A QRadar analyst wants to limit the time period for which an AOL query is evaluated. Which functions and clauses could be used for this?
In QRadar, to limit the time period for which an AQL (Ariel Query Language) query is evaluated, the functions and clauses that can be used include START, STOP, LAST, NOW, and PARSEDATETIME. Specifically, the LAST function is used to define a relative time range for the query, such as 'LAST 2 DAYS'.
Karma
2 days agoHelga
7 days agoMan
12 days agoDominque
17 days agoDenae
22 days agoLacey
27 days agoFletcher
2 months agoPaulina
2 months agoDahlia
2 months agoGerald
2 months agoDyan
2 months agoMartin
3 months agoPaz
3 months ago