Advanced Search
Advanced Search is a rule-based query builder available on Devices, Users, Vulnerabilities, and Software, for filtering beyond what the basic search box and facet rail can express, including rules that reference a different asset type than the page you’re on.
What it can do that basic search can’t
- Cross-asset-type rules: for example, on Devices, add a rule for “Vulnerability severity equals Critical” to filter devices down to ones with a matching finding, even though severity isn’t a device field at all.
- Multiple conditions combined with AND/OR: build a rule list like “OS platform is Windows AND no EDR source reported.”
- Filtering by a specific source’s own reported value, not just the resolved consensus value, useful when you want to check what one particular connector said, independent of what other sources agree or disagree with.
Using it
- Open any list page with the query builder available (look for the “Advanced Search” panel above the table).
- Add a rule: pick an asset type, a field, an operator, and a value.
- Add more rules and choose AND/OR to combine them.
- Click Run Query to apply the filter.
Saving a query
Once you’ve built a query you’ll want again, save it by name. Saved queries can be kept private to you or shared with the rest of your organization. A saved query is re-validated against the current set of available fields every time it’s loaded, so if a field it depends on is ever renamed or removed, you’ll get a clear error instead of a silently wrong filter.
Related pages
- Devices, Users, Vulnerabilities, Software: each page’s own basic search/facet rail for simpler, single-asset-type filtering.