Create SQL Detections

Quickly create SQL queries using the Anvilogic low-code SQL builder for Snowflake

Create SQL Queries

    • Select Snowflake and PROCEED

  • Drag GATHER DATA component from the right components list

  • Select avl_get_snowflake_data_edr

avl_get_snowflake_data_edr is the primary data source for Lab. Please use this for all queries

  • Drag Code Block or Filter component from the right components list to begin building queries

--example
process_name = 'cmd.exe'

Ensure your Time Picker is at least last 24 hours

Last updated