問題文
A SOC wants, per account, the count of distinct destination hosts contacted and the first and last times each account was seen, over 30 days, using only fields present at index time. Which combination achieves that most efficiently?
選択肢
- Aggregate with the ordinary command and accept the slower run, because the boundary timestamps are only available to that command.
- Group the events into transactions by the account and read the duration, since the transaction command reports the boundary times and the group size for free.
- One index-time aggregation grouped by the account, computing the distinct count and the boundary timestamps in the same step.
- An index-time aggregation for the distinct count followed by a separate ordinary aggregation for the timestamps, joined on the account, because the boundary timestamps require reading the raw events in order to establish the exact time each account was first and last observed in the data.