Saved Queries Dialogs

Saved Queries offer a quick and easy way to define a meta group, column group, and a limiting filter (pre-query condition) that you can apply in the Navigate view, the Events view, and the Legacy Events view (see Use Saved Queries to Encapsulate Common Areas for Investigation). The same saved queries are shared between all views, and they are available in the Springboard (Version 11.5) for use in panels. Private saved queries created in the Events view are only available in the Events view for the analyst who created them.

Each query profile specifies a meta group, column group, and sometimes includes a pre-query condition appropriate for the type of investigation.

In a saved query:

You can manage profiles in the Manage Profiles dialog,  the Create Saved Query dialog and the Saved Query Details dialog.

  • The Manage Profiles dialog is for the Navigate view, the Legacy Events view (Version 11.4 and later) , and the Events view (Version 11.3 and earlier). To access this dialog, select Profile > Manage Profiles in the Navigate or Legacy Events view toolbar.
  • The Create Saved Query dialog is for the Events view. To access this dialog, select Saved Queries > New Saved Query in the Events view query bar.
  • The Saved Query Details dialog is for the Events view. To access this dialog, select Saved Queries in the Events view query bar, then click the edit icon (netwitness_cgediticon.png) next to a custom profile name.

Related Topics

Quick Look - Saved Queries Menu, Create Saved Query Dialog, and Saved Query Details Dialog

This section introduces the Saved Queries menu, Create Saved Query dialog, and the Saved Query Details dialog. The following figure is an example of the Saved Queries menu and the table describes the options. The example on the left has built-in saved query highlighted so that the information icon is visible.

 

query_profile_referencetopic.png

Feature Description
Visibility Options Control the types of query profiles that are visible in the list. You can use any combination of the visibility options: Private, Shared, or RSA (blue = selected, black = not selected). Initially none of the buttons are selected and all profile types are visible. This is the same result as if all three buttons are selected. The visibility options work together with text in the Filter Query Profiles field. If the visibility option is hiding built-in profiles (which include "RSA" in the name) and you search for a name that contains "RSA," the list is empty.
Private = display private groups that only you can manage
Shared = display shared groups that anyone in your organization can manage
RSA = display built-in groups that only RSA can manage
Filter saved queries Filters the list of saved queries as you type text so that only profile names that contain that text are displayed.
Saved Query List The list of queries consists of custom and built-in profiles, which are distinguished by the icons that precede the name. In the example, RSA Email Analysis-1 and RSA Email Analysis-2 are custom profiles. The RSA Email Analysis is a built-in profile.
New Saved Query Displays the  Create Saved Query dialog, where you can create a custom profile.

The Create Saved Query dialog, shown in the figure on the left, allows you to define a  custom saved query. The figure illustrates the Saved Query Details dialog, in which you can edit a custom saved query. The table describes the fields and options in the dialogs

query_profile_referencetopic_2.png

Feature Description
netwitness_cloneicon.png Creates a clone of the meta group so that you can edit a copy. This is useful if you want your own copy of a built-in group, a shared copy of a private group, or a private copy of a shared group.
netwitness_cgdeleteicon.png Deletes the custom profile in the Saved Query Details dialog. This action is irreversible and applies globally; the profile is no longer available to anyone who is using the profiles on this service.
Saved Query Name Displays the name of the profile. The name must be unique and contain fewer than 64 characters. You can edit the name in a custom profile.
Column Group Displays a drop-down menu listing available column groups, with the currently selected column group from the Events list already selected. You can change the column group in a custom profile.
Pre-Query Conditions Defines a limiting filter for results in the Events view. If you had a query active in the query bar when you began to create the new profile, the active query is added to the pre-Query field. In a custom profile, you can delete the prepopulated pre-query condition and type additional text for a text search or additional filters in the Pre-Query Conditions field. This is an example of a pre-query condition:
'service=80,25,110'.

Close button

Closes the dialog.

Save Saved Query For the Create Saved Query dialog only, saves the new query.

Reset

For the Saved Query Details dialog only, reverts the edited profile to the last saved state.

Update Saved Query

For the Saved Query Details dialog only, applies changes to an edited query.

Select Saved Query

Applies the saved query.

Quick Look - Manage Profiles Dialog

This is an example of the Manage Profiles dialog showing several profile groups.

netwitness_profgrpnam.png

The Profile panel on the left side of the dialog displays available profiles and allows you to add, delete, import, and export profiles. The following table describes the fields in the Profile panel.

Field Description
netwitness_add.png Adds a new profile using the Settings panel on the right side of the Manage Profiles dialog.
netwitness_delete.png Deletes the selected profile. A confirmation dialog is displayed before the profile is deleted.

netwitness_ic-duplicate.png

Creates a copy of the selected profile.

netwitness_ic-import.png Displays the Profile Import dialog, where you can upload a file.
netwitness_ic-export.png Exports the selected profile to your computer.
Profile Name Lists all profile names.

The Settings panel on the right side of the dialog offers options to configure profiles. It can only be used when one profile is selected. The following table describes the fields in the Settings panel.

Feature Description
Name Displays the name of the profile.
Meta Group Displays a drop-down menu listing available meta groups.
Column Group Displays a drop-down menu listing available column groups. The OOTB column groups and these three groups are available by default:
  • List View
  • Detail View
  • Log View
PreQuery Defines a limiting query for filtering Investigate results. This query is used when the associated profile is activated and the preQuery applies to any queries used in the Navigate and Events views. This is an example of a preQuery:
'service=80,25,110'.

The following table describes the buttons.

Field Description
Close Closes the dialog.
Cancel Cancels all changes.
Save Saves all changes.
Save and Apply Saves and applies all changes immediately.