> For the complete documentation index, see [llms.txt](https://docs.panther.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.panther.com/~/changes/Dd8nx2iqd1Pp2OzWJaWk/search/search-tool.md).

# Search

Construct a data query without writing SQL

## Overview

{% hint style="info" %}
Search is in open beta starting with Panther version 1.85, and is available to all customers. Please share any bug reports and feature requests with your Panther support team.
{% endhint %}

In the Search tool in Panther, you can search across all of your data—including log events, rule matches, and more—without writing SQL. Use dropdown fields to create filter expressions, which contain your search logic, free search terms, or match patterns.

Filter expressions can be constructed in different ways: as [key/value pairs](#key-value-filter-expression), a [free text](#free-text-filter-expression) search, or a [regular expression](#regular-expression-regex-filter-expression) search. Each of these can also use [wildcard characters](#using-wildcards-in-filter-expressions). You can combine different types of filter expressions in one search.

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2F7CX5SvF6imADaomm5x9V%2Fimage.png?alt=media&amp;token=48fa1f90-0fa4-4a71-9821-29d5a3071472" alt="Search in the Panther Console is shown. There are three filter expressions: &#x22;userIdentity.type is AsumedRole&#x22; &#x22;IP Addresses has 50.112.148.219&#x22; and &#x22;.*aws:.*admin.*&#x22; Below the search box are the results displayed in a histogram and table view."><figcaption></figcaption></figure>

When a search is run, a results table is displayed below a histogram visualizing the distribution of result events over time. The results table is customizable—you can [add or remove event fields](#adding-removing-and-reordering-fields-in-the-results-table) as columns. Also from the results table, you can [add inclusive/exclusive filters](#how-to-create-an-inclusive-or-exclusive-filter-expression-from-a-result-event) to your search, pivot, and look up related enrichment data. You can [collaborate with your team](#sharing-a-search) by downloading the results table, or sharing a link to your specific search in Panther.

{% hint style="warning" %}
Search is only available to customers with a [Snowflake](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/search/backend/snowflake.md) data lake. It is not available to Panther instances with an [Athena](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/search/backend/athena.md) data lake.
{% endhint %}

### Limitations of Search

The Search tool currently has the following limitations:

* With multiple filter expressions, only `AND` logic is supported.
* Grouping filter expressions is not supported.

## How to use Search

You can effectively search your data using a combination of filters. Start by making selections in the [database, table, and date range filters](#using-database-table-and-date-range-filters)—then [create your own filter expressions](#creating-filter-expressions).

### Using database, table, and date range filters

Use the database, table, and date range filters to narrow the scope of your search. Using these controls is optional, but can significantly improve search performance when searching over large data sets. Learn more about each of these filters below.

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2F0YLVxy2bQuc87mUri8vt%2FScreenshot%202023-09-07%20at%202.54.27%20PM.png?alt=media&amp;token=bdb2de74-9bf6-48ea-9da3-0c9b8a7e7012" alt="The Search UI in Panther is shown. Three dropdowns in the upper-right corner are shown. The first has a selection of &#x22;Logs,&#x22; the second has a selection of &#x22;All tables,&#x22; and the third has a value of &#x22;Last 24 hours.&#x22;"><figcaption></figcaption></figure>

#### Database filter

Use the database filter to narrow your search to certain databases, such as only **Logs** or **Rule Matches**.&#x20;

The default value of this filter is **Logs**. The options contained in the database filter are:

* Rule Matches
* Logs
* Lookups
* Monitor
* Cloud Security
* Rule Errors

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FanMShbwFdqYkhIlY1MZ1%2FScreenshot%202023-09-08%20at%203.45.32%20PM.png?alt=media&amp;token=fc4ab8b9-4aa0-485b-9e82-398594a1017f" alt="Three dropdown fields are shown. The first one is open, and the checkbox next to &#x22;Logs&#x22; is selected. The middle dropdown has a selection of &#x22;All tables&#x22; made, and the third has a selection of &#x22;Last 24 hours.&#x22;" width="375"><figcaption></figcaption></figure>

#### Table filter

Use the table filter to narrow your search to certain tables, within the databases indicated by the [database filter](#database-filter).

The default value of this filter is **All tables**, which includes all tables for each included database. You can narrow the search by selecting only certain tables in this dropdown.

