Raw logs from the SOCRadar incidents collector
-24h@h now
Raw Collector Logs index=_internal source="*ta_socradar_incidents_socradar_incidents_collector.log*" | sort - _time $log_time.earliest$ $log_time.latest$ 30s