Documentation forSecurity Event Manager

Import and export historical event queries

You can export search queries from SEM historical events in JSON format either as individual queries or by exporting multiple queries.

Export a single query

To export a single query:

  1. On the SEM Console, click the Historical Events and Reports tab.
  2. Select the queries tab and open the category containing the required query.
  3. Move the cursor over the required query and click on the vertical ellipsis icon .

    The Queries menu is displayed.

  4. Click Export.
  5. Enter a meaningful filename and click Save.

Export multiple queries

To export all search queries:

  1. On the SEM Console, click the Historical Events and Reports tab.
  2. Select the Queries tab.
  3. Click the gear icon at the top of the queries list.

  4. The Manage Saved queries window is displayed.

  5. Initially the options are Import and Export All. These change depending on how you proceed.
    • To export all your queries, click Export All.
    • To export a set of queries, use the checkboxes on the left to filter queries by category, whether scheduled or not, etc and select Export Filtered.
    • To export specific queries use the checkboxes in front of the query names and click Export.
  6. Enter a meaningful filename and click Save.

Import queries

To import search queries that have been previously saved as a JSON file:

  1. On the SEM Console, click the Historical Events and Reports tab.
  2. Select the queries tab.
  3. Click the gear icon at the top of the queries list.

    The Manage Saved queries window is displayed.

  4. Click Import.

    The Import Queries window is displayed.

  5. Click Browse file, navigate to the required JSON file, and click Open.
  6. Click Next.

    The queries contained in the selected JSON file are listed.

  7. Filter out any queries you do not want to import by unchecking the boxes in front of the query names, then click Next.

    The import process begins. The queries that are successfully imported are listed. Those that cannot be imported are shown along with the reasons why.

  8. When the import is complete, click OK to close the box. The queries will now be listed in the appropriate categories in the Queries column.