Cortex XDR XQL sort stage identifies the sort order for records returned in the result set.
sort asc|desc <field1>[, asc|desc <field2>...]
sortstage identifies the sort order for records returned in the result set. Records can be returned in ascending (
asc) or descending (
desc) order. If you provide more than one field to the
sortstage, records are sorted in field specification order.
event_timestampfields from all
xdr_datarecords where the
action_countryfield is not "-". Sort the result set first by the
action_countryfield value in descending order, then by
event_timestampfield in ascending order.
dataset = xdr_data | fields action_country as ac, event_timestamp as et | replacenull ac = "N/A" | filter ac != "-" | sort desc ac, asc et
Recommended For You
Recommended videos not found.