Arctera™ Insight eDiscovery Help
- About Arctera Insight eDiscovery
- Getting started with Insight eDiscovery
- Insight eDiscovery roles
- Managing investigations
- About Investigations
- About Targeted Collections
- Adding targeted collection for Microsoft Teams
- Adding targeted collection for OneDrive for Business
- Adding targeted collection for Exchange Online
- Adding targeted collection for Enterprise Vault
- Adding targeted collection for data import
- Managing Insight Capture collectors from Insight eDiscovery
- Sending collected data to cases
- About Analytics Dashboard
- About Managed Accounts
- About Searches in investigation
- About Hit Highlighting
- Working with searched emails
- Working with searched collaboration messages
- Working with searched files
- Working with Advanced ECA searches
- Creating an Advanced ECA search
- Updating an Advanced ECA search
- Filtering an Advanced ECA search
- Applying tags to the Advanced ECA search items
- Applying labels to the Advanced ECA search items
- Exporting the Advanced ECA search items
- Exporting an Advanced ECA search summary report
- Reassigning emails from the Advanced ECA search
- Printing the selected Advanced ECA searched items
- Deleting an Advanced ECA search
- Creating archive sets during investigation
- About Mail Reassignment
- About labels
- About legal holds
- About Tags
- About search log
- About transcription of media attachments
- Managing cases
- About cases
- About case workflow summary: eDiscovery Administrator
- Creating case review statuses
- Creating cases
- Adding parent tags and their child tags
- Applying tags to the searched items in cases
- Removing tags of the searched items in cases
- Viewing case details
- Editing cases
- About searches in eDiscovery
- Managing case documents
- Managing redaction reasons
- Managing reviews
- About reviewing cases
- Reviewing emails
- Accessing emails for review
- Searching for the exact Insight Surveillance item for review
- Applying tags to emails
- Exporting emails
- Exporting a search summary report for emails
- Adding notes to emails
- Applying review status to emails
- Viewing audit history of emails
- Printing emails
- Restoring emails
- Forwarding emails
- Reviewing collaboration messages
- Accessing collaboration messages for review
- Applying tags to collaboration messages
- Applying legal hold to collaboration messages
- Applying and removing review status to collaboration message
- Exporting collaboration messages
- Exporting a search summary report for collaboration messages
- Adding notes to collaborative messages
- Viewing audit history of collaboration messages
- Printing MS Teams messages to PDF during eDiscovery
- Reviewing files
- Annotating and redacting email and file content in native viewer
- Managing production sets
- Annotating and redacting content in native viewer
- Managing exports
- Collaborative reports
- Insight eDiscovery alerts
- Email Continuity
- Methods for searching cases and accounts
- Performing Advanced Search and Query Search
- Search syntax for Advanced Search
- About stop words and special characters
- About Hit-highlighting and navigating to searched terms
- Phrase searches
- Boolean operator searches
- Wildcard searches
- Proximity searches
- Double-byte character set searches
- About enhanced searches in Japanese
- Searchable attachment types
- Search examples and tips
- Methods for searching tables and reports
- Insight eDiscovery Frequently Asked Questions
- Best practices, limitations, and known issues
- Insight eDiscovery updates in previous releases
Search examples and tips
Suppose you want to search for the messages that relate to the resetting of a password. You can enter password reset into the Search box and click to perform a Search. The space between password and reset is treated as an AND operator, so the returned results contain any messages that include both the word password and the word reset.
Suppose that you now decide to search for the phrase password reset, and to exclude from the results any emails that reference the word Box. You can use an Advanced Search for this purpose. Click the expand icon to display the Advanced Search options. Your original Search is now shown in the first criteria row.
Insert double quotation marks around password reset to specify it as a phrase. Then click to add a second criteria row. In the new criteria row, select and enter Box in the text field.
Click to perform the search. The search returns any items that do not contain Box but that contain the exact phrase password reset.
Table: List of query search terms lists some possible query search terms along with examples.
