Advanced search
The Advanced search panel under the events toolbar holds the time range, the scope, the condition builder and your saved searches. This page explains each of them and the text form of a search.
The panel
Click Advanced search under the toolbar to open or close the panel. The number beside its title counts how many of its filters (From, To, scope and each condition) are narrowing the list right now, so a closed panel never hides a filter from you.
The panel opens by itself when you arrive from a link or saved search that uses it. Everything in it is written into the page address, like the toolbar filters (see Filtering).
Time range
From and To limit the list to events that happened between two moments, precise to the second. Type a time in whatever way is natural; the exact instant EyalSec read appears under the box, in your time zone. Leave a box empty for no limit on that side.
| You type | It means |
|---|---|
2026-08-10 14:30 |
that minute, in your time zone |
2026-08-10 |
that whole day |
10/08/2026 |
a day, with day and month in your browser's usual order |
10 aug 2026 2:30pm, aug 10, 2026 14:30 |
the same minute, with the month named |
14:30, 9am, noon, midnight |
today, at that time |
2h ago, 45 minutes ago, -15m, 7d, 3 months ago |
that long before now |
in 3 days, +1w |
that long after now |
now, today, yesterday 09:00, tomorrow |
keywords, with an optional time |
2026-08-10T14:30:00+03:00 |
an exact instant with its offset |
1786554930 |
a unix timestamp, in seconds or milliseconds |
A bound without a time covers the whole unit it names: From starts at the beginning of it and To runs to the end. So To: 2026-08-10 includes all of that day, and To: 14:30 includes all sixty seconds of 14:30.
Always read the line under the box. 08/10/2026 is August 10th to some readers and October 8th to others; the line shows which one was used. If a box holds something it cannot read, it turns red and says so, and the list keeps showing the last range that made sense rather than dropping the limit.
Times are in the time zone set in Settings. Typing a time turns off any quick range.
Scope
The scope pins the list to one place in your code: a source path on es-python, a page host on es-chromium. Pick how to match (is, ends with or matches regex) and type the value; × clear removes it.
Events that carry no such value are left out while a scope is set. Tick include events with no path (the wording follows the product) to keep them.
| List | Scope field | Example |
|---|---|---|
| es-python | Path (a source path) | ends with app/views.py |
| es-chromium | Host (the page host) | ends with .example.com |
Conditions
Conditions let you search fields the toolbar does not cover, such as the value, the stack trace or the command line. Each condition is a row of field, operator and value; click + Add condition to add one and × to remove it. The list reloads as you type.
Conditions are available on the es-python and es-chromium lists. You can have up to 12.
Match all or any
Match all keeps events that satisfy every condition; Match any keeps events that satisfy at least one. The choice applies to the whole set.
Operators and Not
Every text comparison ignores case except is, which must match exactly.
| Operator | Keeps events whose field |
|---|---|
| contains | contains the value anywhere |
| is | equals the value exactly |
| starts with | begins with the value |
| ends with | ends with the value |
| matches regex | matches the regular expression |
| is empty | has no value (no value box) |
The Not button on a row reverses it, so "contains" with Not means "does not contain" and "is empty" with Not means "is not empty".
Fields
The fields you can search depend on the list.
| Field | Lists | Searches |
|---|---|---|
| Sink | es-python, es-chromium | the sink label |
| Value | es-python | the untrusted value that reached the sink |
| Payload | es-chromium | the value at the sink |
| Stack trace | es-python | the stack trace |
| Origin | es-python | the origin block |
| Detail | es-python | the detail line (file path, regex, ...) |
| Source | es-chromium | the source label |
| URL, Page, Script, Extension, Host | es-chromium | the request URL, page, script, extension and page host |
| Command line, Environment | es-python | the command line and environment of the programs that produced the event |
| Run | es-python | one program invocation (see Runs) |
| Machine | es-python, es-chromium | the machine name |
| Severity | es-python, es-chromium | critical, high, medium, low or info |
One event can come from several programs, so Command line, Environment and Run match when any of its programs matches, and a negated condition matches only when none of them does. is empty matches events that recorded no command line at all, for example ones reported before the machine sent it.
Errors
If the server cannot run a search (an unknown field, a broken regular expression, a missing value), a red message under the builder says which part is wrong, and the list shows no rows until you fix it.
Clear
Clear removes every condition at once. It leaves the time range and scope alone; Reset in the toolbar clears everything.
The text form
Text shows the same search written as one line, and Builder switches back. The address of the page carries this text as q=, so you can edit a search by hand or paste it to a colleague.
| Written | Means |
|---|---|
field:"v" |
contains |
field="v" |
is |
field^"v" |
starts with |
field$"v" |
ends with |
field~"v" |
matches regex |
field:!* |
is empty |
field:* |
is not empty |
- before a term |
Not |
any: at the start |
Match any (the default is all) |
Field names are the lowercase keys: sink, value, payload, trace, origin, detail, source, url, page, script, extension, host, package, command, environment, run, machine, severity. For example:
sink:"sql" -value:"'?'" machine="web-01"
keeps SQL events on web-01 whose value does not contain '?'. Put quotes around any value with spaces, and write \" for a quote inside a value. If the text cannot be read, Builder refuses to switch and says why, so nothing you typed is lost.
Saved searches
The Saved search picker at the end of the panel stores and restores a whole page state under a name. See Saved searches.