Use the search bar on the Enterprise Search page to construct search conditions and start your search. Search conditions are token strings constructed using tokens, operators, and values. More than one condition (token string) can be specified in a search expressions. However, the list of the available tokens becomes more limited as your search expression grows. This is because certain tokens automatically eliminate the use of other tokens in the same search expression. See Search token reference for descriptions of each token. To learn about the limitations of Enterprise Searches, see Search limits
Two special tokens are available for conditions:
The Host Set token allows you to limit the search to a specific host set. By default, the search value for this token is set to All hosts (an internal host set that includes every host known to the Endpoint Security (HX)).
The Group By token allows you to display results in grid mode (also known as Group By mode). This mode groups search results by one or more selected fields, summarizing results by the specified fields and displaying them in a grid. When specified, Group By must be the last token in the search expression. See Understanding search modes .
This section covers the following topics: