Resolved! XQL Query: Looking at Multiple Events
Hey there,
I need some help with a query please.
I want a query that returns instances of two events, but ONLY when the events do NOT occur within 2 minutes of each other.
dataset = xdr_data
| filter (event_type = ENUM.PROCESS and event_sub_type =