Skip to main content

Exabeam SearchExabeam Search Guide

Search and View Anomalies

You can search anomaly events in any search mode available from the search bar. When you find an anomaly of interest, open the Event Details pane to view all the available fields, and if needed, build a query with their values.

To find all of the anomalies within a selected time range, select the Advanced search mode from the drop down menu under the search bar and enter the following query: alert_source: "anomaly". Then click Search.

To find specific types of anomalies, use the Anomalies fields available in the Basic search mode as follows:

  1. Select the Basic search mode from the drop down menu under the search bar. The query builder panel opens.

  2. Click the Anomalies tab.

    Anomalies-Search-Tab.png
  3. Click an anomaly field and enter a search value to begin building your query.

    Note

    By including an anomaly field in your query, search results include only anomaly events.

  4. Continue to build your query as needed, and then click Search.

    For information on building queries, see Basic Search.

    Anomaly-Search-Results.png

    For information about working with the search results, see Interact with Anomaly Search Results