Hi @Hoan_Le,
this looks like a data table visualization with a src_address Terms aggregation as the buckets and a Top Hit aggregation on threat_name as the metric. It could be configured something like this (with different field names, obviously):
