Layout
| Area | What it does |
|---|---|
| Query bar | Type field:value terms and free text. Autocomplete suggests field names, their types and descriptions from the dictionary, then values. |
| Time range | Relative presets or an absolute range. The histogram and the hit summary follow it. |
| Search tabs | Keep several searches open. A tab created from an alert carries that alert's context. |
| Hit summary | How many documents matched, how many are shown, and when the query ran. |
| Histogram | Volume over time. Drag to narrow the range. |
| Filters | Chips for the active filters. Click a chip to change its operator or remove it. |
| Fields rail | Popular and available fields with typed icons. Expand a field for its top values and add a filter with one click. |
| Documents | One row per event with the severity dot, time and a summary. Expand a row for every field as a table or as JSON; every value offers "filter for" and "filter out". |
Live or demo
A badge next to the hit summary says LIVE when the page is querying the store. In a demo deployment it says demo and shows fixture data.
From an alert to the evidence
Every alert's event graph and timeline link to the raw documents behind them. Opening one lands you on the Logs page with a tab scoped to the alert, the relevant filters applied and the document expanded.
Saved views
Column layout, filters and the time range can be saved as a view. Views are stored privately in your browser, so a link you share keeps your filters to yourself. To share a view, export it from the tab menu and let the other analyst import it.
Process tree and activity graph
From any process event, Open process tree unfolds the parent chain and the children, and Activity shows what the process did next: connections, files, registry, child processes. Both are built from the events already in the store.