Use the Enterprise Search feature to search all the host endpoints in your enterprise for specific threat indicator rules. Results are returned quickly for quick searches, skipping locations that are time-consuming and costly to search. However, if the quick results are insufficient, you can expand the search to include skipped locations (this is called an exhaustive search).
Note
Enterprise Search queries can only be performed for Windows and macOS endpoints, and Linux endpoints running Endpoint Security (HX) Agents version 34 or later.
Be sure to stop all Enterprise Search queries prior to performing an appliance upgrade. Running Enterprise Search queries at the same time as an appliance upgrade can impact the performance of the upgrade.
Quick search queries for a very specific piece of data result in a list of hosts that match the query. You can group the list of hosts returned by the query, and see how many hosts match the query as well as how many times results were found on each host.
Exhaustive search queries are more in-depth queries with more options, and consequently take longer to perform than quick searches. These searches require the agent on the host to perform a more complete search. In some circumstances, the agent will not regularly capture all the data you need. For example, not all registry activity is regularly captured by agents. You can request an exhaustive search of the registry to ensure that the entire registry is searched.
An example of a quick search query is a query for all the browsers used in your enterprise. An exhaustive search example is a query for the paths on every host in your enterprise where a specific MD5 file is found.
This part covers the following topics:
Note
The Endpoint Security (HX) Web UI inactivity timeout period is ignored if an active Enterprise Search is running and the Enterprise Search page is left open in the browser. (HXEP-6175)