Skip to main content

Exabeam SearchExabeam Search Guide

Event Details

For any event in the search results, you can open an Event Details panel. The panel opens on the right with the Event tab displayed. It includes the full raw message of the event and the entire list of parsed fields for that event.

Accessing Event Details

To access Event Details from different results views:

  • List View – Click View all fields in the upper right corner of an event row.

  • Table View – Click on the event row.

event-detail-panel-norules.png

Note

If an event does not specify a time zone, the time in the parsed fields is reported in the local time zone. In the raw log message, the time remains as is.

You can scroll through the events in the panel and expand and collapse different sets of event details by clicking on the events. Click on an event to expand it and click it again to collapse it. In this way you can scroll through all of the grouped events without leaving the Event Details panel. When expanded, each event is displayed with a raw log message and a list of parsed fields.

event-details-group-noinsights.png

Interacting with Event Details

You can interact with Event Details information in the ways described below.

  • Use the SearchResultsPrevNextEvent.jpg icons at the top of the panel to navigate between result events.

  • Click the SearchCloseEventDetailsIcon.jpg icon to close the Event Details panel and return to the Search results.

  • Use the Search field at the top of the panel to search both the raw message and the list of parsed fields.

  • Use the arrow (collapse-log.png) icon in the top right corner of the Raw Log section to collapse and expand the log line.

  • Click the Copy Raw Log to Clipboard icon (Copy-Raw-Log.png) in the Raw Log section to copy the log line. This icon is only displayed when you hover your cursor over the Raw Log section.

  • Click the SearchHideFieldInListIcon.jpg icon next to any field in the PARSED FIELDS list, to toggle the field visibility on or off in the search results. Toggling the visibility also changes whether or not the field is displayed in parsed fields on the Timeline view of results and in the columns on the Table view of results.

  • Click the enrichment indicator icon (for example: icon-enriched-field.png) next to any field that contains enriched data to display an enriched field tooltip. The tooltip explains the type and source of the enriched data.

    field-enriched-tooltip.png
  • To display additional options for each field in the list, click the drop-down menu icon (PM-ThreeDotMenu.jpg) that appears when you hover your cursor over a field row.

    field-options.png

    Depending on whether or not the field was included in the original query, the options below are available:

    • Use the AND, AND NOT, or OR operators to add the field to your query.

    • Click Remove to remove the field from your query. (Available only for fields that are already included in the query.)

    • Click Copy to copy the value of the field to the clipboard.

    • Click Visualize Field to pivot immediately to the Dashboard app, where you will be presented with the visualization editor view with the information from your search query preconfigured.

      event-detail-fields-menu.png