Introduction
This article will provide advanced search examples using all techniques and capabilities of the Lucene language in the search section.
Advanced Search with Lucene
The screenshot below shows an example search using the criteria: "source IP address must be in the 10.10.100.0/24 or 192.168.250.0/24 subnet group, target port must be 443, protocol must not be TCP, and the search date range must not include times between 00:00 and 08:59 on the relevant day."
In the screenshot below, filtering has been applied to data that includes columns for source MAC address and source IP address, and includes only users with the name Administrator or whose username does not end with the "$" symbol.