Query filtersHistory | Edit
Before generating a data view, you must filter your query. This section lists the query filters available for each analysis. This list is organized alphabetically by query filter.
Query filter | Associated reports | Description |
---|---|---|
Access rule |
|
Select the access rule to investigate. |
Acknowledged by |
|
Users who acknowledged the alarm. |
Acknowledged on |
|
Alarm acknowledgement time range. |
Action taken |
|
User hit actions (Monitor, Diagnose, Clear). |
Acknowledgement type |
|
Check one of the following acknowledgement type options:
|
Alarm priority |
|
Alarm priority. |
Alarms |
|
Select the types of alarms you want to investigate. |
Application |
|
Which client application was used for the activity. |
Archiver |
|
Select the Archivers to investigate. |
Clusters |
|
Select the clusters to investigate. |
Compare with |
|
Compare entities with a source entity of the event. |
Creation time |
|
Incidents created/reported within the specified time range. |
Credential |
|
Specify whether or not the credential is assigned. |
Custom fields |
|
If custom fields are defined for the entity you are
investigating, they can be included in this report. Note: You might
not see the custom fields filter, depending on whether your user
is configured to view that custom field.
|
Description |
|
Restrict the search to entries that contain this text string. |
Devices |
|
Select the devices to investigate. |
Entities |
|
Select the entities you want to investigate. You can filter the entities by name and by type. |
Health event |
|
Name of the health event. |
Health severity |
|
Severity level of the health event. |
Hit rules |
|
Select the hit rules to include in the report. |
Hit type |
|
Select the type of hits to include in the report. |
Impacted |
|
The entities that were impacted by this activity. |
Incident time |
|
Incidents reported within the specified time range. The incident time corresponds to the event or alarm timestamp the incident refers to. If the incident does not refer to any event or alarm, then the incident time corresponds to the creation time. |
Initiator |
|
User responsible for the activity. |
Investigated by |
|
Which user put the alarm into the under investigation state. |
Investigated on |
|
Specify a time range when the alarm was put into the under investigation state. |
Machine |
|
Select a computer that was having health issues to investigate. |
Modified by |
|
User responsible for the entity modification. |
Modification time |
|
|
Notes |
|
Enter text to find incidents with a description starting or containing the specified text. |
State |
|
Current state of the alarm.
|
Triggered on |
|
Alarm trigger time range. |
Triggering event |
|
Events used to trigger the alarm. |
Users |
|
Select the user name. |