PantherFlow Examples: SOC Operations

View log sources that last received data

union panther_logs.public.*
| where p_event_time > time.ago(1d)
| summarize last_received_data=agg.max(p_parse_time) by p_source_label, p_source_id
| sort last_received_data desc

This query leverages summarize, sort, and agg.max().

Example output:

Alert count by severity

This query leverages:

Example output:

Alerts by severity per day over the past two weeks

This query leverages:

Example output:\

Mean time to resolution by severity

This query leverages:

Example output:

Alerts created per hour by severity

This query leverages:

Example output:

Last updated

Was this helpful?