KUMA's SQL functions allow using the attributes of assets and accounts in search queries to filter events, generate reports and widgets (graph type: Table). You can enrich events with data from dictionaries, tables, assets, and accounts using the following sets of functions:
enrich function set includes the following functions:enrich_assetsenrich_accountsenrich_tableenrich_dictionarylookup function set includes the following functions:lookup_assetslookup_accountslookup_assets_categoryThe maximum number of events per query is 10,000.
Page top