Advanced search

The Advanced search panel under the events toolbar holds the time range, the scope, the condition builder and your saved searches. This page explains each of them and the text form of a search.

The panel

Click Advanced search under the toolbar to open or close the panel. The number beside its title counts how many of its filters (From, To, scope and each condition) are narrowing the list right now, so a closed panel never hides a filter from you.

The panel opens by itself when you arrive from a link or saved search that uses it. Everything in it is written into the page address, like the toolbar filters (see Filtering).

Time range

From and To limit the list to events that happened between two moments, precise to the second. Type a time in whatever way is natural; the exact instant EyalSec read appears under the box, in your time zone. Leave a box empty for no limit on that side.

You type It means
2026-08-10 14:30 that minute, in your time zone
2026-08-10 that whole day
10/08/2026 a day, with day and month in your browser's usual order
10 aug 2026 2:30pm, aug 10, 2026 14:30 the same minute, with the month named
14:30, 9am, noon, midnight today, at that time
2h ago, 45 minutes ago, -15m, 7d, 3 months ago that long before now
in 3 days, +1w that long after now
now, today, yesterday 09:00, tomorrow keywords, with an optional time
2026-08-10T14:30:00+03:00 an exact instant with its offset
1786554930 a unix timestamp, in seconds or milliseconds

A bound without a time covers the whole unit it names: From starts at the beginning of it and To runs to the end. So To: 2026-08-10 includes all of that day, and To: 14:30 includes all sixty seconds of 14:30.

Always read the line under the box. 08/10/2026 is August 10th to some readers and October 8th to others; the line shows which one was used. If a box holds something it cannot read, it turns red and says so, and the list keeps showing the last range that made sense rather than dropping the limit.

Times are in the time zone set in Settings. Typing a time turns off any quick range.

Scope

The scope pins the list to one place in your code: a source path on es-python, a page host on es-chromium. Pick how to match (is, ends with or matches regex) and type the value; × clear removes it.

Events that carry no such value are left out while a scope is set. Tick include events with no path (the wording follows the product) to keep them.

List Scope field Example
es-python Path (a source path) ends with app/views.py
es-chromium Host (the page host) ends with .example.com

Conditions

Conditions let you search fields the toolbar does not cover, such as the value, the stack trace or the command line. Each condition is a row of field, operator and value; click + Add condition to add one and × to remove it. The list reloads as you type.

Conditions are available on the es-python and es-chromium lists. You can have up to 12.

Match all or any

Match all keeps events that satisfy every condition; Match any keeps events that satisfy at least one. The choice applies to the whole set.

Operators and Not

Every text comparison ignores case except is, which must match exactly.

Operator Keeps events whose field
contains contains the value anywhere
is equals the value exactly
starts with begins with the value
ends with ends with the value
matches regex matches the regular expression
is empty has no value (no value box)

The Not button on a row reverses it, so "contains" with Not means "does not contain" and "is empty" with Not means "is not empty".

Fields

The fields you can search depend on the list.

Field Lists Searches
Sink es-python, es-chromium the sink label
Value es-python the untrusted value that reached the sink
Payload es-chromium the value at the sink
Stack trace es-python the stack trace
Origin es-python the origin block
Detail es-python the detail line (file path, regex, ...)
Source es-chromium the source label
URL, Page, Script, Extension, Host es-chromium the request URL, page, script, extension and page host
Command line, Environment es-python the command line and environment of the programs that produced the event
Run es-python one program invocation (see Runs)
Machine es-python, es-chromium the machine name
Severity es-python, es-chromium critical, high, medium, low or info

One event can come from several programs, so Command line, Environment and Run match when any of its programs matches, and a negated condition matches only when none of them does. is empty matches events that recorded no command line at all, for example ones reported before the machine sent it.

Errors

If the server cannot run a search (an unknown field, a broken regular expression, a missing value), a red message under the builder says which part is wrong, and the list shows no rows until you fix it.

Clear

Clear removes every condition at once. It leaves the time range and scope alone; Reset in the toolbar clears everything.

The text form

Text shows the same search written as one line, and Builder switches back. The address of the page carries this text as q=, so you can edit a search by hand or paste it to a colleague.

Written Means
field:"v" contains
field="v" is
field^"v" starts with
field$"v" ends with
field~"v" matches regex
field:!* is empty
field:* is not empty
- before a term Not
any: at the start Match any (the default is all)

Field names are the lowercase keys: sink, value, payload, trace, origin, detail, source, url, page, script, extension, host, package, command, environment, run, machine, severity. For example:

sink:"sql" -value:"'?'" machine="web-01"

keeps SQL events on web-01 whose value does not contain '?'. Put quotes around any value with spaces, and write \" for a quote inside a value. If the text cannot be read, Builder refuses to switch and says why, so nothing you typed is lost.

Saved searches

The Saved search picker at the end of the panel stores and restores a whole page state under a name. See Saved searches.

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo