Customize display of query results

After you run a query, you can customize how your results are displayed.

Customize display

You can customize the results section of the Application Control Events dialog.

  • Grouping results by column header. Drag a column header into the top of the results table. This action groups your returned results according to the column header selected.

  • Use the Searching tool to include only those events that match your search criteria. The search applies to all columns. Criteria could include file names or extensions, user or machine names for example. In the case of the Denied Executables query, where a number of event IDs are returned, you could search for a particular event ID, for example.

  • Apply Filtering to one or more column headers. This allows you to include OR exclude events that match your criteria.
    Select Show Filter Editor to add filters to the query results, or hover over a column header and select the filter icon.
    The Filter Editor dialog opens, allowing you to specify filter criteria.

    Refer to the Privilege Discovery use-case video for an illustration of creating and applying a filter.

  • Select Choose Columns to customize which columns display in the query results.

  • Reorder the columns by dragging the column headers to new locations.

  • Select within a column header to sort the column in ascending or descending order.