- Get Started with Threat Center
- Group Detections
- Work on Cases
- Triage Alerts in Threat Center
- Edit and Collaborate in Threat Center
- Find Cases or Alerts
- Build a Search in Threat Center
- Enter a Search Using Exabeam Query Language in Threat Center
- Enter a Search Using Natural Language in Threat Center
- Run a Recent Search in Threat Center
- Create a New Saved Search in Threat Center
- Run a Saved Search in Threat Center
- Edit a Saved Search in Threat Center
- Delete a Saved Search in Threat Center
- Sort Cases or Alerts
- View Case and Alert Metrics
- Get Notified About Threat Center
Enter a Search Using Natural Language in Threat Center
To quickly create complex searches without knowing Exabeam Query Language, type out a search query using natural language.
Like natural language search in Search, you enter a search prompt using everyday, conversational language and full sentences, as if talking to another human; for example, Return all threats related to IP address 1.1.1.1.
After you enter your natural language search prompt, Threat Center uses AI to convert it into Exabeam Query Language syntax; for example, dest_ip:"1.1.1.1" OR src_ip:"1.1.1.1". The more you use it, the better the AI becomes at generating a query that accurately captures what you're searching for.
After you see the converted query in Exabeam Query Language syntax, you can refine the natural language prompt or the Exabeam Query Language query to return your desired search results.
Enter a Search for Cases
Navigate to the Cases tab, then in the Search mode menu, select Natural Language.
In Type your natural query..., enter a search prompt. After a few seconds, the prompt is converted into Exabeam Query Language syntax and appears in Your query in EQL will appear here. If you mention a time range in your prompt, it's automatically reflected in the time range menu.
To refine your search, edit the prompt or the Exabeam Query Language query.
Click Search.
Enter a Search for Alerts
Navigate to the Alerts tab, then in the Search mode menu, select Natural Language.
In Type your natural query..., enter a search prompt. After a few seconds, the prompt is converted into Exabeam Query Language syntax and appears in Your query in EQL will appear here. If you mention a time range in your prompt, it's automatically reflected in the time range menu.
To refine your search, edit the prompt or the Exabeam Query Language query.
Click Search.