min
The min function returns the minimum of the values within a numeric column. It
is often used with match to get the minimum value within each
group in the data.
| Syntax | Param data types | Return type |
|---|---|---|
min(numericExpression) |
NUMBER |
NUMBER |
Code Sample
Find all the events where
target.ipis not empty. For all the events that match onprincipal.ip, store the minimum ofmetadata.event_timestamp.secondsin a variable calledmin_seconds.target.ip != "" match: principal.ip outcome: $min_seconds = min(metadata.event_timestamp.seconds)