Search
Search in Sophos XDR provides powerful tools to investigate security data across your environment. Use our search tools to:
- Query detections and events.
- Build and save searches.
- Use AI to generate natural-language queries.
- Pivot on key data points throughout Sophos XDR.
Data Lake Search
Data Lake Search is the primary interface for querying detections and events in your tenant. For more information, see Data Lake Search.
Data Lake Search offers three main modes:
-
AI Search: Use natural language to generate queries with AI Search, making it easier to retrieve relevant data without knowing the query syntax. For more information, see AI Search.
-
Query Builder: A visual, guided interface for constructing queries without writing code. For full documentation, see Advanced Search query language.
Features include:
- Select detections or events and choose event types, such as process, auth, and netflow.
- Add multiple criteria and use AND/OR logic.
- Support for nested queries and logical types.
- Save and add searches to cases.
- For full documentation, see Query Builder.
-
Query Editor: Write advanced, flexible queries using a custom syntax. For full documentation, see Advanced Search query language.
Features include:
- Operators for string matching, regex, wildcards, and CIDR notation.
- Inline help, schema library, and query examples.
- Save and add searches to cases.
- Column customization and result filtering in the UI.
- Support for logical types (like
@ip,@user, and@host) to simplify cross-schema searches. For more information, see Logical types.
Search management features
- Saved queries: Save and organize queries for reuse. View your own or your organization’s saved queries, filter and sort them, and add them to cases. For more information, see Saved queries.
- Search history: Review and filter executed searches from the past 30 days. Reload results or edit previous queries. For more information, see Search history.
Live Endpoint Search
Live Endpoint Search lets you run real-time queries on Sophos Endpoint-protected devices to look for signs of a threat or assess compliance.
You can use Live Endpoint Search queries to search devices for signs of threats that haven’t been detected by other Sophos features. For example:
- Unusual changes to the registry.
- Failed authentications.
- A running process that is very rarely run.
For more information, see Live Endpoint Search.
Pivot search
Quickly investigate related detections and events by pivoting from details such as IPs or usernames. For more information, see Pivot search.
Quick search
Run single-term search queries to find data across multiple data types. For more information, see Quick Search.