators in CLI with the query firstSeen:>="90 days ago" and export to
How the community answered
(41 responses)- A2% (1)
- B7% (3)
- C73% (30)
- D17% (7)
Explanation
https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.12/Cortex-XSOAR-Administrator- Guide/Export-Indicators
Topics
#indicator export#Threat Intel#CSV export#indicator query
Community Discussion
No community discussion yet for this question.