Queries and Filters

Stellar Cyber Academy icon Learn more at Stellar Cyber Academy.

The following link takes you to a course on the Stellar Cyber Academy technical training portal where you can learn more about this topic by watching the suggested lessons.

The first time you access a link on the portal during a session, you must log in to access content.

The Query and Filter Manager (System | Saved Objects | Queries and Filters) is organized into tabbed sections with each section consisting of a table and a builder for queries or filters:

  • Queries table

    The table displays previously configured queries and displays columns for each query name, tenants for which the query is available, query conditions, and (not shown by default) description. It also shows when the query was created and updated and by whom. There's a column showing where the query is in use and an Actions column with options to Edit and Delete it.

    The In Use column identifies how many features are using a query before you consider modifying or deleting it. An entry of zero indicates a query is not in use. Hovering your cursor over a usage count causes a pop-up panel to appear with a list of all the features that are using it. Any change you make to a query affects all associated features. If you want to delete a query, you must first remove it from all associated features.

  • Alert Filters table

    The table displays previously configured alert filters and displays columns for each filter name, tenants for which the filter is available, filter conditions, and its status as active or inactive. It also shows when the filter was created and updated and by whom and any notes about the filter and who wrote them. There's a column showing the hit count, which indicates the number of alerts that have been suppressed by the filter, and an Actions column with options to Edit and Delete the filter.

  • Case Filters table

    The table displays previously configured case filters and displays columns for each filter name, the tenant for which the filter is available, filter conditions, and its status as active or inactive. It also shows when the filter was created and updated and by whom. The Description column can contain information about the purpose, usage, and other relevant details of a case filter—making it easier for you to recall its intent later and enabling other users to understand its function and context. There's also an Actions column with options to Edit and Delete the filter.

  • Query and filter builder

    The query and filter builder is a robust tool that not only lets you construct complex searches and exclusion filters—as the query builders and filter builders on individual feature pages also do—but it also includes Run, Test and Save As functions. The Run option for queries lets you test queries before applying them, ensuring you get expected results before leaving the page. The Test option provides the same functionality as the Run option but it's for testing alert filters and case filters. The Save As function lets you make copies of queries and filters and adjust settings, working on up to ten variations in tabbed dialog boxes simultaneously.

Queries, alert filters, and case filters are constructed using similar components from the Lucene search engine library. They are covered in the main sections below: