Hi,
You can do it from Query/Report utility.
1) On the Query/ Reports tab, from the first drop down box, select "Activity: All Events and Netflow Top Destination Ports"
2) Then Click on the "Edit" button in the green box in the middle of the page. A new Green box appears.
3) Under "Result Format", select: "All Matching Events"
4) Under 'Order/Rank by', select: "Time"
5) Under 'Filter by Time', select: "Last 1 hour" (assuming you want to get specific events in the past hour"
6) Click Apply
7) Click Submit Inline
You can save this query as report or as your new rule.
Change the source or destination with specific IP, or you can also drill down to service port.
Hope this helps.
Rgds,
AK