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2F2buLB2QVjgTtQ5dADCZd%2FScreenshot%202023-09-08%20at%203.40.36%20PM.png?alt=media&amp;token=d38eb746-bf81-4dd9-94e2-21ceb498add4" alt="Three dropdowns are shown: in the first, &#x22;Monitor&#x22; is selected. the second one is open, and the checkbox next to &#x22;Classification Failures&#x22; is checked. In the third dropdown, &#x22;Last month&#x22; is selected." width="375"><figcaption></figcaption></figure>

#### Date range filter

Use the date range filter to narrow your search to a certain period of time.&#x20;

The default value of this filter is **Last 24 hours**. You can use the date range picker to set a custom date and time range, or select one of the preset relative options on the left-hand side.

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FQsPFjAVIlLOiQ4wNdclw%2Fimage.png?alt=media&amp;token=c03233a2-d091-4573-ace3-06d03d5d8734" alt="A date and time picker is shown. On the left-hand side there are preset relative values, like &#x22;Last hour,&#x22; &#x22;Last 3 days,&#x22; etc. On the right-hand side is a calendar picker, as well as dropdown fields to select the time. At the bottom are &#x22;Cancel&#x22; and &#x22;Apply&#x22; buttons. " width="375"><figcaption></figcaption></figure>

### Creating filter expressions

A filter expression is a clause containing your [key/value search logic](#key-value-filter-expression), [free search terms](#free-text-filter-expression), or [match patterns](#regular-expression-regex-filter-expression). To create filter expressions, click the **Add query filter** bar or use the `command` + `/` keyboard shortcut.

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FXF5EYEkYn8PZCZYTh9Wn%2FScreenshot%202023-09-07%20at%202.54.27%20PM.png?alt=media&amp;token=b84adeba-b9db-4d70-a1f6-f5f0db8bfc62" alt="The Search tool is shown. The search bar, which has placeholder text of &#x22;Add query filter,&#x22; is empty. It is circled."><figcaption></figcaption></figure>

#### Key/value filter expression

With a key/value filter expression, you will select an event key and provide a value (if necessary).

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2Fn1pbz3kp4k3ZgpYDhPiE%2Fimage.png?alt=media&amp;token=0af5bc22-bf45-466b-8b3b-12547faf3144" alt="In the Search bar is one filter expression. It reads &#x22;Emails has john.doe@email.com&#x22;"><figcaption></figcaption></figure>

To create a key/value filter expression:

1. Click the **Add query filter** bar, or press `command`+`/`.
2. Select an event key from the dropdown list. The dropdown menu contains options grouped into the following categories:
   * **Panther Fields**: Includes [Indicator Fields](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/search/panther-fields.md#indicator-fields) (also known as `p_any` fields), and [Core Fields](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/search/panther-fields.md#core-fields) (`p_udm` fields), which are useful when searching across log types.\
     ![In the Search bar, a dropdown shows "Panther Fields" including Actor IDs, AWS Account IDs, and AWS ARNs](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FzqpRG9FCDDkLpxZidqec%2FScreenshot%202023-09-07%20at%2012.59.31%20PM.png?alt=media\&token=d8477df0-8c89-4cb6-a42e-a65a3d64445c)
   * **Multiple tables:** Fields that are found in more than one log type.\
     ![In the Search bar, there is a dropdown showing "Multiple Tables" options, including apiVersion, kind, and level](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FGV0l640rFJNzeIKZAohB%2FScreenshot%202023-09-07%20at%2012.59.13%20PM.png?alt=media\&token=d8c52c5a-6536-4a28-8317-e2556e75b6d9)
   * All remaining tables with a matching field(s) are displayed in alphabetical order.&#x20;
3. Select an operator (also known as a condition) from the dropdown menu.
   * The dropdown options will be limited to those applicable to the selected field's data type.
   * See a full list of available operators on [Search Filter Operators](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/search/search-tool/filter-operators.md).
4. Enter a value, if the selected operator requires one.
   * Learn more about using the [wildcard character below](#using-wildcards-in-filter-expressions).
5. If you would like to create another filter expression, click outside the expression you just created (but within the search bar), or press `TAB`.&#x20;
   * If you are ready to execute your search, click **Search** or press `ENTER`.

#### Free text filter expression

In a free text filter expression, you will enter a string.&#x20;

{% hint style="info" %}
Free text filter expressions search every field in every event (within the database, table, and date constraints), including fields nested in complex objects.

