Enter text in the search entry bar, then click Search. When you type a query, it will automatically wrap to the next line when it reaches the edge of the search entry bar. The filter options shown beneath the text entry box update as you enter text. You can use the arrow keys to scroll through the filter options. Click on the filter or press tab to select it.
The operators shown are based on the selected field. The = operator is an exact match and is case sensitive. The ~= operator functions as "contains."
Values entered that are greater than one word must be in quotations. Single words do not require quotations. Values with parenthesis in the beginning must be closed with parenthesis. Enter a comma behind selected fields that follow "in" or "not in" to see the list of other fields.
You can also select all the filter options available for the query. The select all option will be available if the below two conditions are valid:
You are using IN or NOT IN operator
The filter has minimum 2 or maximum 20 options.
You can add multiple conditions using the AND, AND NOT, OR, and OR NOT operators.
Example queries:
"Advanced Threat Verdict" in (Fail) AND Subject = "malware test""Custom Rule Name" in ("Test1") AND "From (SMTP)" = "tql_test@musubi2.etp-testdomain5.com""Rejection Reason" in ("Recipient Rejected", "Rate Limit Exceeded", "DHAP Match", "RBL Match", "SPF Failure", "DKIM Failure", "DMARC Failure", "Start TLS not issued")"Riskware Rules" in ("65030 - Encrypted PDF Document", "65004 - Script Delivered via Email") AND "Recipient (SMTP)" = "phani@bathory1.etp-testdomain5.com""Policy Action" in ("Drop or Quarantine or Remediate") AND Domain in (bathory1.etp-testdomain5.com)"Spam Verdict" in (Pass) AND Domain in (yararule2.etp-testdomain5.com)"Yara Rule Action" in ("Alert and Quarantine") OR Subject = "ERPPX_Yara_Rule_On_Body+Custom_dropping""Remediate Action" in (Quarantined) AND "Spam Verdict" in (Fail)Domain in (etpqag3.com) AND Subject ~= Test"Advanced Threat Verdict" in (Fail) OR "Has Retroactive Alert" = True"Has Release Justification" = True
Select Clear to clear the search entry bar. For descriptions of the filters, see Basic filters and Adding more filters. Select
to view and select previous searches. The timeframe is not stored for previous searches.
To select the search timeframe, click within the calendar entry bar then select a time frame. The options are Last 24 hours or a custom timeframe. The timeframe is set to the last 24 hours by default.
To view the details of a message, place the cursor on the row you want to review and then click the Details link.