index=YOUR_NETWORK_INDEX src_ip="YOUR_ZIMBRA_IP" earliest=-7d latest=now | where in(dest_ip, "45.32.30.235", "193.42.40.135") OR in(lower(dest_host), "transzimbra.linkpc.net", "psk1zim.abrdns.com", "tls.psk1zim.abrdns.com", "wslogzimbra.linkpc.net") | table _time src_ip dest_ip dest_port dest_host action | sort -_time | head 200