Search Results
Enter your search in the search bar. Use a Search Template, a Search Template from a Search Package, or create your own query.
After search, use the results to:
Drill down and understand the details.
View the top fields or values found or identified in your search query in Interesting Fields.
Get search result statistics.
Save the Search for future use, either by itself or as part of a Search Package.
Visualize your search data as a dashboard, widget, or a graph.
Add a new Alert Rule based on the search results to create a detection.
Create a new Labelling Rule.
Add the search results to an Incident to respond to.
Share through a report.
Share results outside of Logpoint through a Public URL.
Export raw logs of search results.
Live searches update dashboard widgets and search results in real-time. The more dashboards you have open when performing a search, the more power is required. If you want faster search performance, turn off live searches. If you do, Logpoint will calculate and store dashboard data ahead of time and reuse the data to speed up the time it takes to perform a search. When you want to view live search results, then turn it on again.
Results

After you run your query, the total number of results is displayed under the Search Bar in Found. This number can dynamically change based on how fast the query runs. Select a value from the drop-down to view the specified number of logs per page. The default value is 25.
Histogram & Charts
The search histogram displays search data graphically. It is located at the top of Logpoint Search. When you hover the mouse over a histogram column you get the timestamp and the log count. You can hide the histogram by default, or show it. Be aware if there are a large number of logs, results are sorted into time buckets, and those time buckets will add more time for your query. If you hide it by default, you get search results much faster. The histogram is only hidden, you can always view it by clicking the arrow to expand it.

Charts
Dashboard widgets and search result visualization display log data as a chart or a time chart. The data in the widgets reflect search query results for charts and time charts, with timecharts displaying data according to time buckets. A chart also includes a list of result details, and time charts include a table with search details.
To view your data as a chart or timechart, you need to use aggregators in your search query. How you use the aggregators depends on your search and how you want to visualize the results. Which chart or timechart is displayed depends on the search itself, and you can switch between charts depending on the search data results.
After you run a search, you get the results as a chart or a histogram. Depending on the query and the aggregators used, you can change the search visualization.
Drilldown
After performing a search, you can drill down on the results. Click:
Histogram or chart data to drill data.
Key in the Key-Value pair add the key as a filter to the original query. Query results are updated.
Value in the Key-Value pair to add the value as a filter to the original query. Query results are updated.
Arrow next to the Value in the Key value Pair to view.
Raw Log message to add the value to the original query. Query results are updated.
Histogram & Chart Drilldown
When you click on one of the Histogram columns, you get:
Filter that contains:
Range, or the drilldown data's period of time. Range is only displayed when the query contains the
timechart.count() or total number of logs.
View Logs: to view the logs searched. View them in the drilldown or click the open in new window icon to open a new browser window with the logs.
Drilldown by is the field used in the search.
Top 10 drilldown by the labels used in the search.

You can combine multiple key-value pairs or raw logs highlighted in the results and apply them as filters.
Example: To view successful login events for user [email protected] from IP 192.168.2.20
Click the successful login in the action field
Click the user [email protected].
Click IP: 192.168.2.20. The selected value(s) are added to the query bar.
The drill-down for search applies to the filesystem, Logpoint, and localhost, all of which are included in the search.

You can also remove a key value pair or raw log from a search drilldown. Select the key value pair or raw log and then press the Shiftkey. For example, deselecting the filesystem field for the query “col_type” = “filesystem” removes filesystem from the search results.

You can apply filters to view specific details of the search data results or the entire database. Click the drop-down next to the key value pair to view:
Top 10 Fields
Time Trend for Fields
Time Trend for Full Resultset or the collection of data retrieved from the search query.
You can also use drilldown in a search template, or move from your search results and view more details in the search template. Click the arrow next to the key value pair to expand, and then click Explore in Search Template. You are redirected to the search template with the selected value filled in.

You can also exclude a key value pair using the Exclude Fields.
If there are key value pairs that are encrypted using Data Privacy, you can request to view them if you do not have access. If your request is granted, you can now view the fields.

