how to write and combine 2 saperate Query #11781
-
I have Palo Alto and fortigate, and now I want to collect event or threat names with this separate query,
Fortigate :
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
Would something like this work? |
Beta Was this translation helpful? Give feedback.
-
thanks for your suggestion, its work for me.
Do you have any suggestion how to save this query or make it default |
Beta Was this translation helpful? Give feedback.
From https://docs.securityonion.net/en/2.4/dashboards.html#query-bar: