Detections of the APT simulatorAPT Demo hitsOver time by deviceindex=wineventlog sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" tag=APT | timechart count(tag) by dvc$field1.earliest$$field1.latest$1APT Demo hitsOver time by typeindex=wineventlog sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" tag=APT | timechart count by tag$field1.earliest$$field1.latest$1APT Demo hits