What is a one sentence summary of your feature request?
More Event Details fields in query filtering
Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.
When creating a new investigation, not all fields visible in the event details are available for use as filters in creating queries.
For example its not possible to query over:
Originating Client Protocol, Client IP, Host IP and more.
How do you currently solve the challenges you have by not having this feature?
Was not able to find workaround for lack of this functionality.