Reviewing search results

Prev Next

To review the results of an Enterprise Search, click on the search on the Enterprise Search page in the Endpoint Security (HX) Web UI. The search expands showing search request and results.

HX_ReviewSearch.png

The search request area appears at the top of the expanded search request and shows the search conditions (search tokens and values) requested by the search and any exhaustive search options that were requested. The search conditions appear on the WHERE line of the search request area. The exhaustive search options appear on the OPTIONS line of the search request area.

Search results are presented on a series of tabs:

Tab Name

Description

Matched

Lists hosts for which a match was found for the search expression.

Not Matched

Lists hosts that were searched, but for which no match to the search expression was found.

Not Responded

Lists hosts that have not yet responded to the search request. All hosts are initially in this category. As hosts respond, they are moved to the Matched and Not Matched tabs. Hosts listed on the Not Responded tab might be down or might still be performing the search.

Not Searched

Lists hosts for which the search was not applicable. A search is not applicable for a host endpoint when a search condition in the Enterprise Search is not valid for the host endpoint's operating system or is not valid for the version of the Trellix Endpoint Security (HX) xAgent running on the host endpoint.

If this tab does not appear in the search results, the search applied to all host endpoints in your enterprise.

Errors

Lists errors that were encountered during the search.

If this tab does not appear in the search results, there were no errors during the search.

Click on the ESerror.png icon next to a host name to see the item types affected by any malformed or unexpected data the search encountered on the host. Such search issues are common, but may mean that the host could not be fully searched for these item types. By default, the Endpoint Security (HX) records and reports up to ten unique issues caused by malformed or unexpected data during a search. This default can be changed using the hx server search issues items-limit CLI command. For more information, see the CLI Command Reference.

If you specified host mode, each tab contains a list of hosts. If you specified grid mode, the Matched tab shows the results in a grid, listing the requested Group By field values and grouping hosts that matched the search request by those values. See Understanding search modes.

Note

Search requests continue running even after all hosts have responded. They continue running until they are manually stopped or until they reach one of the search limits.

Timestamps in the Web UI are presented in UTC time.

In addition to reviewing search results on the Enterprise Search page, you can download them to a CSV file.

To download the results of an Enterprise Search to a CSV file:
  1. Select Enterprise Search in the Investigate section of the main menu in the Endpoint Security (HX) Web UI.

  2. Select the search request containing the search results you want to download.

  3. Select the tab of data you want to download (Matched, Not Matched, or Not Responded).

  4. Click the Download button (HX_Download.png).

    The results on the selected tab are download into a CSV file.

    Note

    The limit for search results displayed on the Web UI is 1,000 rows. The CSV file can contain more than 1,000 rows. However, the Matched and Not Matched CSV files will exceed 1,000 rows only if the 1,000 row limit is reached in the middle of processing. The Not Responded CSV file will show every host that did not respond to the search and, depending on the number of hosts searched, may regularly exceed 1,000 rows.