This search looks for if the the field "State" or "status" has changed but the risk message still shows a generic format by user which is not captured in the _raw log. I recommend we show either State or status and value in the [ ] brackets. For example, the values will be Started or Stopped
This search looks for if the the field "State" or "status" has changed but the risk message still shows a generic format by user which is not captured in the _raw log. I recommend we show either State or status and value in the [ ] brackets. For example, the values will be Started or Stopped