<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>columns &#8211; Blue Lance</title>
	<atom:link href="https://bluelance.com/docs-tag/columns/feed/" rel="self" type="application/rss+xml" />
	<link>https://bluelance.com</link>
	<description></description>
	<lastBuildDate>Mon, 01 Jun 2026 18:20:05 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bluelance.com/wp-content/uploads/2025/11/fevicon-ic-1.png</url>
	<title>columns &#8211; Blue Lance</title>
	<link>https://bluelance.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Searching &#038; Filtering Events</title>
		<link>https://bluelance.com/docs/searching-filtering-events/</link>
		
		<dc:creator><![CDATA[peter thomas]]></dc:creator>
		<pubDate>Thu, 28 May 2026 16:18:40 +0000</pubDate>
				<guid isPermaLink="false">https://bluelance.com/?post_type=docs&#038;p=15849</guid>

					<description><![CDATA[The View module provides real-time and historical access to all audit log data collected by LT Auditor MP. It is the primary tool for investigating suspicious activity, verifying that expected events are being captured, and exporting log data for further analysis or incident documentation. Accessing the View module: Creating a new view: If no saved [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The View module provides real-time and historical access to all audit log data collected by LT Auditor <sup>MP</sup>. It is the primary tool for investigating suspicious activity, verifying that expected events are being captured, and exporting log data for further analysis or incident documentation.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Accessing the View module:</strong></p>



<ol class="wp-block-list">
<li>In the main navigation menu, click <strong>View</strong></li>



<li>Select a saved view from the list, or create a new one</li>



<li>The log table displays audit records matching your current filters and date range</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Creating a new view:</strong></p>



<p class="wp-block-paragraph">If no saved views exist yet, or you need a view tailored to a specific purpose:</p>



<ol class="wp-block-list">
<li>Click <strong>Create View</strong></li>



<li>Configure the view settings:
<ul class="wp-block-list">
<li><strong>View Name</strong> — a descriptive name for the view</li>



<li><strong>Description</strong> — the purpose of this view</li>



<li><strong>Environment</strong> — the monitored environment to display logs from</li>



<li><strong>Category</strong> — the log category to focus on</li>



<li><strong>Default Date Range</strong> — the initial date range shown when the view is opened</li>
</ul>
</li>



<li>Navigate to the <strong>Columns</strong> tab and select which fields to display:
<ul class="wp-block-list">
<li>Drag columns to reorder them</li>



<li>Set column widths for optimal display</li>



<li>Enable sorting and filtering per column</li>
</ul>
</li>



<li>Click <strong>Save</strong></li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Filtering events:</strong></p>



<p class="wp-block-paragraph"><strong>Quick filters:</strong></p>



<ol class="wp-block-list">
<li>Use the filter bar at the top of the view</li>



<li>Enter search terms in the quick search box</li>



<li>Select filter criteria from the available dropdown menus</li>



<li>Results update in real time as you type</li>
</ol>



<p class="wp-block-paragraph"><strong>Advanced filters:</strong></p>



<ol class="wp-block-list">
<li>Click <strong>Advanced Filters</strong></li>



<li>Add one or more filter conditions:
<ul class="wp-block-list">
<li>Select a <strong>field</strong> from the log schema (e.g., User, Event Type, Severity)</li>



<li>Choose an <strong>operator</strong> (e.g., Equals, Contains, Starts With, Greater Than, Is Null)</li>



<li>Enter a <strong>comparison value</strong></li>
</ul>
</li>



<li>Combine conditions using AND/OR logic:
<ul class="wp-block-list">
<li><strong>AND</strong> — all conditions must match</li>



<li><strong>OR</strong> — any condition must match</li>



<li>Nest condition groups for complex logic (e.g., (A OR B) AND (C OR D))</li>
</ul>
</li>



<li>Click <strong>Apply Filters</strong></li>
</ol>



<p class="wp-block-paragraph"><strong>Date range filter:</strong></p>



<ol class="wp-block-list">
<li>Use the date range picker at the top of the view</li>



<li>Choose from:
<ul class="wp-block-list">
<li><strong>Quick ranges</strong> — Today, Yesterday, Last 7 Days, Last 30 Days, etc.</li>



<li><strong>Custom range</strong> — specific start and end dates</li>



<li><strong>Relative range</strong> — dynamic ranges that update automatically (e.g., Previous Month)</li>
</ul>
</li>



<li>The log table refreshes automatically when the date range is changed</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Searching log data:</strong></p>



<p class="wp-block-paragraph">Perform full-text searches across all collected log data:</p>



