Search for historical data on multiple endpoints

Prev Next

The Historical Search capability enables you to search historical data across multiple endpoints. During the investigation, you can create and run a search query using artifact details such as malicious process name, IP address, file hash, process, device name, and command line, etc. for the activities in a specified time frame.

Under Historical Search, you can search data using either the Search with EDR QL method or the Search with Wise method. The dashboard caches your last used method so that when you return to Historical Search, your preferred option is retained. While using the Search with Wise method, each tenant is allocated a predefined quota based on the Trellix Wise subscription purchased for that tenant. See Quota management system for details.

For information about supported fields and logical operators on the Historical Search dashboard, see Supported fields and operations for the Historical Search.

  1. Log on to Trellix EDR.

  2. Go to MenuHistorical Search, select Search with Trellix EDR QL, Search with Wise, or import indicators of compromise (IOCs) file with hashes options as needed.

    Enter artifacts with details or import indicators of compromise (IOCs) file with hashes, and select a time period. Then click the search icon.

    Important

    The Search with Wise method allows you to construct queries with proper syntax based on the natural language input.

    In the Search with EDR QL method, parentheses determine operator precedence, allowing you to control the order of query execution. For example:

    DeviceName starts with "test" OR (ProcessName not contains "exe" AND CommandLine contains "exe")

    For details about importing IOCs file with hashes to hunt for a number of specific threats in a single search, see Import IOCs file to hunt for threats.

    The search result displays around 500 results on a page by default. You can use the filter option on every column to search data only on the displayed results. Scroll down to see the complete set of results, and then use the filter option to search data and get the required results.

    Note

    A total of only 10 requests/minute/tenant can be made including both search and export data requests.

    The empty query search is supported only for the time range of 4 hours. The maximum results displayed are 5000 and sorted by Detection Date in descending order.

    On the grid, you can hover over the column headers and click on the menu icon to perform these activities:

    • Pin Column — Pin a column to the left or right. You can click No Pin to unpin a column.

      This option is not available on Event Details.

    • Autosize This Column — Auto size a particular column.

    • Autosize All Columns — Auto size all columns.

    • Group by Trace Date — Group columns by trace date. You can use Un-Group by Trace Date to un-group the Trace Date column.

      You can group and ungroup all columns displayed on the grid except Event Details.

    • Reset Columns — Reset columns to the default view.

    • Filter... — Filter results within a column.

      The available logical operators and options for the Date type of columns:

      • Options — Equals, Greater than, Less than, Not equal, In range

      • Logical operators — AND and OR

      The available options and logical operators for the String type of columns:

      • Options — Contains, Not Contains, Equals, Not equal, Starts with, and Ends with

      • Logical operators — AND and OR

      Note

      On the Event details column, the filtering option supports only Contains and Not Contains.

      The available options and logical operators for the Numerical type of columns:

      • Options — Equals, Greater than, Less than, Not equal, In range, Greater than or equals, and Less than or equals

      • Logical operators — AND and OR

      The available options and logical operators for the Boolean type of columns:

      • Options – Equals and Not equals

    • Search... — Search and select column headers to add multiple columns to the grid.

      Trace Date, Artifact, Activity, Event details, Device Name, and Detection Date are the default columns displayed. However, you can add multiple columns to the grid using Search....

      In the event type columns, consider the column names as given below:

      • Process targetPid as Process Reattribution TargetPid

      • Process TargetTraceID as Process Reattribution TargetTraceID

      • Process Type as Process Reattribution Type

      • Process Status as Process Reattribution Status

    Note

    The EDRF Client generates a unique Agent ID for each endpoint. The interface displays the Agent ID only when the endpoint runs on the EDRF Client and is connected to the Endpoint Security (HX) server. The field remains blank if the endpoint is disconnected.

    For more details about filtering operators and sorting options in Device Search and Historical Search, see the Trellix Knowledge Base article, Filtering and sorting updates for Historical and Device Search Dashboards in the EDR - KB96644.

    You can also perform these activities on the grid:

    • Sort columns in ascending or descending order

    • Drag columns to set row groups

    • Move or rearrange columns to the left or right

    Click a Device Name to view device details and historical data.

    Option

    Description

    View device details

    Gives details of the particular device. From this pane, you can access View all historical data for this device.

    View all historical data for this device

    Device Search dashboard opens in a new window. It displays the device details for the time period selected.

  3. Click Export All to export data in .csv file format.

    The export data is based on the search criteria. The group by and filter options applied on the grid columns are not considered in the exported data.

    Note

    The maximum data you can download is 100K results.

You can use the historical data to analyze a threat by tracing its behavior from the past 4 hours to the maximum retention time.