Benefits of Helix search include the following:
The same query language is used to search previously collected data stored in Helix and data from other technologies and products.
The five most recent searches are displayed as you start to create a new search. You can click a recent search to see the initial search results.
Search results are presented in an intuitive tabular format, making it easier to scan data and quickly see patterns. The search table provides rich sorting and filtering features, as well as the ability to show, hide, and reorder columns. A graph above the search results shows the distribution of events across the selected time range.
You can interact with search results to add key-value pairs to a query, remove key-pairs from a query, create a new query, or copy the key-value pairs to use later.
A side panel in the search results shows all key-value pairs from an event, including raw event data and key-value pairs that are not shown in search table columns.
Search results are updated dynamically as the search runs. You can see the status of a running search and cancel it if it is not returning the expected data.
You can save queries for reuse and quick access. The search can be saved as a new search or you can overwrite an existing search. Other SOC team members can quickly see and use the saved searches.
When examining search results, you could see data deemed malicious that did not trigger an alert. You can proactively create a new detection rule based on that pattern. An option in search results opens the create new rule interface, where search data automatically populates fields for the new rule.
You can extend searches beyond the event data held within an alert to fully investigate a threat and do proactive work, such as threat hunting.