Network Search Tokens

On the Network tab of the Industrial Control System (ICS) application, use the following tokens to search the network traffic. Build your search queries by using various combinations of these tokens. Click each token for information about how to use it.

Supported Boolean operators

The Qualys Query Language (QQL) supports the following logical or Boolean query operators. Use these operators in your queries to narrow down or broaden your search.

and

not

or

 

Search tokens

asset.name

source.asset.name

destination.asset.name

interfaces.address

source.interfaces.address

destination.interfaces.address

hardware.type

source.hardware.type

destination.hardware.type

interfaces.protocol

interfaces.transport.protocol

destination.interfaces.port

interfaces.macAddress

source.interfaces.macAddress

destination.interfaces.macAddress

traffic.total

traffic.ingress

traffic.egress

 

For information about search tokens on the Assets tab, see Assets Search Tokens.

For information about search tokens on the Vulnerabilities tab, see Vulnerabilities Search Tokens.

For information about search tokens on the Import Asset tab, see Import Asset Search Tokens.