Improve log filtering workflow with quick “exclude / NOT filter” option from Traffic logs

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Improve log filtering workflow with quick “exclude / NOT filter” option from Traffic logs

L1 Bithead

Hi team,

 

I’d like to suggest a small but impactful improvement to the Traffic Logs filtering workflow.

Today, when we click on a value in a log entry (e.g. source IP, destination IP, user, etc.), it automatically adds that value to the search bar as a positive filter (e.g. eq / in). This is extremely useful and significantly speeds up building queries.

However, during investigations, it is very common to also build exclusion filters (e.g. neq / not in) while drilling into traffic patterns. Right now, this requires manually editing the query after adding the value, which slows down the workflow.

Suggestion:
Introduce a quick way to add a value as a negated filter directly from the log view. For example:

  • Standard click → adds positive filter (current behavior)
  • Shift + click (or another modifier / UI option) → adds the same value as a negative filter (neq / not in)

Benefit:
This would significantly speed up investigative workflows by allowing analysts to quickly include or exclude values without manually editing the query syntax, reducing friction and improving usability during time-sensitive troubleshooting.

Thanks for considering this improvement — it would be a great enhancement for daily SOC / network analysis workflows.

0 REPLIES 0
  • 32 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!