Previous Topic: Event Search Syntax Guidelines and Best PracticesNext Topic: Operations and Expressions


Event Properties and Values

Syntax

Use the following syntax to complete a basic search pattern:

property[operator]'value'

Note: For deployed policies and when performing searches using string values, property values must be delimited by single quotes. An error message appears when a property is missing a quote character on either side. For example, to enter a pattern that returns events with a severity of Critical, you would enter Severity='Critical'.

Alternatively, leave the search patterns empty to return a console view of all events for the defined scope.

Event Properties