Examples
Return the last timestamp found in the dataset for any given
action_total_download
value for all records
that have matching values for their
actor_process_image_path
and
actor_process_command_line
fields.
dataset = xdr_data
| fields _time,
actor_process_image_path as Process_Path,
actor_process_command_line as Process_CMD,
action_total_download as Download
| filter Download > 0
| comp last(_time) as download_time by Process_Path, Process_CMD