Using lists in queries

Prev Next

You can create lists and use them in a query or share them with other NDR users in your network. This eliminates the task of entering individual IP addresses and domains in a query.

For example, you can create a list named “web_servers” and then search for any sessions for those hosts with a query such as destinationIPv4Address:web_servers.

Prerequisites

  • NDR software 1.2.0 and above

Creating lists

Values in a list must be the same type. Each value must be entered on a separate line in the list.

To create a list using the list manager in the Web UI:
  1. Click Main_menu.png and from CONFIGURATION, select Lists.

  2. Select +Add List.

  3. Enter the name for your list. The name must be alphanumeric with underscores and no spaces. For example, web_servers.

  4. Enter the terms for the list.

  5. Click Create List.

Shared lists

Lists can be shared among users with access to your NDR appliance. Shared lists cannot be shared with single or select individuals.

To create a shared list using the list manager in the Web UI:

  1. Click Main_menu.png and from CONFIGURATION, select Lists.

  2. Select +Add List.

  3. Enter the name for your list. A shared list's name must be unique across all users and must be alphanumeric with underscores and no spaces.

  4. Enter the terms for the list.

  5. Check the empty box next to Share list.

  6. Click Create List.

Querying lists

After you create a list, you can use it in a query after entering a field name. As you type the value of the field, you are prompted for a list name. After the query is executed, the values in the list expand in the query bar.

To query using a list in the Web UI:
  1. Click Main_menu.png and from INVESTIGATION, select Search.

  2. Enter a field name in the query bar.

    The field name will prompt with a list.

  3. Select the list that you want to query.

Shared lists are displayed to all users on the same NDR appliance when entering field names in the Query Bar. Your shared lists appear in a drop-down menu of lists shared in your NDR appliance. Shared lists are marked by a globe (Shared_ListQuery_Icon.png) icon.

Deleting or Editing Lists

To delete or edit a list using the list manager in the Web UI:
  1. Click Main_menu.png and from CONFIGURATION, select Lists.

  2. Select the gear icon next to the list you wish to edit or delete.

  3. Select Edit or Delete.

Existing, private lists can be edited and changed into shared lists and vice versa.

To make a private list a shared list using the list manager:

  1. Click Main_menu.png and from CONFIGURATION, select Lists.

  2. Click the gear icon and select Edit from the drop-down menu.

  3. In the List Setup window, check the empty box next to Share list.

  4. Click Update List. Your list is no longer private and can be accessed by others.