I want to create a search query to search a specific ids event from a source to destination wherever the count of the event from the same source exceeds 2 in an hour. Please advise
Field available are
source destination ids event
Try this
yoursearchhere | stats count by ids source | where count > 2
Could you provide some example output you are looking for?