A QRadar analyst wants to limit the time period for which an AOL query is evaluated. Which functions and clauses could be used for this?
In QRadar, to limit the time period for which an AQL (Ariel Query Language) query is evaluated, the functions and clauses that can be used include START, STOP, LAST, NOW, and PARSEDATETIME. Specifically, the LAST function is used to define a relative time range for the query, such as 'LAST 2 DAYS'.
Fletcher
5 days agoPaulina
10 days agoDahlia
15 days agoGerald
21 days agoDyan
26 days agoMartin
1 month agoPaz
1 month ago