name: cloud_instances_enough_data date: 2024-12-23 version: 2 id: 2aabac97-9782-4156-9dfd-7c1fb7aab2a6 author: Splunk Threat Research Team lookup_type: kvstore description: A lookup to determine if you have a sufficient amount of time has passed to collect cloud instance data for behavioral searches fields: - _key - filter - enough_data match_type: - WILDCARD(filter)