Creating a search from an existing search
Creating a search based on an existing search allows you to add granularity by adjusting the filters, category, and columns to suit your specific needs.
To create a new search based on an existing custom or built in search
- Under the Searches tab, select the search.
- Click the pencil icon to modify the search.
- Remove, add, edit search criteria as required. Search terms are highlighted in the preview (and search results and event details) to allows you to quickly scan for matches.
- If required, click Edit Columns to rearrange, add, and remove columns. See Customizing the search display.
- Select Save As.
- Edit the search name and select the category.
- Select whether this is a private or shared search. Working with private and shared searches.
- Click Save.
- If required, click Alert, select the required alert plan (or create a new alert plan) to notify the required individuals , click Save. See Working with alerts and alert plans
Creating or filtering a search based on event details
You can quickly create a new search or refine an existing search based on values within the event details pane. This allows you to delve deeper into the details found from existing searches.
To create a search based on an event detail
- Select the Searches tab.
- Locate the required search in the list of categories.
- To run the search, simply click it or highlight it and click the run (arrow) icon.
- Select the required value, click the More options icon (...), and select New Search on this value.
- You can select to run the search, save it, or further filter it as required.
To filter a search based on an event detail
- Select the Searches tab.
- Locate the required search in the list of categories.
- To run the search, simply click it or highlight it and click the run (arrow) icon.
- Select the required value, click the More options icon (...), and select Add filter on this value.
- You can select to run the search, save it, or further filter it as required.
Customizing the search display
When you create a search, a preview displays to help ensure the search criteria meet your needs. You can easily customizing the columns that display in the generated report and set how you want the report results displayed through the visualization settings.
To customize the display of the search results
- As you create a search, click Edit Columns.
- Drag and drop the columns to change the order.
- To remove a column, click the - next to the appropriate column.
- To add a column, click Add Column.
- Select the Visualize menu and choose how to visualize the results. You can choose between a Chart & Grid, Grid only, or Chart only.
- If you select to display as a chart & Grid or Chart, you can further refine the display by selecting the type of chart (horizontal bar chart, time series, or donut) and how you want to group and summarize the data.
- Click Preview to view your changes.
- Click Save to save your changes.
If you have selected to visualize the search in a donut or bar chart, you can add and remove items from the display by clicking to clear or enable them from the legend, and select a section of the donut or bar to view more details.
Viewing search results and event details
When selecting an event that has been returned from a search, you can view all the details of the activity that triggered the event. If the search contains string filters, the string is highlighted in the search results and event details to allow you to quickly scan for matches.
A summary of important event details is displayed at the top of the event details that includes:
- Activity Name
- Service
- Time Detected
- User display name
- Target
- Location
- Status (Successful/Failed)
For Azure Active Directory, Active Directory, and Group Policy events, the summary also displays the following:
- Property After Value
- Property Before Value
- Property Name
To view event details
- Select the Searches tab.
- Locate the required search in the list of categories.
- Highlight the search and click the arrow icon to run it.
- Click an event to open a new window that contains all the event details.
- Click the Event Link to create a dedicated page for the event details within On Demand Audit. Once created you can view the information, copy the URL to share with others, or bookmark it for future use.