Grouped by Detection Method
- Known-Bad Destination Port Use
- Anomalous Destination Port Use
- Newly observed Source System, Protocol
- Newly Observed Source System, HourOfDay
- Source System, Destination System, Protocol=UDP where Source System Count exceeds threshold
- Source System, Destination System, Protocol=UDP where Destination System Count exceeds threshold
- Source System, Protocol=TCP where Count exceeds threshold
- Destination System, Protocol=TCP where Count exceeds threshold
- Layer 3 or 7 Firewall Logs