Search operators are available to the analyst.
Search operators are case-sensitive!
- To check for traffic between the specific search and destination IPs:
src:”18.104.22.168” AND dest:”22.214.171.124”
- To check for traffic from a specific user:
- To check if there’s a user who ever logged in from a specific IP:
src:”126.96.36.199” AND _exists_:user_uuid
- To check if there’s a user who ever logged in to a specific IP (based on their AD authentication information mostly):
dest:”188.8.131.52” AND _exists_:user_uuid
- To find all logs from a user excluding connection logs:
user_uuid:someuser AND – entry_type:Connection
- To inspect all connections from a specific client User Agent pattern:
Operators and modifiers
field1:(term1 AND term2)
field1:(term1 OR term2)
Any single character
We do not recommend using the wildcard operator when searching for IP Addresses. Instead, use the TO operator to search for a range of IP Addresses.
[1 TO 10]
Use the TO operator to search for a range of IP Addresses: [IPaddress TO IPaddress].
For example: [184.108.40.206 TO 220.127.116.11]