You can create lists and use them in a query or share them with other NDR users in your network. This eliminates the task of entering individual IP addresses and domains in a query.
For example, you can create a list named “web_servers” and then search for any sessions for those hosts with a query such as destinationIPv4Address:web_servers.
Prerequisites
NDR software 1.2.0 and above
Creating lists
Values in a list must be the same type. Each value must be entered on a separate line in the list.
Click
and from CONFIGURATION, select Lists.Select +Add List.
Enter the name for your list. The name must be alphanumeric with underscores and no spaces. For example, web_servers.
Enter the terms for the list.
Click Create List.
Shared lists
Lists can be shared among users with access to your NDR appliance. Shared lists cannot be shared with single or select individuals.
To create a shared list using the list manager in the Web UI:
Click
and from CONFIGURATION, select Lists.Select +Add List.
Enter the name for your list. A shared list's name must be unique across all users and must be alphanumeric with underscores and no spaces.
Enter the terms for the list.
Check the empty box next to Share list.
Click Create List.
Querying lists
After you create a list, you can use it in a query after entering a field name. As you type the value of the field, you are prompted for a list name. After the query is executed, the values in the list expand in the query bar.
Click
and from INVESTIGATION, select Search.Enter a field name in the query bar.
The field name will prompt with a list.
Select the list that you want to query.
Shared lists are displayed to all users on the same NDR appliance when entering field names in the Query Bar. Your shared lists appear in a drop-down menu of lists shared in your NDR appliance. Shared lists are marked by a globe (
) icon.
Deleting or Editing Lists
Click
and from CONFIGURATION, select Lists.Select the gear icon next to the list you wish to edit or delete.
Select Edit or Delete.
Existing, private lists can be edited and changed into shared lists and vice versa.
To make a private list a shared list using the list manager:
Click
and from CONFIGURATION, select Lists.Click the gear icon and select Edit from the drop-down menu.
In the List Setup window, check the empty box next to Share list.
Click Update List. Your list is no longer private and can be accessed by others.