Entering Queries

Prev Next

You can search the session data for documents that match specific parameters with NDR tools that simplify query construction and execution. The Query bar makes it easy to enter query syntax and exceptions.

The Query bar will assist with query construction depending on the search mode you select. For information on how to change the search mode, see Query Bar modes.

Note

If you apply filters after running the initial query, you must click the search icon again to run the search with filters.

Important

When searching the field name mailTo or any string type field, the query is case sensitive. To ensure matches against indexed data, enter values in lowercase.

Entering queries in Context Sensitive Help mode

The Query bar's contextual help suggests syntax options for you to enter in your search. The time picker allows you to select a time range for you to search. Click the search icon in the Query bar to run a search.

To enter and run a search query while in Context Sensitive Help mode:

  1. Click inside the Query bar to view the list of syntax options allowed for a search. Hover your cursor over an option to reveal the explanation of the term.

  2. Click on or type the syntax you want in the Query Bar and enter a value.

  3. Press Enter to accept and apply your query syntax. If your query has exceptions, press Esc and Enter to accept and apply the query syntax and exceptions.

  4. Use the time picker to select a start and end time for your search.

  5. Click the search icon in the Query Bar to run your search.

  6. (Optional) Apply additional query syntax or filters to your query using the filter options described in Filtering.

  7. Click the search icon to run your search with filters.

Entering queries in Default mode

The Query bar's automatic completion feature helps with query construction by creating Structured Pills for you. The time picker allows you to select a time range for your search. Click the search icon in the Query Bar to run a search.

IA Search Bar.png

To enter and run a search query while in Default mode:

  1. Type your query or click inside the Query bar to select a fieldname. NDR automatically completes a Structure-Pill for you.

  2. Click Enter to accept and apply your query syntax. If your query has exceptions, press Esc and Enter to accept and apply the query syntax and exceptions.

  3. Use the time picker to select a start and end time for your search.

  4. Click the search icon in the Query Bar to run your search.

  5. (Optional) Apply additional query syntax or filters to your query using the filter options described in Filtering.

  6. Click the search icon to run your search with filters.

Entering queries in Expert mode

In Expert mode, the Query Bar has no contextual help and does not automatically complete syntax for you. You should be familiar with Elasticsearch syntax to use Expert mode.

To enter and run a search query while in Expert mode:

  1. Type your query inside the Query Bar.

  2. Click Enter to accept and apply your query syntax. If your query has exceptions, press Esc and Enter to accept and apply the query syntax and exceptions.

  3. Use the time picker to select a start and end time for your search.

  4. Click the search icon in the Query Bar to run your search.

  5. (Optional) Apply additional query syntax or filters to your query using the filter options described in Filtering.

  6. Click the search icon to run your search with filters.