Table: List of query search terms
Search term | Data type | Description | Example |
|---|---|---|---|
_All, Entiremessage | Text | Searches through all default fields. Add search criterion before query text/value. | _All:(test or test2) "hello world" Entiremessage:test |
Attachments.content | Text | Search by attachment content. | Attachments.content: "Hello World" |
Attachments.extension | Text | Search by attachment file type (PDF, DOC, docx, and so on.) | Attachments.extension:docx |
Attachments.filename | Text | Search by the file name of the attachment. | Attachments.filename:Report.PDF |
Attcount | Integer | Search by the amount of attachments. Note: This query search term does not support the Searches for the Microsoft Teams messages. | Attcount:6 |
Attflag | Boolean | Search by whether there is an attachment. | Attflag:true |
Atttext | Text | Search the content of the attachments. | Atttext:Computers |
Atttypes | Text | Search by the attachment type. | Atttypes:PDF |
Bcc | Text | Search by blind carbon copy recipients. | Bcc:JoeBlogs@example.com Sender:*@example.com |
Cc | Text | Search by carbon copy recipients. Note: This query search term does not support the Searches for the Microsoft Teams messages. | Cc:JoeBlogs@example.com Sender:*@example.com |
Classification.tags | Text | Search by classification tags. Note: This query search term does not support the Searches for the Microsoft Teams messages. | Classification.tags:PII |
FromOrTo | Text | Search the text in the From and/or To fields of the email. | FromOrTo:JoeBlogs@example.com |
Hidden | Boolean | Search whether email is visible to end user or not. Note: This query search term does not support the Searches for the Microsoft Teams messages. | Email Hidden: Hidden:(1) Email Visible: NOT Hidden:(1) |
Inbound | Boolean | Search inbound emails. Note: This query search term does not support the Searches for the Microsoft Teams messages. | Inbound:false |
Internal | Search and retrieves only internal messages exchanged within the same organization. Note: This query search term does not support the Searches for the Microsoft Teams messages. | To include internal emails, use: Internal:(3). To exclude internal emails, use: NOT Internal:(3). | |
Ipheader | IP Address | Search by the IP header of the email. Note: This query search term does not support the Searches for the Microsoft Teams messages. | Specific IP Address: Ipheader:(10.201.1.1) IP Address using wildcards: Ipheader:(10.*.1.1) AND Ipheader:(10.201.?.1) |
MailDate | Date Time | Search by the date the message was sent. | Closed Range: MailDate: [2018-01-01T00:00:00 TO 2019-12-31T23:59:59] Open Range: MailDate: {2018-01-01T00:00:00 TO 2019-12-31T23:59:59} |
Messagesizeinkb | Floating Point Number | Search by total size of the email. Note: This query search term does not support the Searches for the Microsoft Teams messages. | Messagesizeinkb:[2.5 TO 5] |
Outbound | Boolean | Search whether a user sent the email. Note: This query search term does not support the Searches for the Microsoft Teams messages. | Outbound:true |
Sender | Text | Search by the sender address(es). | Sender:JoeBlogs@example.com Sender:*@example.com |
Subject | Text | Search by the subject of the email. | Subject:IT |
SubjectBody | Text | Search the text in the subject of emails and/or in the content of the email. | SubjectBody:Test |
Textbody | Text | Search the text content of the email. | Textbody: "Hello World!" |
To | Text | Search by recipient. | To:JoeBlogs@example.com To:*@example.com |
Examples of Query Searches:
Sourcetype:"Exchange"
SourceType:{"Exchange" OR "Citrix"}
MailDate:[2016-05-14T05:00:00 TO 2019-06-18T08:00:00]
Messagesizeinkb:[0.0 TO 11.5]
Subject:(export OR report)
MailDate:[2016-05-14T05:00:00 TO 2019-06-18T08:00:00] AND subject:archive
Sender:(*@domain.com OR *@domain2.com OR *@domain3.com)
Atttypes:(pdf OR docx) AND atttext:process
Attachments.filename:(Report.PDF or Export.docx)
The , , and search options are available within an Advanced Search.
The option provides search results from the To, BCC, and CC fields.
The option provides search results from the From field.
The option provides search results from the From and To fields.
One way to search for items within a specific domain is to enter the domain name in the To field of an Advanced Search.
You can use wildcards to search for results from a group of similar domains. For example mycloud* returns emails for the domains that begin with mycloud.