Running a guided query of event records
To run a guided query of event records:
-
Go to Investigations > Investigate and select an investigation from the list.
-
Click View Results to view the investigation results.
-
Right click on an entity to open the context menu and select Guided Queries.
- Select a guided query from the list. If the event record has matching variables in the query , then the variables will be populated with values from the event record.
-
Add or modify the values for the variables.
- Create a new investigation or add the guided query to an investigation.
Create a New Investigation Select this option to create a new investigation. Enter the Investigation Name and Description.
The default name for new investigations is the first and last name of the user creating the investigation as well as a date stamp of when the investigation was created.
Add to Existing Investigation
From the Choose Investigation dropdown, select and investigation.
-
Click Run Guided Queries.