|restsplunk_server=local /services/saved/searches |wherematch(search,"datamodel")and 'action.correlationsearch.enabled'=1|fields title search|rexfield=search"datamodel=(?<datamodel1\S+)"|rexfield=search"datamodel:(?<datamodel2>\S+)"|rexfield=search"datamodel\s\"(?<datamodel3>[^\"]+)"|evaldatamodel=coalesce(datamodel1,coalesce(datamodel2,datamodel3))|table title searchdatamodel
|restsplunk_server=local /services/saved/searches |wherematch('action.correlationsearch.enabled',"1|[Tt]|[Tt][Rr][Uu][Ee]")andmatch('is_scheduled',"1")andmatch('disabled',"0")|table title search
|fromdatamodel:"Authentication"."Authentication"|searchaction=failure ORaction=success
|streamstatswindow=0current=truereset_after="(action=\"success\")" count as failure_count by user
|whereaction="success"and failure_count >10|statsvalues(failure_count)as failure_count by user