Hi all,
I am trying to add time modifiers to "from" command ,from within the query, with not much of a luck.
An example for the command is:
| from datamodel:"Authentication"."Failed_Authentication" | search dest="Host1" app="win:local"
Can anyone help me figuring this out ?
↧