Forum Discussion

Matthew Maguire's avatar
Matthew Maguire
Copper Contributor
Jan 18, 2018
Solved

Filtering log by date

Hi, I can't seem to find the right syntax for this query:   ProtectionStatus | summarize ThreatStatusRank = max(ThreatStatusRank) by Computer, Time = bin(todatetime(DateCollected), 10m) | summa...
  • Matthew Maguire's avatar
    Jan 18, 2018
    Hi, managed to get this working using the following:
     
    ProtectionStatus
    | where TimeGenerated > ago(1d)
    | summarize ThreatStatusRank = max(ThreatStatusRank) by Computer, Time = bin(todatetime(DateCollected), 10m)
    | summarize(Time, ThreatStatusRank) = argmax(Time, ThreatStatusRank) by Computer
    | where ThreatStatusRank !in (150, 470)
    | project Computer, Rank = ThreatStatusRank
     

Resources