• Show the % free disk space - DATA LAKE

    • Under Review
    • 1 Comment
    Please i need the query for Show the % free disk space on DATA LAKE. Its possible???? Thanks
    • 17 Sep 2021 12:24 PM
  • querie with file movements, on computers, to external storage

    • Under Review
    • 0 Comments
    It's possible ? be able to see the movements of all files on all computers to external storage.
    • 2 Sep 2021 11:43 AM
  • Application Inventory Query

    • Under Review
    • 0 Comments
    I thought I had already published this one and if I can't find it I suspect others have that same challenge. This was from one of the videos to show how the data lake can go broad and the devices dive deep. -- Application Inventory across all devices...
    • 20 Apr 2021 2:11 PM
  • ASCII FILE Reader, HEX Dump, STRINGS Search for Binary and MORE

    • Under Review
    • 0 Comments
    With XDR we are adding a pair of new Sophos extensions GREP and HEX_TO_INT both of these come in handy when you want to read a file and show the contents as the result of a query. ASCII DUMP -- Perform an ASCII DUMP for a file -- VARIABLE...
    • 5 Apr 2021 8:24 PM
  • Queries from the March SophSkills presentation

    • Approved
    • 1 Comment
    Video: https://vimeo.com/519661823 Queries used: Queries used during SophSkills Demo DATA LAKE - List all EP and FW tables in the data lake This query will need to run against the data lake. As we add more sensors to the data lake we will be...
    • 8 Mar 2021 2:38 PM
  • XG FW - List all tables in the data lake

    • Under Review
    • 1 Comment
    List the tables in the data lake from an XG Firewall. -- List ALL XG FW Tables SELECT DISTINCT log_type, log_component, COUNT(dist_key) entries FROM xgfw_data GROUP BY log_type, log_component ORDER By log_type, log_component ASC Sample results...
    • 16 Nov 2020 9:55 PM
  • windows_wsl_installed

    • Under Review
    • 0 Comments
    windows_wsl_installed SCHEMA atime long Last access time ctime long Time of the change event filename string Name of the file that has changed mtime long time of the most recent registry write path ...
    • 14 Oct 2020 8:38 PM
  • windows_updates_patch

    • Under Review
    • 0 Comments
    windows_updates_patch SCHEMA caption string Short description of the patch description string Plugin description text hotfix_id string The kb article ID for the update installed_by string The system context...
    • 14 Oct 2020 8:36 PM
  • windows_startup_programs_md5

    • Under Review
    • 0 Comments
    windows_startup_programs_md5 SCHEMA core_file_info string Core file info file_size long File size now global_rep int The machine learning global reputation now global_rep_data string All global reputation data...
    • 14 Oct 2020 8:34 PM
  • windows_startup_items

    • Under Review
    • 0 Comments
    windows_startup_items SCHEMA cmdline string Process command line name string Name of the registry value entry path string Full path to the value result string The authenticode signature of the startup item...
    • 14 Oct 2020 8:31 PM