How to: Compound Queries In Gravwell

Logo
Presented by

Gravwell

About this talk

Compound queries in Gravwell unlock incredible potential for analysts who need to ask critical questions about their data. In this short video, we use a compound query containing a non-temporal lookup table to combine two discrete data sources in order to understand the different locations from which an attacker was staging their malware and gain further insights into the attacker’s TTPs across our systems.
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (8)
Subscribers (1709)
Gravwell is a data platform with security lake features that enables teams to investigate, collaborate, and analyze data on-demand, from any source — all with unlimited data collection and retention.