I want to use the new search signature="test" in the below search.
I don't want to add this new signature to the existing lookup.
| tstats summariesonly=true values (IDS_Attacks.action) as action
from datamodel=Intrusion_Detection.IDS_Attacks
by _time, IDS_Attacks.src, IDS_Attacks.dest, IDS_Attacks.signature
| `drop_dm_object_name(IDS_Attacks)`
| lookup rq_subnet_zones Network as dest OUTPUTNEW Name, Location
| lookup rq_subnet_zones Network as src OUTPUTNEW Name, Location
| search NOT Name IN ("*Guest*","*Mobile*","*byod*","*visitors*","*phone*")
| lookup rq_emergency_signature_iocs_v01 ioc as signature OUTPUTNEW last_seen
| where isnotnull(last_seen)
| dedup src
| head 51