To run a new search in Helix, enter a search query written using TQL.
Note
After you run one query, you can use options in the search results to refine the query or create a new query. See Use event data to refine a search or run a new search .
To run a search:
Select Investigate > Search in the main menu to open the search page.
Enter a search query using TQL syntax in the Search bar at the top of the page. You can select a recent search as a starting point.
Select a time range over which you want to search by clicking Time Range at the left of the Search bar.
Press Enter or click Search at the right end of the search bar.
The search is added to the Search Activity tab.