This query will detail network activity for a defined Sophos Process ID
-- Data Lake show network activity for defined Sophos Process ID
-- VARIABLE $$sophos_pid$$, SophosPID
WITH split_pids AS (
SELECT
x2.new_pid,
x1.*
FROM
xdr_data...