Hi All,
I am looking to create a rule to compare the current number of events at a given day and time against the historical average for the same period. E.g. 100 events on Monday between 09:00 - 10:00 today versus the same number of events a week earlier (on Monday between 09:00 - 10:00).
I have looked into the series by
Other SIEM platforms have the concept of subsearches, I’m not sure if the same functionality exists in YARA-L 2.0 or if there is a workaround to achieve a similar result.
Any advice would be appreciated!
TIA