Example Queries

To see only data from one of the feeds, you can search with the query:

#event.dataset := "zia.web"

Which only returns the data that was parsed with the parser for web events (and similarly for the other feed types and their parsers).

To see where your traffic is headed, you can search for:

worldMap(ip=destination.ip)