Horizontal Scan:
External scan against a group of IPs for a single port.
Vertical Scan:
External Single IP being scan against multiple port.
What events are you dealing with? Please share an anonymised sample selection.
What do your expected results look like?
What have you tried so far?
I'm dealing with Cisco firewall events.
I see that you are new here. But this is a Splunk forum. Very few people will know what Cisco firewall events entail. In fact, Cisco firewall can also have multiple forms. @ITWhisperer is asking you to post sample (anonymized) or mock data. You can use raw events, or field tables. You should also illustrate desired results. Additionally, explain very clearly which part of the data will lead to your desired result and how. In short, you need to explain how to get your desired results WITHOUT Splunk.