It came from the infosec app under host investigation Here is the search | tstats summariesonly=true allow_old_summaries=true max(_time) as _time, values(Authentication.action) as action, values( as app, count from datamodel=Authentication.Authentication where (Authentication.src="::ffff:" OR Authenication.dest="::ffff:") by Authentication.src, Authentication.src_user, Authentication.dest, Authentication.user | rename "Authentication.*" as "*" | eval src=if((src=== "unknown"),null(),src), dest=if((dest == "unknown"),null(),dest) | fields + _time, src, dest, action, app, count, user, src_user, count | sort - count
... View more