A QRadar analyst wants to limit the time period for which an AOL query is evaluated. Which functions and clauses could be used for this?
In QRadar, to limit the time period for which an AQL (Ariel Query Language) query is evaluated, the functions and clauses that can be used include START, STOP, LAST, NOW, and PARSEDATETIME. Specifically, the LAST function is used to define a relative time range for the query, such as 'LAST 2 DAYS'.
Carri
16 days agoZita
21 days agoAlishia
26 days agoDelfina
1 month agoChristiane
1 month agoMalcom
1 month agoKarma
2 months agoHelga
2 months agoMan
2 months agoDominque
2 months agoDenae
2 months agoLacey
2 months agoFletcher
3 months agoPaulina
3 months agoDahlia
4 months agoGerald
4 months agoDyan
4 months agoMartin
4 months agoPaz
4 months ago