To increase search performance, [select a subset of tables](#table-filter) to search.&#x20;
{% endhint %}

To create a free text filter expression:

1. Click the **Add query filter** bar, or press `command`+`/`.
2. Enter the text value.
   * Learn more about using the [wildcard character below](#using-wildcards-in-filter-expressions).
3. If you would like to create another filter expression, click outside the expression you just created (but within the search bar), or press `TAB`.&#x20;
   * If you are ready to execute your search, click **Search** or press `ENTER`.

#### Regular expression (regex) filter expression

Using regex in Search can be powerful for dynamic text-based searches across logs. Learn more about the [re2 syntax for regular expressions here](https://github.com/google/re2/wiki/Syntax).

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2Fw0K0OotOea4wTDjzuRrQ%2Fimage.png?alt=media&amp;token=fa185219-f6f6-432d-bfed-6b79db92e180" alt="A single filter expression is created in the Search bar. It reads &#x22;.*aws:.*admin.*&#x22;"><figcaption></figcaption></figure>

To create a regex filter expression:

1. Click the **Add query filter** bar, or press `command`+`/`.
2. Press `command`+`/` to enter into regex mode.&#x20;
   * To exit regex mode, you can press `command`+`/` again.
3. Enter the regular expression you wish to search, e.g., `.*aws:.*admin.*`.
   * Learn more about using the [wildcard character below](#using-wildcards-in-filter-expressions).
4. If you would like to create another filter expression, click outside the expression you just created (but within the search bar), or press `TAB`.&#x20;
   * If you are ready to execute your search, click **Search** or press `ENTER`.

### Using wildcards in filter expressions

The wildcard character (`*`) may be used as a placeholder at the beginning, middle, or end of a string or expression. The wildcard character may be used within a [key/value filter expression](#key-value-filter-expression) (only where the key has `type: string` and the operator is `LIKE`), [free text filter expression](#free-text-filter-expression), or [regex filter expression](#regular-expression-regex-filter-expression).&#x20;

Where the wildcard character is positioned affects which data is returned as a match:

* Beginning: Any character(s) at or preceding the `*` are considered a match.
* Middle: Any character(s) at the `*` are considered a match.
* End: Any character(s) at or following the `*` are considered a match.

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2Fd8t1fK2YkQ3GhmqGDoYJ%2Fimage.png?alt=media&amp;token=098a8ca8-5645-4416-b371-a50807b799e4" alt="The Search bar has three filter expressions: &#x22;Log Type is not Windows.EventLogs&#x22; &#x22;Log Type like AWS*Flow&#x22; and &#x22;ACCE*&#x22;"><figcaption></figcaption></figure>

### Creating a Saved Search

Creating a Saved Search means you can quickly reuse commonly run searches. Learn more on [Saved and Scheduled Searches](/~/changes/Dd8nx2iqd1Pp2OzWJaWk/search/scheduled-searches.md).

To create a Saved Search:

1. Create a search by following the instructions in [How to use Search](#how-to-use-search).
2. Under the **Add query filter** box, click **Save As**.

   <figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FxcaUYnytZCIYQWhYvckf%2FScreenshot%202023-09-08%20at%204.00.47%20PM.png?alt=media&amp;token=3281f155-4b01-4be7-95c8-a61d9c3673fc" alt="The Search UI is shown, with one filter expression created (&#x22;kind is http&#x22;). Below the search bar, the &#x22;Save As&#x22; text is circled." width="563"><figcaption></figcaption></figure>
3. Enter values for the fields in the popup modal:
   * **Query Name**: Add a descriptive name.
   * **Tags** (optional): Add tags. Tags can be helpful to group related searches.
   * **Description** (optional): Describe the purpose of the search.
4. Click **Save Search**.
   * See the next section to learn how to open and reuse Saved Searches.

### Open and reuse a Saved Search in the Search tool

After creating a Saved Search in the Search tool, you can view and reuse it. It can be opened from the Search page, or from the Saved Searches page.

{% tabs %}
{% tab title="Search page" %}

#### Open a Saved Search from the Search page:

1. In the left-hand navigation bar of your Panther Console, click **Investigate** > **Search**.
2. In the upper right corner, click the three dots icon, then **Open Saved Search**.
   * An **Open a Search** modal will pop up, displaying previously saved search.
3. Find the search you'd like to open, select it, then click **Open Search**.
   * The Saved Search will populate in Search.
     {% endtab %}

{% tab title="Saved Searches page" %}

#### Open a Saved Search from the Saved Searches page:

1. In the left-hand navigation bar of your Panther Console, click **Investigate** > **Saved Searches**.
2. Find the search you'd like to open, utilizing the search bar and **Filters** at the top, if necessary.
3. In the top right corner of the search's tile, click the three dots icon.
4. Click **View in Search**.
   * You will be redirected to Search, where the Saved Search will populate.
     {% endtab %}
     {% endtabs %}

## Working with Search results

### Search results histogram

The results histogram displays the distribution of events within the search's date and time window, to help immediately contextualize results. To zoom in or out of a particular segment of time, click and drag the ends of the bar beneath the histogram.

<figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FB5RNZmnKifHJmrvjGlRQ%2Fimage.png?alt=media&amp;token=8fcda3dc-dfa7-4820-92f6-68e88ce22651" alt="The Search results histogram is shown. It has a number of purple bars sticking up, corresponding to different dates and times."><figcaption></figcaption></figure>

#### Interacting with the histogram

To see additional data insights into the counts by log type for any of the time periods, hover over a bar within the chart.

![A tooltip in the Search results histogram displays the date and time, then three different log sources and the number of hits for each.](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FI9VdzF268Og7k2W5QEE8%2Fimage.png?alt=media\&token=90357ed4-c50c-4874-9f79-cf7d711055a5)

To create a new search (in a new browser tab) with a time period set to that of one of the histogram bars, click the bar.

### Adding, removing, and reordering fields in the results table

You can customize a search's results table by [adding](#how-to-add-a-column-in-the-search-results-table), [removing](#how-to-remove-a-column-in-the-search-results-table), and [reordering](#how-to-reorder-columns-in-the-search-results-table) columns.

#### How to add a column in the Search results table

You can add a column to the Search results table using the [**Available Fields** list](#add-a-column-to-the-search-results-table-from-the-available-fields-list) on the left-hand side of the table, or from the [JSON event view](#add-a-column-to-the-search-results-table-from-the-json-event-view).&#x20;

It is only possible to add *nested* fields to the table from the [JSON event view](#add-a-column-to-the-search-results-table-from-the-json-event-view).

{% tabs %}
{% tab title="Available Fields list" %}

#### Add a column to the Search results table from the Available Fields list

1. In the field list on the left-hand side of the results table, within the **Available Fields** header, locate the column you'd like to add to the results table.

   <figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2F526U0zgpEtAEObtfgwnK%2Fimage.png?alt=media&amp;token=c6e57bfa-0f1f-445e-b6c2-4cc737b45cd8" alt="A list of event fields is displayed underneath an &#x22;Available Fields&#x22; header." width="167"><figcaption></figcaption></figure>

   * Only top-level fields are shown in this list. If you'd like to add a nested field to the table, you can do so from the [JSON event view](#add-a-column-to-the-search-results-table-from-the-json-event-view).
2. To the right of the field, click **+** (the plus symbol).
   * The field will be added as a column in the results table, and listed on the left-hand side of the table within **Selected Fields**.
     {% endtab %}

{% tab title="JSON event view" %}

#### Add a column to the Search results table from the JSON event view

1. In the results table, click on a row to open the JSON event view slide-out panel.
2. Locate the field you'd like to add to the results table.
3. While hovering over the field, click **+** (the plus symbol).\
   ![The JSON event view of a log is shown. To the right of one field, the plus button is circled.](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2F8qdOEb7BQbZzDSSTgYsS%2FScreenshot%202023-09-12%20at%203.15.23%20PM.png?alt=media\&token=b47686c7-fdb2-40dc-a5ef-7cea75047b34)
   * The field will be added as a column in the results table, and listed on the left-hand side of the table within **Selected Fields**.
     {% endtab %}
     {% endtabs %}

#### How to remove a column in the Search results table

You can remove a column from the Search results table using the [**Selected Fields** list](#remove-a-column-from-the-search-results-table-from-the-selected-fields-list) on the left-hand side of the table, from the [JSON event view](#remove-a-column-from-the-search-results-table-from-the-json-event-view), or from the [table header row](#remove-a-column-from-the-search-results-table-from-the-header-row).

{% tabs %}
{% tab title="Selected Fields list" %}

#### Remove a column from the Search results table from the Selected Fields list

1. In the field list on the left-hand side of the results table, within the **Selected Fields** header, locate the field you'd like to remove from the results table.
2. To the right of the field, click **-** (the minus symbol).

