Query records with an advanced filter
You can query records that are stored in the recordstore from multiple areas in the ExtraHop Web UI.
The following figure shows the main records page, that you access by clicking Records from the top menu.
Note: | You can also automate this task through the REST API. |

- Click Records from the top menu to start a new record query for all records stored on the Explore appliance or other supported recordstore.
- Click the Load icon
from the top of the page to access any saved queries.
- Type a search term in the global search field at the top of the screen and click Search Records to start a query across all stored records.
- From a device Overview page, click View Records to start a query filtered by that device.
- Click the Records icon
from a chart widget, as shown in the following figure.
- Click the Records icon
next to a detail metric after drilling down on a top-level metric. For example, after drilling down on HTTP Responses by Server, click the Records icon to create a query for records that contain a specific server IP address.
Note: | To create a record query for a custom metric, you must first define the record relationship by linking the custom metric to a record type. |
No matter where you start your query from, you might have a large set of records results. You can narrow down your results by applying filters to find the specific record you need.
Next steps
- Filter your record query
- To learn how to query for a specific record, see our walkthrough for Discovering missing web resources.
Filter your records with advanced query rules
For advanced queries, you can create and modify complex filters by clicking the Add
Advance Filter button or by
clicking the pencil icon
next to any filter that you have added.

- You can specify multiple criteria with OR (Match Any), AND (Match All), and NONE operators
- You can group filters and nest them to four levels within each group
- You can edit a filter group after you create it
- You can create a descriptive name to identify the general purpose of the query
Create a complex filter with AND and OR operators
The following example shows how you can create an advanced query to filter your records with complex criteria. We will create a filter to return results for all HTTP records that include two URIs plus a status code greater than or equal to 400 or a processing time greater than 750 milliseconds.
Important: | To try this example on your own Discover appliance, you must have HTTP traffic on your network. |

Next steps
You can click the Save icon
Thank you for your feedback. Can we contact you to ask follow up questions?