AQL Functions Reference
Lookup Functions
| Function | Description | Example |
|---|---|---|
|
App name from ID |
|
|
Protocol name from ID |
|
|
Hostname from asset DB |
|
|
Log source name |
|
|
Event name from QID |
|
|
Category name |
|
Date/Time Functions
| Function | Description | Example |
|---|---|---|
|
Current timestamp |
|
|
Format timestamp |
|
Network Functions
| Function | Description | Example |
|---|---|---|
|
Check if IP in CIDR |
|
|
Geo lookup |
|
Context
-
flows = NETWORK ACTIVITY → Advanced Search
-
events = LOG ACTIVITY → Advanced Search
If you get "Database 'flows' is invalid" you’re in the wrong context!