Apply Not Operator in the Omnibar
The NOT operator in an omnibar is used to exclude specific terms from your search results. Preceding a word with NOT omits any results containing that word, thereby narrowing the search to more relevant information. Multiple NOT operators can be used in a search query for both Shadow/Web and Sanctioned IT data. Additionally, you can also create a report ( PDF, CSV, XLS) for filtered results that utilize the NOT operator. This enhancement assists SOC in identifying critical incidents that need immediate attention and resolution and improves the efficiency of SOC operations.
For instance, you can utilize the NOT operator to exclude Service Names, Service Categories, Service Groups, Incident Type, Response Action, Severity, or other parameters, allowing you to pinpoint specific results.
The NOT conditional operator is available on the following pages:
NOTE: The NOT operator does not support all available filters on the Policy Incidents and Policy Summary pages. For detailed information on specific limitations and known issues, see Limitations and Known Issues of NOT Operator.
How to use the NOT operator in Omnibar?
To use the NOT operator:
- In the Omnibar, enter NOT, and the Logical Operator NOT is displayed as a predictive search text. Click it to add NOT to the Omnibar as a pill.
- You can either search for a segment of a keyword in the Omnibar from the predictive text or select the required filters directly to exclude them from your search. Anything added after the NOT is excluded from your search.
NOT Operator Examples
Services
Search for All Services Except Two
In this example, search for all cloud storage services, except NOT Dropbox and OneDrive.
Search for All Service Categories Except One
In this example, search for all Service Categories, except Social Media.
Use the NOT operator as the first item in the Omnibar, then exclude the Service Category: Social Media.
Search for all GDPR Services that Do Not use TLS 1.2 Encryption
In this example, search for all services that are GDPR High Risk that do NOT use TLS 1.2 encryption.
Search for Low-Risk Services that are Not GDPR
In this example, search for all low-risk cloud storage services that are not GDPR compliant.
Policy Incidents
Search for Policy Incidents with Multiple Exclusions
In this example, search for all policy incidents that have multiple exclusions related to the services Box and Onedrive, as well as the severities classified as Minor and Info.
Policy Summary
Search for all Incident Status Except One, and Exclude the Incidents based on Policy
In this example, search for incidents that are neither new nor from the commonly used files policy.