Skip to content

Updating TI queries based on feedback and discussions#3571

Merged
petebryan merged 5 commits into
masterfrom
shainw-updateTIjoins
Nov 30, 2021
Merged

Updating TI queries based on feedback and discussions#3571
petebryan merged 5 commits into
masterfrom
shainw-updateTIjoins

Conversation

@shainw

@shainw shainw commented Nov 29, 2021

Copy link
Copy Markdown
Contributor

Discussions as part of - #3477 - This includes generic changes that need to be done. Customers may still want to customize.

Proposed Changes

  • Specifying join kind explicitly and commenting as to why we use innerunique.
  • Making changes to filtering after the join and fixing the 2nd argmax to use the activity time instead of indicator time as you want the most recent activity that matches
  • Include the primary join token value in the 2nd argmax() so we do not lose visibility on the friendly name of the IOC and only use the IndicatorId.
  • Added in some additional entity mappings

 - and I don't want preferences for a specific environment to be included.  This includes generic changes that need to be done.

@petebryan petebryan left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All make sense

@petebryan petebryan merged commit d8ba659 into master Nov 30, 2021
@petebryan petebryan deleted the shainw-updateTIjoins branch November 30, 2021 00:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants