PantherFlow Statements
There are two types of PantherFlow query statements
Overview
Tabular expression statements
panther_logs.public.aws_cloudtrail
| where accountId != '1234567'
| summarize Count=agg.count() by eventName
| extend tooHigh = Count > 100
| where tooHigh
| sort Count
| limit 10let statements
let statementsExample
Last updated
Was this helpful?

