KNOWLEDGE BASE
Visit dnif.it
Go to Customer Portal
Sign in
ANALYZE IN STYLE
START YOUR TRIAL
DEVICE INTEGRATION
CISCO
FORTINET
MICROSOFT
SYMANTEC
CONNECTORS
Supported connectors
DATA INGESTION
EXTRACTORS
ENRICHMENT
ENRICHMENT EXAMPLES
HUNTING WITH WORKBOOKS
GETTING STARTED
VISUALIZATION
ANALYZE IN STYLE
PIPES
FUNCTIONS
DQL (LEGACY)
SECURITY MONITORING
INVESTIGATE SIGNALS
MANAGING CASES
OPERATIONS
MANAGE DASHBOARDS
MANAGE REPORTS
MANAGE USERS AND ACCESS
BILLING
MANAGING YOUR COMPONENTS
PICO
GETTING STARTED
INSTALLATION
SOLUTION DESIGN
AUTOMATION
SUPPORTED AUTOMATION
SUPPORTED AUTOMATION - SSH
TROUBLESHOOTING AND DEBUGGING
TROUBLESHOOTING CONNECTORS
LICENSE MANAGEMENT
RELEASE NOTES
API
POLICIES
SECURITY BULLETINS
Back to home
KNOWLEDGE BASE
ANALYZE IN STYLE
START YOUR TRIAL
DEVICE INTEGRATION
CISCO
FORTINET
MICROSOFT
SYMANTEC
CONNECTORS
Supported connectors
DATA INGESTION
EXTRACTORS
ENRICHMENT
ENRICHMENT EXAMPLES
HUNTING WITH WORKBOOKS
GETTING STARTED
VISUALIZATION
ANALYZE IN STYLE
PIPES
FUNCTIONS
DQL (LEGACY)
SECURITY MONITORING
INVESTIGATE SIGNALS
MANAGING CASES
OPERATIONS
MANAGE DASHBOARDS
MANAGE REPORTS
MANAGE USERS AND ACCESS
BILLING
MANAGING YOUR COMPONENTS
PICO
GETTING STARTED
INSTALLATION
SOLUTION DESIGN
AUTOMATION
SUPPORTED AUTOMATION
SUPPORTED AUTOMATION - SSH
TROUBLESHOOTING AND DEBUGGING
TROUBLESHOOTING CONNECTORS
LICENSE MANAGEMENT
RELEASE NOTES
API
POLICIES
SECURITY BULLETINS
ANALYZE IN STYLE
Work with events data, look and find using these tools and techniques.
DQL - Right from the start
Basic Syntax
Schema on Read
PIPES
Duration
Having Clause
Timeslice
Last
First
Limit
Groupby
Select
See more
FUNCTIONS
Count_if
Distinct_count
Length
Avg
Min
Max
Sum
Not Clause
Regex Match
Distinct
Wildcard
Percentage_of
Ratio_of
See more
DQL (LEGACY)
_checkif
_trigger
Schema on Read (Legacy)
_lookup
_retrieve
_store
_export
_limit
_agg
_fetch
_sort
See more