Looking for assistance to search Bro/Zeek for peaks/dips in traffic (what is the best sourcetype to go by).
Also if anyone is good with Bro/Zeek how can I see what occured when for about a week bro_conn (connections) did not ingest but the other sourcetypes for bro were still being ingested.