Test the Historical Search module

Prev Next

After the module is configured, verify that it is working correctly by performing a search.

  1. Navigate to the MenuHistorical Search.

    Note

    For Endpoint Security (HX) version 10.0.5 or later, it is in the Investigate section of the main menu.

  2. Perform a test search:

    1. Set the time range: The search defaults to the Last 24 hours. To change this, click the Time Range, select a different time period, and click Apply.

    2. Enter the query: To see the latest events from all devices, enter the following query in the search field:

      host:*
    3. Click Search.