Filter tab

Prev Next

The NDR Search has a filter tab that allows you to filter query results. For example, you may have a set of results that correspond to all sessions between two hosts, for example, 192.168.1.11 and 192.168.1.14. You can filter this result set for sessions that are on destination transport port 23. When you add and apply a filter to an active search query, NDR updates the associated dashboard with an "active" filter status at the top of the dashboard.

To use the Filter tab to add a filter to your search query:
  1. Click Main_menu.png and from INVESTIGATION, select Search.

  2. click the Filters tab on the left of the dashboard.

  3. Click the arrow in the Operator field and select the operator you want to apply to your search filter: Must, Must Not, or Either.

  4. Click the arrow in the Term field and select the field filter you want to apply to your search.

  5. Enter the field term or value in the Value field.

  6. Check the Enable checkbox and click Apply.

Important

When using the Filter tab, you must click the Apply button at the bottom left of the Filter tab each time you add or modify a filter. This applies the new or modified filter to your NDR search query.