You can reconstruct the sequence of events during an attack by following the attacker's movements through your network.
Start your investigation with a known Indicator Of Compromise (IOC), such as a malicious IP address or a compromised user account. Enter this value into the Search hostname / ipaddr or Search username field.
In the results grid, identify a related host or account you want to investigate further.
Pivot your search by clicking on the value in the Src/Tgt Host or Src/Tgt Acct column. This action automatically starts a new search for all activity related to that entity.
Repeat this pivoting process to follow the trail from one system to the next, which builds a timeline of the attacker's activity.