Filter Data

You can filter aggregate data or un-aggregated top level view data using a sub-set of the Falcon LogScale query language to filter, the filters are the same as those used in the Manage Groups page.

  1. Go to Data Ingest and click Insights.

  2. Optionally, Aggregate Data before or after filtering data.

  3. Use the filter to refine the data displayed in the widgets on the page using simple queries, for example, system=ubuntu* OR hostname=linux-test-server-1 or a simple version based query like version=1.10.1

  4. Click Apply or enter.

  5. Only in an aggregated view, click Open in overview to view more details on the Falcon LogScale Collector instances.