query(group) indicators by domain name
If I have a tenant/account that has incidents.
some of those incidents have indicators / entities tied to abc.com or xyz.com
Is there a way to query for, show me all the incidents that have hostnames or account names that end in abc.com?
Wasn't having l



