Overview
The NDR appliance Web interface has three separate search modes with powerful search capabilities that allow you to find indexed metadata for supported protocols. The following section describes how to construct basic and advanced search queries against these metadata fields using Boolean operators, terms and values, and special characters.
Supported protocols
The NDR query syntax follows a set of guidelines for constructing queries, searching indexed metadata fields for specific terms and values, and using filters to refine search results. A search of indexed fields for specific terms, values, or both are supported for the following protocols:
HTTP
DNS
TLS
FTP
SSH
SMTP
IMAP
POP3
MSN
MODBUS