Field names correspond to the names of indexed metadata fields, extracted in real time, from network traffic captured by connected PX appliances.
In Default mode, NDR uses Structured-Pills in the Query Bar to contain query syntax. This syntax consists of a field and term or a field and value. The Structured-Pill also applies any conditions or exceptions associated with the field name or included in the query syntax. For example, the Structured-Pill below contains a sourceTransportPort field with a value of 80.
Note
You must click outside of the structured-pill to register the query. If the structured-pill is not registered, the query will fail.
In Context Helpmode, NDR provides a list of field names when you click inside the Query Bar. When you begin typing a field, the list with contextual help automatically narrows recommended results based on what you type. For example, when you begin typing "app" in a blank field, the list of contextual field names shortens to nine selectable fields.
Selecting a field name prompts you to immediately enter a value for that field. In Context Help mode, you are prompted to enter syntax in the following order: Field, then value. Syntax does not appear in Structured-Pills.
In Expert mode, successful queries depend on your knowledge of Elasticsearch standards. The Query Bar does not automatically organize syntax or notify you when a field or value is incorrectly entered.