Search filters for the query filter tool
Investigators filter the data for their assigned cases. The data is separated into groups by filter type, for example, IP address or MAC Address.
Using the logic action toggle, the investigator can either include or exclude items that are selected from the list.
Each search filters group has a logic action toggle that can be set to either include or exclude the items that are selected in the list. When set to include, the items in the list are joined with a logical AND, meaning each available document contains all of the items selected. When set to exclude, a logical OR is used, meaning each available document does not contain any of the items selected.
Investigators can use the UserQuery group to formulate their own query strings to be added to the filter.