Filter Data

You can filter aggregate data or un-aggregated top level view data using a sub-set of the Falcon LogScale query language to filter, the filters are the same as those used in the Manage Groups page.

  1. Go to Data Ingest and click Insights.

  2. Optionally, Aggregate Data before or after filtering data.

  3. Use the filter to refine the data displayed in the widgets on the page using simple queries, for example, system=ubuntu* OR hostname=linux-test-server-1 or a simple version based query like version=1.10.1

    Fleet Insights page showing the query filter options

    Figure 21. Fleet Insights page


    NOTE: The Query Editor displays one line by default. To view more, expand the Query Editor by clicking SHIFT + ENTER.

  4. After making your changes, click Apply or enter.

  5. Only in an aggregated view, click Open in overview to view more details on the Falcon LogScale Collector instances.