-7d@d now * endpoint endpoint `itsi-cp-servicenow-indexes` sourcetype="snow:*" | top limit=20 endpoint -24h@h now *
Events by Resource `itsi-cp-servicenow-indexes` eventtype=snow_em_event endpoint=$Snow_Instance_Endpoint$ | stats dc(sys_id) by resource $time_picker.earliest$ $time_picker.latest$ Events by Type `itsi-cp-servicenow-indexes` eventtype=snow_em_event endpoint=$Snow_Instance_Endpoint$ | stats count by sys_id type | top limit=4 type $time_picker.earliest$ $time_picker.latest$ Events by Severity `itsi-cp-servicenow-indexes` eventtype=snow_em_event endpoint=$Snow_Instance_Endpoint$ | stats count by sys_id severity_name | top limit=20 severity_name $time_picker.earliest$ $time_picker.latest$ Events by Node `itsi-cp-servicenow-indexes` eventtype=snow_em_event node != "NULL" endpoint=$Snow_Instance_Endpoint$ | timechart dc(sys_id) by node limit=10 $time_picker.earliest$ $time_picker.latest$ ServiceNow Events `itsi-cp-servicenow-indexes` eventtype=snow_em_event endpoint=$Snow_Instance_Endpoint$ | dedup sys_id|table description,type, resource, dv_state, sys_created_on|rename dv_state as status|rename sys_created_on as "create time" $time_picker.earliest$ $time_picker.latest$