Examples event_description:"accepted a TCP/80 connection from" event_description:"accepted a UDP/5222 connection from" event_description:"established a TCP/443 connection to" event_description:"established a UDP/443 connection to"
event_description:("accepted a" AND "TCPP/80" AND "connection from")
event_description:("accepted a" AND "UDP/5222" AND "connection from")
event_description:("established a" AND "TCP/443" AND "connection to")
event_description:("established a" AND "UDP/443" AND "connection to")