Cortex XDR XQL comp sum aggregate returns the sum of an integer field in the result set.
comp sum(<field>) [as <alias>] by <field_1>,<field_2>
sumaggregation is a comp function that returns the sum of an integer field, for all records that contain matching values for the fields identified in the
Return the sum of the
action_total_downloadfield for all records that have matching values for their
dataset = xdr_data | fields actor_process_image_path as Process_Path, actor_process_command_line as Process_CMD, action_total_download as Download | filter Download > 0 | comp sum(Download) as total_download by Process_Path, Process_CMD
Recommended For You
Recommended videos not found.