<ol class="wp-block-list">
<li>Enter search terms in the search box</li>



<li>Choose the search scope:
<ul class="wp-block-list">
<li><strong>All Fields</strong> — searches across every field in the log schema</li>



<li><strong>Specific Field</strong> — searches within a single selected field</li>
</ul>
</li>



<li>Use search operators for more precise results:</li>
</ol>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><td><strong>Operator</strong></td><td><strong>Usage</strong></td><td><strong>Example</strong></td></tr><tr><td>AND</td><td>Both terms must appear</td><td>login AND failed</td></tr><tr><td>OR</td><td>Either term must appear</td><td>login OR logon</td></tr><tr><td>NOT</td><td>Exclude a term</td><td>login NOT success</td></tr><tr><td>Exact phrase</td><td>Match exact wording</td><td>&#8220;account locked&#8221;</td></tr><tr><td>Wildcard</td><td>Match partial terms</td><td>admin*</td></tr></tbody></table></figure>



<ol start="4" class="wp-block-list">
<li>Press <strong>Enter</strong> or click <strong>Search</strong></li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Sorting and navigating results:</strong></p>



<ul class="wp-block-list">
<li>Click any <strong>column header</strong> to sort by that field</li>



<li>Click again to reverse the sort direction</li>



<li>Hold <strong>Shift</strong> and click multiple column headers for multi-level sorting</li>



<li>Use the <strong>page size selector</strong> to control how many records display per page (20, 50, 100, or 200)</li>



<li>Use <strong>Previous</strong> and <strong>Next</strong> to navigate between pages</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Viewing full event details:</strong></p>



<ol class="wp-block-list">
<li>Click on any log row in the table</li>



<li>A detail panel opens showing:
<ul class="wp-block-list">
<li><strong>All Fields</strong> — complete field values for the event</li>



<li><strong>Raw Log</strong> — the original unprocessed log entry</li>



<li><strong>Metadata</strong> — timestamp, source, and receiver information</li>



<li><strong>Related Logs</strong> — links to related audit events</li>
</ul>
</li>



<li>Click <strong>Close</strong> to return to the table view</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Exporting log data:</strong></p>



<ol class="wp-block-list">
<li>Apply your desired filters and date range</li>



<li>Click the <strong>Export</strong> button</li>



<li>Choose an export format:
<ul class="wp-block-list">
<li><strong>CSV</strong> — for use in Excel or data analysis tools</li>



<li><strong>Excel</strong> — native Excel format with formatting applied</li>



<li><strong>PDF</strong> — formatted document suitable for printing or sharing</li>
</ul>
</li>



<li>Configure export options:
<ul class="wp-block-list">
<li>All Columns or Visible Columns Only</li>



<li>Include or exclude column headers</li>



<li>Set a maximum record limit if needed</li>
</ul>
</li>



<li>Click <strong>Download</strong></li>
</ol>



<p class="wp-block-paragraph">For very large exports, the system may queue the export and deliver it via email when complete. For datasets that regularly require large exports, consider scheduling a report instead.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Saving and sharing views:</strong></p>



<ul class="wp-block-list">
<li>Click <strong>Save</strong> at any time to save your current filter and column configuration as a named view</li>



<li>Click <strong>Duplicate View</strong> to create a copy of an existing view as a starting point for a new one</li>



<li>Click <strong>Share</strong> to share a view with other users or roles, with either View Only or Edit permissions</li>



<li>Click the <strong>Star</strong> icon on any view to add it to your favorites for quick access</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Auto-refreshing views:</strong></p>



<p class="wp-block-paragraph">For real-time monitoring, enable auto-refresh to keep the view updated automatically:</p>



<ol class="wp-block-list">
<li>Click the <strong>Auto-Refresh</strong> control</li>



<li>Select a refresh interval: 5s, 10s, 30s, or 1 minute</li>



<li>The view will reload at the selected interval</li>
</ol>



<p class="wp-block-paragraph">Use auto-refresh cautiously with large datasets or broad date ranges, as frequent reloads can impact performance.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><strong>Best practices:</strong></p>



<ul class="wp-block-list">
<li>Set a reasonable default date range on saved views to avoid loading excessive data on open</li>



<li>Display only the columns you need for faster load times</li>



<li>Use named, saved views for recurring investigation tasks rather than rebuilding filters each time</li>



<li>For large-scale data analysis, schedule a report rather than exporting directly from a view</li>



<li>Use descriptive view names so other team members can understand the purpose at a glance</li>
</ul>



<p class="wp-block-paragraph"><em>[Your administrator should create and share a set of standard views for common investigation scenarios so the team has a consistent starting point.]</em></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
