Fields

Prev Next

Field names correspond to the names of indexed metadata fields, extracted in real time, from network traffic captured by connected PX appliances.

In Default mode, NDR uses Structured-Pills in the Query Bar to contain query syntax. This syntax consists of a field and term or a field and value. The Structured-Pill also applies any conditions or exceptions associated with the field name or included in the query syntax. For example, the Structured-Pill below contains a sourceTransportPort field with a value of 80.

Note

You must click outside of the structured-pill to register the query. If the structured-pill is not registered, the query will fail.

In Context Helpmode, NDR provides a list of field names when you click inside the Query Bar. When you begin typing a field, the list with contextual help automatically narrows recommended results based on what you type. For example, when you begin typing "app" in a blank field, the list of contextual field names shortens to nine selectable fields.

Selecting a field name prompts you to immediately enter a value for that field. In Context Help mode, you are prompted to enter syntax in the following order: Field, then value. Syntax does not appear in Structured-Pills.

In Expert mode, successful queries depend on your knowledge of Elasticsearch standards. The Query Bar does not automatically organize syntax or notify you when a field or value is incorrectly entered.