Jan 18 2018
03:46 AM
- last edited on
Apr 07 2022
04:51 PM
by
TechCommunityAP
Jan 18 2018
03:46 AM
- last edited on
Apr 07 2022
04:51 PM
by
TechCommunityAP
Hi, I can't seem to find the right syntax for this query:
ProtectionStatus | summarize ThreatStatusRank = max(ThreatStatusRank) by Computer, Time = bin(todatetime(DateCollected), 10m) | summarize(Time, ThreatStatusRank) = argmax(Time, ThreatStatusRank) by Computer | where ThreatStatusRank !in (150, 470) | where TimeGenerated > ago(1d) | project Computer, Rank = ThreatStatusRank
Jan 18 2018 04:29 AM
SolutionProtectionStatus | where TimeGenerated > ago(1d) | summarize ThreatStatusRank = max(ThreatStatusRank) by Computer, Time = bin(todatetime(DateCollected), 10m) | summarize(Time, ThreatStatusRank) = argmax(Time, ThreatStatusRank) by Computer | where ThreatStatusRank !in (150, 470) | project Computer, Rank = ThreatStatusRank
Jan 19 2018 12:26 PM