Hi! Yes, here is the complete search: $case_token$ sourcetype=hayabusa $host_token$ $level_token$ $rule_token$
| table Timestamp, host, Computer, Level, Channel, RecordID, EventID, Ruletitle, Detail...
See more...
Hi! Yes, here is the complete search: $case_token$ sourcetype=hayabusa $host_token$ $level_token$ $rule_token$
| table Timestamp, host, Computer, Level, Channel, RecordID, EventID, Ruletitle, Details, * Channel is added as a field in the table command, as well as specified in the code: <fields>Timestamp, host, Computer, Level, Channel, RecordID, EventID, RuleTItle, Details</fields>