NQL bitwise operators
NQL 'and'
binaries during past 30d
| where name == "chrome.exe" and platform == windows NQL 'or'
binaries during past 7d
| where name == "*chrome*" or name == "*firefox*"Last updated
Was this helpful?
Was this helpful?