|
Create a new advanced query |
If you want to use an existing query template to create a new query, click Show Template List and click a template, then skip the first step below.
- In the query field, type or paste the EQL syntax for the query. As you type, syntax options and validation messages will display to help you build your query.
If you want to save the current query as a template, click Save As Template. Type a name and description and select whether you want the template to be private or available to all administrators. Click Save. You can pin, edit, and delete queries from the templates list.
- To set the scope of the query, under Search devices, click By Zone or By Device (an icon next to each device indicates whether the device is online). Select one or more zones or devices, then click Save. If you don't set the scope, the query applies to all zones and devices.
- To set a date and time range for the query, click
and configure the range. Click Apply. If you don't set a range, the query applies to all available data.
- Do one of the following:
If you want to save query results to view them later from the Query Snapshots tab, in the results section, click . Type a name and description and select whether you want the results to be private or visible to all users. |
|
View a query snapshot |
On the Query Snapshots tab, click a query snapshot.
Note that this displays the original results of the query when it was saved and is not a new query. |