values
Cortex XDR XQL comp values aggregate returns an array for all the values seen for the field in the result set.
Synopsis
comp values(<field>) [as <alias>] by <field_1>,<field_2>
Description
The
values
aggregation is a
comp function that returns an array of all the values found for a given field, for all records that contain
matching values for the fields identified in the
by
clause. The array values are all non-null. Each value appears in the array only once,
even if a given value repeats multiple times in the result set.
Examples
Return an array containing all the values seen for the
action_total_download
field for all records that have matching values for their
actor_process_image_path
and
actor_process_command_line
values:
dataset = xdr_data | fields actor_process_image_path as Process_Path, actor_process_command_line as Process_CMD, action_total_download Download | filter Download > 0 | comp values(Download) as values_download by Process_Path, Process_CMD
Recommended For You
Recommended Videos
Recommended videos not found.