Creating a quick search

Prev Next

Follow the procedure in this section to start creating searches using the built-in search condition prompts. Search conditions are token strings constructed using tokens, operators, and values.

To create a quick search:
  1. Select Enterprise Search from the Investigate section of the main menu in the Endpoint Security (HX) Web UI.

  2. Click the plus sign (+) on the left side of the search bar and select a token from the drop-down list. See Search token reference .

    The drop-down list provides a filter area you can use to quickly locate your token. Start typing the token name. The tokens that match the characters you enter are shown.

  3. Select an operator button from the row at the bottom of the drop-down list. See Search condition operators .

  4. Supply the value or values for which you wish to search. No wild card characters are supported.

    Be careful to remove any trailing spaces in the values you specify. Enterprise Search does not remove these trailing spaces and your search may fail because of them. (HXEP-9325)

  5. Repeat the previous steps to add conditions to the search expression.

    Note

    When Japanese or Chinese characters are entered in the Enterprise Search bar using a Japanese or Chinese Input Method Editor (IME) in Firefox or Microsoft Edge, the cursor moves unexpectedly or starts the search before the search request is complete. (HXEP-6440)

    When you click at the end of the search string in the search bar, a message appears indicating which types of host endpoints can run the search. (ENDPT-7844 partial)

  6. Start the search. See Starting a search .