Simple Feed Scanner searches offers the same back-end functionality as an advanced search query, but use a graphical UI (instead of command line syntax) that links a Field name
, Operator
and Value
together in a single Expression
, which can be chained together using AND
functionality.
- Navigate to
Threat Intelligence Management
>Feed Scanner
Simple Search
tab will be preselected- Specify a
Field name
scroll through the menu - Use the drop-down menu to select an
Operator
relevant to theField name
- Specify a
Value
- Click plus icon to chain together a new
Expression
usingAND
- (Optional) Use the
Reset
button to clear all parameters - When you're ready to execute the query, click the
Search
button
Once the scan is complete, results are populated in the table view
Editing parameters
Editing the parameters can be easily done through your investigation.
-
To edit the initial query make the required amendments in the
Expression
boxes -
Re-run the query by clicking the
Search
button
Saving queries
- Enter a valid set of parameters in the
Query
box - Click the
Save
button on the top right - Enter a
Search Name
- (Optional) Enter a
Description
- (Optional) Enter a
Tags
that will classified your saved searches - (Optional) Reordered columns can be save by checking the
Save column headers with the query
box - Click
Save