SIEM Query Translator

Source Format
Target Format
Valid
Quick Patterns

Translated Query

high confidence
SecurityEvent
| where EventCode == "4625" and src_ip == "10.0.0.1"

Translation Diff

Preserved (1) Modified (2) Lost (1)
EventCode=4src_ip=1searchAND

Confidence Breakdown

FieldValueConfidenceReason
EventCode4625HIGHDirect field mapping available
src_ip10.0.0.1HIGHDirect field mapping available