PantherFlow Examples: SOC Operations
View log sources that last received data
union panther_logs.public.*
| where p_event_time > time.ago(1d)
| summarize last_received_data=agg.max(p_parse_time) by p_source_label, p_source_id
| sort last_received_data descThis query leverages summarize, sort, and agg.max().
Example output:

Alert count by severity
This query leverages:
Functions:
time.ago(),agg.count(), andcase()
Example output:

Alerts by severity per day over the past two weeks
This query leverages:
Functions:
time.ago(),time.trunc(),agg.count(),agg.sum(), andcase()
Example output:\

Mean time to resolution by severity
This query leverages:
letstatement functionalityFunctions:
time.ago(),time.diff(),agg.avg(), andcase()
Example output:

Alerts created per hour by severity
This query leverages:
letstatement functionalityFunctions:
time.trunc(),time.ago(),agg.count(),agg.sum(),case()
Example output:

Last updated
Was this helpful?

