Splunk Enterprise Security 8
list_alt
Source: Choose from existing sources in your asset and identity lookups.
Category: Choose from existing categories in your asset and identity lookups.
Pattern match: Enter a pattern to match against normalized_risk_object values.