Pivoting from event data

Prev Next

After completing a search, you may find data of interest within a parsed field of an event in your search results. You may want to refine your search or run a new search for the same data in other events. When events appear in the search results, the parsed fields provide pivoting and drill-down options. Pivoting through data is how you add context to an event so you can determine what to do next.

To pivot from event data:
  1. From the main menu, select Investigate > Alerts and open an alert.

  2. Click the down arrow (downarrow_pivotmenus.png) next to a field value in the Most Recent Event area of the alert details or on the Events tab of the alert details.

Helix_PivotFromEventData.png

One or more of the following pivot and drill-down options are available.

Option

Description

New search

To search for the same field and data in other events, select New search. A new query appears in the Search box, which you can either run as is or modify.

Add to current search

To add another field and data to the current query in the Search box, click Add to current search.

Exclude from current search

To add a field and data to the current query as a “not” statement, click Exclude from search.

Group by field

To use a field and its data in a groupby clause in the current query, click Group by field.

Add to List

To add the data of a field to a Helix Enterprise list, click Add to list. In the Add to List dialog, select the list to which the data should be added.

Copy to clipboard

To copy the field and its data to the clipboard for use in another application or for your notes, click Copy to clipboard.

Query VirusTotal

If the type of data in the field is an IP address, domain, or hash, click Query VirusTotal to link to the VirusTotal website and view the VirusTotal information for the field value.

Query DomainTools

If the type of data in the field is a domain, click Query DomainTools to link to the DomainTools website and view the DomainTools information for the field value.