Summarize Operator
Overview
Aggregate findings with summarize
.
Many aggregations are supported, including:
See a full list of available aggregations on PantherFlow Functions.
Examples
Count
The following query displays the count of all events in the last day stored in field num_connections
:
Group count by single field
The following query counts the number of connections for each clientIp
and orders results with the largest number of connections first:
Group count by multiple fields
The following query displays num_connections
grouped by both the clientIp
and clientPort
fields:
Group count by arbitrary expressions
Count distinct
The query below stores the distinct number of clientIp
s in num_distinct_clients
:
Refer to an aggregation later
You can refer to an aggregation in a subsequent query expression:
Summarize by field (without aggregation)
The query below displays each unique userAgent
:
Last updated