Skip to main content

Exabeam SearchExabeam Search Guide

Event Details

For any event in the search results, click View all fields to display an Event Details panel. The panel includes the full raw message of the event, along with the entire list of parsed fields for that event. You can interact with the Event Details panel in the ways described below:

Note

If an event does not specify a time zone, the time in the parsed fields is reported in the local time zone. In the raw log message, the time remains as is.

event-detail-panel.png
  • Use the Search field at the top of the panel to search both the raw message and the list of parsed fields.

  • Use the SearchResultsPrevNextEvent.jpg icons at the top of the panel to navigate between result events.

  • Click the SearchCloseEventDetailsIcon.jpg icon to close the Event Details panel and return to the Enhanced Search homepage.

  • Click the SearchHideFieldInListIcon.jpg icon next to any field in the PARSED FIELDS list, to hide/show the field in the search results.

  • Click the enrichment indicator icon (for example: icon-enriched-field.png) next to any field that contains enriched data to display an enriched field tooltip. The tooltip explains the type and source of the enriched data.

    field-enriched-tooltip.png
  • To display additional options for each field in the list, click the drop-down menu icon (PM-ThreeDotMenu.jpg) that appears when you hover your cursor over a field row.

    field-options.png

    Depending on whether or not the field was included in the original query, the options below are available:

    • Use the AND, AND NOT, and OR operators to add the field to your query.

    • Click Remove to remove the field from your query. (Available only for fields that are already included in the query.)

    • Click Copy to copy the value of the field to the clipboard.

    • Click Visualize Field to pivot immediately to the Dashboard app, where you will be presented with the visualization editor view with the information from your search query preconfigured.

      SearchAddFieldToQueryDropDown.png