Events

The Events page allow advanced search about events with the dork language.

Type your query in the box above the list of events to find expected events.

Fields

The dork language enables finding events according to the following fields:

name type description alias
entity_uuid string Match events according the identifier of their entity
entity_name string Match events according the name of their entity
intake_key string Match events according their intake key
timestamp datetime Match events according when they happen date
outcome Status Match events according their status status
error_code string Match failed events according their error code
dialect string Match events according the name of their format format
dialect_uuid string Match events according the uuid of their format format_uuid
source string Match events according the source (IP address) of a network-traffic
target string Match events according the target (IP address) of a network-traffic

Type

Status

For the outcome (or status) search field, the following value are expected:

name description alias
valid Match valid events success
invalid Match invalid events failure

Example

Get valid event, from November 22nd to November 23rd, that are neither apache nor nginx logs:

date:>="2019-11-22" AND date:<"2019-11-23" AND outcome:"success" AND NOT(format:"apache" OR format:"nginx")