I would like to search in Cortex XSOAR for running timers that exceed a certain time. I tried it but it didn't worked out.
It should work like this that I can search for an timer (in this case detectionsla the total duration) and afterwards it should show all INC that are still running (active) where the decetion sla is over 16 hours
While running the above described search I don't get any result. But there are running Incidents that are over these 16 hours.
If anyone can help I would really appreciate it.
When querying incidents by the total duration of the timer you should use a number of the total seconds, in this case 57,600 seconds,
"ago" would make sense for for a field that holds a specific date, like incidents creation date, but a duration cannot be X time ago.
You can try searching by the timer's dueDate field,
more for example please review:
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!