When you are investigating or hunting for a threat on managed endpoints, you can search for real-time data using search expressions or queries on the real-time search dashboard. This helps you to search for current processes and events happening on endpoints in real-time.
Log on to Trellix EDR.
Select Menu → Real-time Search.
Select Search with Trellix EDR QL, or Search with Wise. Select a time period, and click Apply.
Note
The Real Time Search dashboard allows you to cache the previously used search method, ensuring that when you navigate back to the Real Time Search dashboard, your preferred search method is retained.
Each tenant is allocated a predefined quota limit based on the Trellix Wise quota purchased for that specific tenant. For details, seeQuota Management System..
In the Search box, enter a search expression.
For details about real-time search syntax to create powerful expressions, see Real-time Search syntax.
For real-time search expression examples, see Real-time Search examples.
Important
The Search with Wise method allows you to construct queries with proper syntax based on the natural language input.
In the Search with EDR QL method, parentheses determine operator precedence, allowing you to control the order of query execution. For example:
DeviceName starts with "test" OR (ProcessName not contains "exe" AND CommandLine contains "exe")
Click the search icon to start collecting data from managed endpoints.
On the grid or results table, you can hover over the column headers and click on the menu icon to perform these activities.
Pin Column — Pin a column to the left or right. You can click No Pin to unpin a column.
.png)
Reset Columns — Reset columns to the default view.
Filter... — Filter results within a column.
The available logical operators and options for columns:
Options — Contains, Not contains, Equals, Not equal, Starts with, and Ends with
Logical operators — AND and OR
.png)
Search... — Search and add or remove available columns to the grid.
.png)
You can also perform these activities on the grid:
Sort columns in ascending or descending order
Move or rearrange columns to the left or right
Drag column headers to set row groups
Example: You can drag and drop column headers to the row highlighted below to group by Hostname and Status of a file currently available or deleted.
.png)
Note
Real Time Search queries that rely on script execution returns empty results if endpoint security policies restrict script execution. Such restrictions can block scripts executed by Trellix EDR system processes. This can occur with Trellix Endpoint Security (ENS) or any other endpoint security solution that enforces script control policies. Ensure that required processes are allowed to execute scripts to avoid incomplete results.
Click Export All option to export the results from a real-time search to a .csv file to analyze it offline using other third-party tools.