Query builder tool

Use the query builder tool to create searches or manage saved searches.

The query builder tool graphically walks investigators through the process of creating powerful searches that use categorized lists of query terms with examples.

Table 1. Parameters for the query builder tool
Parameter Description
Select Category Filters the list of metadata tags available in the Select Field list.
Select Field The metadata tags used to tag the information in the forensics repository.
Query Example Runs the query that is in the Query Input field and reports the number of results.
New Replaces an existing query with the new query when you click Insert Query.
AND Combines a new query with the existing query when you click Insert Query. the documents must match both query terms.
OR Combines the new query with the existing query when you click Insert Query. Documents must match either term.

Investigators can save and organize searches in folders on the file system, which allows sharing between investigators. Investigators use descriptions or names for saved queries for reference, management, and understanding purposes.

The Use Query function on the Query tab is used to send a saved query to the Search Criteria Input filed for execution.

Investigators use the previous query list to find previously run queries and re-execute them by selecting the query that they want to run and clicking Insert Query.