News

1. Search for SSH Events index=main sourcetype=sshd 2. Extract Relevant Fields index=main sourcetype=sshd | eval parts=split(_raw, "\t") | eval timestamp_epoch ...