max

The max function returns the maximum of the values within a numeric column. It is often used with match to get the maximum value within each group in the data.

Syntax Param data types Return type
max(numericExpression) NUMBER NUMBER

Code Sample

  • Find all the events where target.ip is not empty. For all the events that match on principal.ip, store the maximum of metadata.event_timestamp.seconds in a variable called max_seconds.

    target.ip != ""
    match:
      principal.ip
    outcome:
      $max_seconds = max(metadata.event_timestamp.seconds)