Moved from Community Support to Business > SIEM for better support.
Can u pls explain us what exactly you want to achieve?,if you want to see only events containing with destination IP (::),than go with filters which are present in right side of the dashboard.
This is exactly what i am looking for : Filter all events in a dashboard contains destination IP (::)...However i dont know the value that i need to put in a filter in dashboard...
When i use :: as a value in a filter(destination IP), i does not show any event....
At first convert your dashboard in tabular form and check whether :: is present in destination column or not?if yes than easiest way to include or exclude through filter.
The Destination IP of '::' which shows in the Events pane is a representation that the Destination IP is blank, not that it is actually '::' in other words there was not a Destination IP in the packet.
The funny part is that you can filter on ! :: (Not then the Pipe Pipe) and see all the results where a Destination IP is present, but it will not allow you to search for if one is absent/blank.