Search Tokens for Connected IP

You can use the search tokens available in the Connected IP tab and refine your search results. Click each token to learn more about it.

andand

Use a boolean query to express your query using AND logic.

Example

Show findings with Cache Mode and Cache Port

cacheMode: enabled and cachePort: 443

oror

Use a boolean query to express your query using OR logic.

Example

Show findings with one of these TLS Protocol client

tlsProtocolClient: 1.1 or tlsProtocolClient: 1.2

applianceNameapplianceName

Use a text value ##### to search the appliance name you're looking for.

Example

Show all results where name of the appliance is QGS Test

applianceName:QGS Test

ipip

Use an integer value ##### to find the appliance with an ip address.

Example

Show appliance with this ip address

ip:10.xx.xx.xx

assetHostNameassetHostName

Use a text value ##### to search all the assets with their host name.

Example

Show assets with the host name qgstest1

assetHostName:qgstest1

lastTunnelModeActivitylastTunnelModeActivity

Use a date range or specific date to define when the last tunnel mode activity on the appliances occurred.

Examples

Show findings with last tunnel mode activity within certain dates

lastTunnelModeActivity: [2016-01-01 ... 2016-01-10]

Show findings with last tunnel mode activity starting 2015-10-01, ending 1 month ago

lastTunnelModeActivity: [2015-10-01 ... now-1M]

Show findings with last tunnel mode starting 2 weeks ago, ending 1 second ago

lastTunnelModeActivity: [now-2w ... now-1s]

Show findings with last tunnel mode activity on a specific date

lastTunnelModeActivity:'2015-12-01'

lastCacheModeActivitylastCacheModeActivity

Use a date range or specific date to define when the last cache mode activity on the appliances occurred.

Examples

Show findings with last cache mode activity within certain dates

lastCacheModeActivity: [2016-01-01 ... 2016-01-10]

Show findings with last cache mode activity starting 2015-10-01, ending 1 month ago

lastCacheModeActivity: [2015-10-01 ... now-1M]

Show findings with last cache mode activity starting 2 weeks ago, ending 1 second ago

lastCacheModeActivity: [now-2w ... now-1s]

Show findings with last cache mode activity on a specific date

lastCacheModeActivity:'2015-12-01'

cacheModecacheMode

Use the values enabled | disabled to find appliance with their cache mode enabled or disabled.

Examples

Show appliance that have cache mode enabled

cacheMode: enabled

patchModepatchMode

Use the values enabled | disabled to find appliance with their patch mode enabled or disabled.

Example

Show appliance that have patch mode enabled

patchMode:enabled

notnot

Use a boolean query to express your query using NOT logic.

Example

Show appliance incidents that were not pre-approved.

agentService.status:`FIMC_RUNNING` not operatingSystem:`linux`