Events Search
Overview
The Events Search tool, available from version 8.3.0, provides the capability to search events collected and stored in Snare Central, for fast troubleshooting and forensic analysis.
Both Basic and Advanced search options are available. The user can save a query for future re-use, view the search history, and view results of recent queries. An intuitive graphical interface can interactively filter search results by Time, Log Type and System.
Basic Search
Basic Search selectors allow the user to easily define search criteria.
Basic Search Selectors
Date and Time | Search for events within a given date and time range. Date and Time search criteria can be defined using either Quick Picks or using a custom Date and Time. |
Systems | Search results can be narrowed by selecting systems that generated the events. By default, all systems will be included in a search. Click the selector and use check boxes to choose systems of interest. Use the filter to quickly find a system by host name or IP address. |
Log Types | Search results can be narrowed by selecting Log Types. By default, all log types will be included in a search. Click the selector and use check boxes to choose from available log types. Use the filter to quickly find a log type. |
More Fields | Search for text that appears in specific event fields by clicking the More Fields selector. A filter can be used to quickly find a field of interest. Click > to reveal an input field, and enter your search criteria in the field. Multiple values are supported. |
Text Search | To search for content in any event field, use the Text Search input field. |
Additional Search Options
Check the Override Timeout checkbox to override the default query timeout of 5 minutes. Note: Status indicates that the search time out has been reached, and the search results returned may only represent a subset of the potential results stored on the Snare Central server. It is recommended that search criteria be refined in order to reduce the range of data to be searched. | |
Check the Override Limit checkbox to override the default limit of 100,000 events in query results. Note: the search will stop executing when the Limit is reached, however due to a parallel nature of execution it is possible that more results will be returned than the configured Limit. | |
Check the Case Sensitive checkbox to make text and fields search case sensitive. | |
Check the Exact Match checkbox to make text and fields search match the content of the whole field. Click on information icon that opens below information box |
Available Actions
Click to run the search.
Click to clear the query and the selectors.
Click Query Preview to view the query in Snare Query Language.
Click to edit the query in Advanced Search mode.
Click to switch from Basic to Advanced Search.
Click to read more information about search options and their performance
Advanced Search
Advanced search allows to write and edit a search query using the Snare Query Language. This allows complex queries to be specified, including complex conditions and regular expressions.
Additional Search Options
Check the Override Timeout checkbox to override the default query timeout of 5 minutes. Note: Status indicates that the search time out has been reached, and the search results returned may only represent a subset of the potential results stored on the Snare Central server. It is recommended that search criteria be refined in order to reduce the range of data to be searched. | |
Check the Override Limit checkbox to override the default limit of 100,000 events in query results. Note: the search will stop executing when the Limit is reached, however due to a parallel nature of execution it is possible that more results will be returned than the configured Limit. |