A very important step in learning to search through your IDR logs effectively and quickly is to familiarize yourself with the logs coming into each of the IDR Log Search Log Sets. Each of the log sets may have differentiating keywords that are only found in that particular log set and maybe one or two more.
For example, the keyword “action” is found in Active Directory Admin Activity, Cloud Service Activity, and Cloud Service Admin activity, but not in others, so building a query to search multiple log sets can be difficult.
Try simply going through each log set and finding a keyword(s) that is typically only found in that log set and perform a simple groupby() in order to visualize all the potential values for that keyword. You can perform the groupby function on any keyword in any log set.
groupby() - Helps visualize and organize the logs so you can better understand and see what you are looking at
calculate() - Helps show trends and other useful metrics via line graphs
where() - Helps zero in on your search by only showing you results based on the data in your where statement
All three can be used in the same query or you can mismatch in order to see what you want to see.