A basic search runs against all of the event fields in Table 2. Some sample basic searches include the following:
root
127.0.0.1
Lock*
driverset0
NOTE:If time is not synchronized between the end user machine and the Sentinel Rapid Deployment server (for example, one machine is 25 minutes behind), you might get unexpected results from your search. Searches such as
or are based on the end user’s machine time.Click the
link on the left.Sentinel Rapid Deployment is configured to run a default search for non-system events with severity 3 to 5 the first time you the
link. Otherwise, it defaults to the last search term you entered.For a different search, type a search term in the search field (for example, admin). The search is not case sensitive.
Select a time period for which the search should be performed. Most of the time settings are self-explanatory, and the default is
.allows you to select a start date and time and an end date and time for the query. The start date must be before the end date, and the time is based on the browser’s local time.
searches all the data in the database.
Select
to include events that are generated by Sentinel Rapid Deployment system operations.Select
to arrange data with the most recent events at the beginning.Sorting by time takes longer than sorting by relevance, which is the default.
Click
.All fields in the index are searched for the specified text. A spinning icon indicates that the search is taking place.
The event summaries are displayed.
For trademark and copyright information, see Legal Notices.