Thanks for the responses thus far, it is much appreciated. Here are some sanitized examples of logs: "2023-04-25 13:14:27","QZ-NewYork_DMZ","QZ-NewYork_DMZ","80.20.59.143","80.20.59.143","Allowed","28 (AAAA)","NOERROR","webdefence.global.whitespider.com","Software/Technology,Application,Computers and Internet","Networks","Networks","" "2022-10-23 11:34:59","Charlie Five (cfive@workplace.com)","Charlie Five (cfive@workplace.com),QZ-NewYork_Verizon_VPN_NAT,QZ-845310891334","172.32.5.8","8.8.8.8","Allowed","1 (A)","NOERROR","outlook.office365.com","Software/Technology,Webmail,Business Services,Organizational Email,Application,Web-based Email,Online Document Sharing and Collaboration","AD Users","AD Users,Networks,Anyconnect Roaming Client","" In the first example, I would want the values for the categories field to be as follows; each line represents one complete field value as it would display in a search: Software/Technology Application Computers and Internet Alternatively, this would also suffice, which is the entire string exactly as it displays in the log: Software/Technology,Application,Computers and Internet The same applies to the second example, here I will display them as if I clicked on the field in the event drop-down and selected "view events", this is what would be added to the search bar: categories="Software/Technology,Webmail,Business Services,Organizational Email,Application,Web-based Email,Online Document Sharing and Collaboration" Or (I'll only show 1 here for the sake of brevity): categories="Online Document Sharing and Collaboration" Hope this helps you more, and thank you again for your assistance.
... View more