Query :
index=notable source="Sigma Alert- Data Compressed"
| eval a0=if(isnull(a0), " ", a0),
a1=if(isnull(a1), " ", a1),
a2=if(isnull(a2), " ", a2),
a3=if(isnull(a3), " ", a3)
| stats count by a0 a1 a2 a3
Target:
To count all commands with dynamic arguments
index=notable source="Sigma Alert- Data Compressed"
| eval a0=if(isnull(a0), " ", a0),
a1=if(isnull(a1), " ", a1),
a2=if(isnull(a2), " ", a2),
a3=if(isnull(a3), " ", a3)
| stats count by a0 a1 a2 a3
Target:
To count all commands with dynamic arguments