Hello,
I run YARA-L queries in the SecOps Native Dashboards to obtain variety of metrics. In this case, I am trying run a query that returns byte size for Defender logs, but broken down by product event type (e.g. DeviceProcessEvents) and ingestion label; since we have multiple feeds for certain event types and I'd like to check on a per feed basis. Is there any guidance on what syntax I could use for bytes?
Thank you
