Skip to content

Analytics

Open Reports > Analytics for a summary of runtime activity over a selected period. Results respect your sensor access.

For an investigation that needs progressive loading through more history, use Investigate.

Run a query

  1. Choose a Time range. The default is Last 24 hours.
  2. Filter by Event kind, Severity, or Sensor.
  3. Enter a Keyword when you know a process, message, or other event detail.
  4. Select Run Query.

For Custom range, enter From (local time) and Until (local time). The end must follow the start, and the window can span up to 30 days. Available history depends on retention.

Changing the form does not apply a new query until you select Run Query. Refresh reruns the current form.

Read the results

Analytics returns up to the latest 2,000 matching events, shown 100 per page. The charts and counts summarize these returned events, not all matching history.

  • Select a row to inspect its evidence.
  • Use Previous and Next to move through loaded results.
  • Select a process under Hot Processes to apply a process filter.
  • Use Clear process filter to remove it.

A process filter can match part of a process name or path. Review the filtered result before treating it as one exact executable.

Export

Select Export CSV to download all loaded results, including pages you have not opened.

The export does not retrieve additional history. If the result limit is reached, narrow the time range, sensor, or event conditions before exporting.

Troubleshooting

SymptomWhat to check
No resultsConfirm the sensor scope, range, and filters. Check that the sensor was reporting during that period.
Results stop at 2,000Narrow the query or use Investigate to continue searching more history.
A chart differs from a fleet-wide totalAnalytics charts summarize only the returned events.
Query failsReview the reported error and retry. A failed query is not evidence of zero activity.

Released under the Telovix Commercial License.