string_count - Reference Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR XQL Language Reference

Product
Cortex XDR
Creation date
2024-02-26
Last date published
2024-05-21
Category
Reference Guide
Abstract

Learn more about the Cortex Query Language string_count() function that returns the number of times a substring appears in a string.

Syntax

string_count (<string>, <pattern>)

Description

The string_count() function returns the number of times a substring appears in a string.

Example

dataset = xdr_data 
| fields actor_primary_username as apu 
| filter string_count(apu, "e") > 1