Per documentation, for example the action field in network traffic datamodel, prescribed values are allowed, blocked and teardown. But you have many values under action field. As suggested above, you can create a calculated field like | eval action=case((action="xxx" OR action="yyy"),"allowed",1=1,"blocked") Doing this on all recommended fields will increase you compliance %
... View more