Using search results

Prev Next

The results for an index or archive search query appear on the Search page as a list of events. Each event includes both the raw event data and the parsed fields, if applicable. Parsed fields have pivoting options. By default, event data is sorted in the results by the date and time the data arrived in Helix Enterprise.

You can also view data results on a timeline by clicking Show Timeline at the top of the search results.

After finding results, you can open the Filters slider to access options that will help you use your search results more efficiently.

  • Layout. Select whether you want to view your results as a Table or List.

  • Page Size. By default, Helix Enterprise displays ten search results per page. To change the number, click Page Size and select how many results you would like to see per page.

  • Highlight Raw. To see the fields that matched the search query, select this checkbox.

  • Geo. Helix Enterprise uses data from the srcipv4 and dstipv4 fields in events. If there is no srcipv4 or dstipv4 data, then Helix Enterprise uses data from the srcipv6 and dstipv6 fields in events. To display the geographical information for an event, such as the destination country, destination IP, or destination domain, click Geo.

  • Meta. To see the metaclasses in the events, click Meta.

  • Sort. The events in the results are sorted by the newest first. If you view Index Search results as a list, you can reverse the order by selecting Oldest for the Sort option. The date that Helix Enterprise uses is the date and time that the event arrived into Helix Enterprise (which is also used in the query). If you are viewing the results in a table, you can select the field you want to sort by from the drop-down menu. You can also click on the heading for a column to search in ascending or descending order.

  • Show. By default, all search results are shown. To view only specific events, select the events in the search results (by checking the box next to the events) and choose Selected for the Show option. The Visible and None options for Select also change the events displayed.

  • View. You can see all the results, which may include both raw events and parsed events, or you can show just one or the other. Select an option for View.

  • Density. If you are viewing the results in a table, you can adjust the appearance of the search results. Choose either Compact or Comfortable from the drop-down menu.

Note

If you think results are missing, check the tooltip under the Search box to see if the results have been limited.