KAPE / Zimmerman tools
Hayabusa events
index=* source="windows_evtx_hayabusa" | table _time,computer,level,ruletitle,details,extrafielnfo,eventid,recordid | sort -_time
index=* source="windows_evtx_hayabusa" | table _time,computer,level,ruletitle,details,extrafielnfo,eventid,recordid | sort -_time