index=network (traffic_volume>normal OR src_ip=internal AND dst_ip=external)
index=network (file_name=sensitive AND (protocol=ftp OR protocol=http))
index=system (user_permissions_changed=* OR user_type=admin_account_created)
index=network (traffic_volume_change>normal OR new_connection=true)
index=system (file_encryption=true OR file_name=ransom
index=network dst_domain=malicious_domain
index=system (protocol=ssh OR protocol=rdp)
index=network (traffic_volume>normal OR resource_usage>normal)
index=system (file_modified=true AND (file_type=system OR file_path=sensitive_directory))
index=email (link=suspicious OR attachment=suspicious)
index=system (query_text=* OR query_syntax=suspicious)
index=system (login_status=failed OR (username=* AND password=*))
index=system (file_access=sensitive OR database_access=sensitive) AND user!=authorized_user
index=system (cpu_utilization>normal OR memory_utilization>normal OR response_time>normal)
index=system (data_exfiltration=true OR user_account_access=unauthorized)
index=web (code_injection=true OR javascript_executed=unexpected)sp
index=web (traffic_volume_change>normal OR new_referral_source=true)
index=web (access_attempt=suspicious OR (username=* AND password=*))
index=web (new_page_appeared=true OR error_generated=true)
index=web (directory_access=suspicious OR traversal_technique=used)
index=network (src_ip=trusted AND (dst_ip=external OR dst_ip=malicious))
index=system (crypto_weakness=exploited OR crypto_algorithm=unexpected)
index=system (config_changed=true AND config_change_authorized=false)
index=system (vulnerability_exploited=true OR exploit_used=true)
index=system (command_executed=unexpected OR (file_accessed=unexpected AND directory_accessed=unexpected))
index=system (account_type=privileged AND (access_authorized=false OR usage_authorized=false))
index=system (new_log_source=true OR log_entry_type=error)
index=system (data_changed=true AND (data_type=database OR data_fake=true))
index=system (user_account_access=unexpected OR device_access=unexpected OR (device_type=suspicious AND software_type=suspicious))
index=system (data_access=restricted OR command_executed=unauthorized)
index=email (attachment_received=suspicious OR data_sent=sensitive)
index=system (privilege_level=elevated OR privilege_escalation_attempt=true)
index=system (log_deleted=true OR log_error_generated=true)
index=system (data_transferred=sensitive OR data_shared=unauthorized)
index=system (process_executed=unexpected OR process_arguments=unexpected)
index=system (login_attempts=repeated AND password_attempts=different) OR (attack_technique=dictionary)
index=network (new_listening_port=true OR (protocol=unexpected AND port=known))
index=system (malware_detected=true OR (program_executed=unexpected AND script_executed=unexpected))
index=system (new_admin_account=true OR user_permissions_changed=true)
index=security_device (config_changed=true AND config_change_authorized=false)
index=network (src_ip=internal AND (dst_ip=external OR protocol=unexpected))
index=cloud (access_attempt=unauthorized OR (username=* AND password=*))
index=network (src_ip=external AND (dst_ip=internal OR protocol=unexpected))
index=system (installed_software_vulnerability=known OR (application_outdated=true AND application_supported=false))
index=system (command_executed=unauthorized AND system_type=critical) OR (data_accessed=sensitive AND system_type=critical)
index=network_device (device_vulnerability=known OR (firmware_outdated=true AND firmware_supported=false))
index=network (src_ip=malicious OR dst_ip=malicious) AND (protocol=unexpected OR protocol=known_malicious)
index=web (web_application_vulnerability=known OR (web_application_outdated=true AND web_application_supported=false))
index=network (src_ip=external AND (dst_ip=internal OR dst_resource=internal))
index=network (internal_resource_access=unauthorized OR protocol_executed=unexpected)
index=system (user_account_access=unauthorized OR (username=* AND password=*))
index=network (dst_domain=malicious AND domain_blacklisted=true)
index=system (file_access=sensitive OR directory_access=sensitive OR system_setting_access=sensitive) AND user!=authorized_user
index=system (vulnerability_unknown=true OR exploit_unknown=true)
index=network dst_ip=malicious_IP
index=system (data_access=sensitive AND user_type=trusted) OR (command_executed=unauthorized AND user_type=trusted)
index=system (third_party_application=unapproved OR third_party_application_installation_source=untrusted)
index=network (dst_ip=malicious OR dst_domain=malicious)
index=system (privileged_account_access=unauthorized OR privileged_account_permissions_changed=
index=system (third_party_software_vulnerability=known OR (application_outdated=true AND application_supported=false))
index=mobile (app_installed=unauthorized) OR (data_accessed=sensitive AND device_type=mobile)
index=system (operating_system_vulnerability=known OR system_library_vulnerability=known OR (system_software_outdated=true AND system_software_supported=false))
index=network (traffic_volume_change=unexpected OR new_protocol_detected=true)