In the Navigate view or Legacy Events view, you can create a query rather than clicking through the meta keys and values to drill down into the meta data. The dialogs for creating a query offer syntax help with drop-down lists of applicable meta keys and operators. To access this dialog in the Navigate or Legacy Events view toolbar, select Query.
What do you want to do?
|User Role||I want to ...||Show me how|
Incident Responder or Threat Hunter
review detections and signals seen in my environment
NetWitness Platform Getting Started Guide
|Incident Responder|| |
review critical incidents or alerts
NetWitness Respond User Guide
|Threat Hunter||query a service, metadata, and time range*|
|Threat Hunter|| |
|Threat Hunter|| |
view sequential events
reconstruct and analyze an event
|Threat Hunter||examine files and associated hosts|
|Threat Hunter||perform lookups|
|Threat Hunter||create an incident or add to an incident|
add a meta value to a Context Hub list
*You can perform this task in the current view.
The Query dialog has three views:
In the Simple view, you can create a query using the options displayed in the dialog. In the Advanced view, you can create a query without guidance. In the Recent view, you can select a query from a drop-down list of recent queries.
The following table describes features of the Query dialogs.
|Select Meta||Displays a drop-down list of meta groups.|
|Operator||Displays a drop-down list of operators (=,NetWitness Platform!=,NetWitness Platformexists,NetWitness Platform!exists)|
|Value||Allows you to enter a value to complete the query.|
|Network||Limits the query to packets if Log is not selected.|
|Log||Limits the query to logs if Network is not selected.|
|Query box||Allows you to enter a query in the Advanced view. When you begin typing, a drop-down list of available meta keys for the service is displayed, then a drop-down of operators is displayed as you type. If the expression currently entered in the query box is invalid, a warning appears near the box. When the query is valid, the warning is removed.|
|Query list||Allows you to select a query from a list of recent queries in the Recent view. Double-clicking a query automatically applies it.|
|Apply||Applies the new query to the current Investigation view.|
|Cancel||Closes the dialog without applying changes.|
|Reset||Resets all fields.|