Interesting Fields
A field is the key in the key value pair that identifies the value in a normalized logs key value pair. They are the value identifier, or identifier names given to normalized values.
Interesting Fields are the top fields or values found or identified from your search query. After you perform a search using a Simple Search One to One and Filtering Commands, the top 15 fields found most often are listed at the bottom-left.
When you are performing a search, and it the results are taking time to load, there will be a small icon at the top that tells you loading interesting fields is taking time. When the results are completed, it will disappear.
Interesting Fields are turned on by default. You can also turn them off and then turn them on.

Field Statistics
You can sort the list by clicking column headers. The list contains the Fields and their Percentage (%), or the ratio of the field within the overall results. This is the default view. If the percentage of a field is less than 0.005, the number is rounded to 0.
The default is a percentage that you can change using the drop-down.
Percentage — (Total field count / Total number of logs found) * 100
Mean Deviation — absolute value of (total field count - mean count)
Median Deviation — absolute value of (total field count - median count)
Distinct Count — number of times the field shows up in the search results. If the total number of fields or the distinct count exceeds 100, the results are rounded.
Fields log_ts, col_ts, msg, logpoint_name, repo-name, and label are not included in Interesting Fields.

Add Fields
If you don't see a field you want to work with in Interesting Fields, you can add up to 20 additional ones. You cannot use special or Unicode characters. These fields will be in the list even if there are 0 search results. If you add new fields to the search, you will need to run the search again to include those fields.
The Interesting Fields feature is enabled by default unless you are using Data Privacy. You can also turn it off.
Hide Fields
You can select Hide this field from the drop-down on the key-value pairs to hide them. You can also hide fields in user preferences. You can always go back to your user preferences and change your settings to view these fields again.
Save a Search
After you perform a search, you can save it and use it again. Add it to a search package to group it with other searches.
Create Dashboard Widget
Create a widget based on a search to view search results as a graph. You add the widget to an existing dashboard or create a new dashboard and add the widget to it.
Create a New Detection (Alert Rule)
After you run a search, add it as an Alert Rule to create a new detection.
Add a Labelling Rule
Create Report
After you run a search, generate a report of the search results and send it via email as a report.
Share Search (Public URL)
Share the search query results with people who aren't Logpoint users. Adding a search to a public URL lets other people view the search results without having to log in to Logpoint SIEM.
Key Values & Statistics
View search results according to normalized key-value pairs data. Log data is listed according to key value pairs and calculates the top 10 data based on the frequency or greatest number of times the value, from the key value pair, appeared or was identified from the search. Termed Search View, you setup a new view through selecting which fields to include in the top 10 list. If you aren't interested in a specific field, don't select it.
You can share Key Value views or clone one of the views and then edit to use the view as a template for a new view.

At the top is the query used to perform the search. The table lists all of the search results, based on the fields you selected for the view. On the right are the top 10 lists, sorted by the query fields.
Use your mouse to switch between the list and the Top 10 data. You filter your search data by entering a key or field in the filter.
Examples
Initial search query:

After drilling down on action = reporting speed:

Remove a field
After performing the search, you can remove fields that you don't want or need to see from Results list and the Top 10 statistics. Add the minus (-) symbol before the field you want to remove.
Example query:

To remove the field action= denied, the query becomes:
Search Views
Search Views lets you customize how search results are displayed and analyzed. After you run a search query, Logpoint shows key value statistics (often referred to as a “search view”) that highlight the top fields and values found in your results. These views help you quickly understand the most relevant aspects of your search results and focus your investigation.
To access Search Views, use the Search Views option in the bottom-right corner of the Search page to open All Search Views or select a specific view to display its search results.
Export Raw Logs
Export Management allows you to export raw logs from Search results to a target storage location on a remote Logpoint. You can export raw logs from simple search queries, not aggregated queries. If Data Privacy is enabled, you can’t export raw data.
Accessing a Target
To access the created and configured target, go to Search from the navigation bar, click the More dropdown and click Export Logs. The names of the created targets are listed in the dropdown menu under Search >> More >> Export Logs >> Target. You can export search results for any query to any target as required.
If you have configured SCP Export, multiple lines of the same log are counted as different logs. Therefore, the number of logs in the search results is different from the number of exported logs.
Last updated
Was this helpful?
