The name of the content field that you want to search for might differ depending on whether you
search by using a regular search or an advanced search. If you want to do a regular search, use the
Query builder name from the content tables. To run an advanced search, use the
Advanced Search name.
Procedure
To include the data fields in a regular search, complete the following steps:
On the Network Activity tab, click Search > New search.
In the Column Definition section, the Available
Columns list shows the QRadar Network Insights data that you can include in
your search results.
To include the column in your query results, select the column from the list and then
click the arrow to move the column to the Columns list.
Figure 1. Network Activity tab search view
For more information about searching by using the query builder, see Creating searches.
To include the data in an advanced search, follow these steps:
On the Network Activity tab, click Advanced
Search.
In the Advanced Search box, type the Ariel Query Language (AQL) query
that specifies the fields that you want and how you want to group them.
The flows that match the search criteria appear on the Network
Activity tab. To view more information about the flow, double-click it to open the
Flow Information window.