Cortex XDR XQL comp count_distinct aggregate counts the number of total values seen for the field in the result set.
comp count(<field>) [as <alias>] by <field_1>,<field_2>
Return a count of all values seen for the
actor_process_image_pathfield for all records that have matching values for their
dataset = xdr_data | fields actor_process_image_path as Process_Path, actor_process_command_line as Process_CMD, action_total_download as Download | filter Download > 0 | comp count(Process_Path) as num_process_path by process_path, process_cmd | sort desc process_path
Recommended For You
Recommended videos not found.