What Investigate tool would you use to allow an analyst to view all events for a specific host?
Which SPL (Splunk) field name can be used to automatically convert Unix times (Epoch) to UTC readable time within the Flacon Event Search?
When performing a raw event search via the Events search page, what are Event Actions?