Examples
Return the chronologically earliest timestamp found for any given
action_total_download
value for all records
that have matching values for their
actor_process_image_path
and
actor_process_command_line
fields.
dataset = xdr_data
| fields _time,
actor_process_image_path as Process_Path,
actor_process_command_line as Process_CMD,
action_total_download as Download
| filter Download > 0
| comp earliest(_time) as download_time by Process_Path, Process_CMD