   ![Under the "Selected Fields" header, there are log fields. To the right of "PantherAudit.actionName" the minus button is hovered over. Its tooltip reads, "Remove column"](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FCcUyt8lxRtbxZKETvRkd%2Fimage.png?alt=media\&token=2eff01b4-748b-4276-9d6e-ba81d5f7e85d)

   * The field's column will be removed from the results table, and listed on the left-hand side of the table within **Available Fields**.
     {% endtab %}

{% tab title="JSON event view" %}

#### Remove a column from the Search results table from the JSON event view

1. In the results table, click on a row to open the JSON event view slide-out panel.
2. Locate the field you'd like to remove from the results table.
3. While hovering over the field, click **-** (the minus symbol).\
   ![The JSON event view of a log is shown. To the right of one field, the minus button is circled.](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FceiAs8wlkECLii71yBhv%2FScreenshot%202023-09-12%20at%203.45.23%20PM.png?alt=media\&token=36c75c5d-2521-4edc-9ffb-598a0fc1e73a)<br>
   * The field's column will be removed from the results table, and listed on the left-hand side of the table within **Available Fields**.
     {% endtab %}

{% tab title="Table header row" %}

#### Remove a column from the Search results table from the header row

1. In the results table, hover over the header of the column you'd like to remove.
2. On the right side of the column header, click **X**. \
   ![A header reading "GitHubAudit.config.content\_type" is shown, and the "X" to its right is circled.](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FhcDEdqz8qePnauLXmErh%2FScreenshot%202023-09-12%20at%203.48.26%20PM.png?alt=media\&token=3d1f9900-78e7-4af3-aed5-c3c6295b3ca6)
   * The field's column will be removed from the results table, and listed on the left-hand side of the table within **Available Fields**.
     {% endtab %}
     {% endtabs %}

#### How to reorder columns in the Search results table

* Reorder the columns in the results table by clicking on a column header and dragging it to the desired position.&#x20;

### Iterating on a Search

Interact with the search results table or JSON event view to include, exclude, or pivot on a field within your filter expression.&#x20;

#### How to create an inclusive or exclusive filter expression from a result event

{% hint style="info" %}
The same ability to create include or exclude filters is available from within the JSON event view, when hovering over a field.
{% endhint %}

1. In the results table, hover over the value you'd like to create an inclusive or exclusive filter expression for.

   ![A column called "PantherAudit.actionName" is shown. To the right of its first value, GET\_UBER\_SEARCH, are a plus and minus sign. The plus sign is highlighted.](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FsY482okpl6oSnzLKQWDV%2Fimage.png?alt=media\&token=e7e765c9-795b-4a08-979a-87bb066c3d06)

   * To create an inclusive filter, click **+** (the plus symbol).&#x20;
   * To create an exclusive filter, click **-** (the minus symbol).
2. View the new filter expression in the search bar at the top of the window.
3. To refresh the search results, click **Search**.

#### How to replace values in filter expressions with a result event value

1. In the results table, locate the event row of interest, and click it.
   * The JSON event slide-out panel will be shown.
2. In the JSON event slide-out panel, hover over the field on which you'd like to pivot.

   ![A JSON event slide-out panel is shown. To the right of one of the event fields, the replace icon (a curved arrow) is hovered over.](https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FLnWfA5JUehP4ACrz5NKq%2Fimage.png?alt=media\&token=5a3b842f-e1f0-466b-9a78-7d299939fbf5)
3. Click the replace icon <img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FjkRUVGy9CXvk1PRe0bjM%2FScreenshot%202023-09-12%20at%203.54.39%20PM.png?alt=media&amp;token=063ffc21-6fca-4287-8601-5af1f4c9fdbc" alt="" data-size="line">.
   * All existing filters are replaced with a filter expression representing only the key/value you pivoted on.
4. To refresh the search results, click **Search**.

### Sharing a Search

While investigating or threat hunting, it may be useful to share a Search or a results set with your team. To do this:

1. In the upper-right corner of the results table, click **Share**:

   <figure><img src="https://4011785613-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LgdiSWdyJcXPahGi9Rs-2910905616%2Fuploads%2FOT6XNpZvzGosaeq85u7p%2Fshare_table.webp?alt=media&amp;token=1747c489-e2df-46a3-a8df-62694ab9d866" alt="The results table is shown. In the upper-right corner, the Share button&#x27;s menu is open, displaying two options: Copy link to view and Download CSV. This button and its options are circled."><figcaption></figcaption></figure>
2. Select one of the menu options:
   * **Copy link to view**: Copies a URL to this specific Search to your clipboard.
   * **Download CSV**: Downloads a CSV of the results table.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.panther.com/~/changes/Dd8nx2iqd1Pp2OzWJaWk/search/search-tool.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
