https://tryhackme.com/room/splunk2gcd5
index="botsv2" 10.0.2.101 sourcetype="stream:HTTP"
|stats count as visited by site
| table site, visited
| dedup site
| sort -visited
#add a count the the table.
index="botsv2" sourcetype="stream:smtp" *amber* AND *berk*