Hello,
I’m quite new to InsightIDR and just getting used to writing queries.
I need to subtract two timestamps from eachother and cannot find a way to do this.
What I’m after is a calculation between the time field for the ALERT_OPENED action and the ALERT_ASSIGNED action contained in Audit Logs/InsightIDR Alerts.
Essentially I need to subtract the timestamp for ALERT_OPENED from ALERT_ASSIGNED and track the SOC’s SLA this way - the difference.
I can see that the Security Operations Activity dashboard has something similar, but it’s not as granular (shows <1hour) and I can’t see the search that drives the infromation behind that card.
Does anyone have an idea on how to do something like this? Thanks!