Custom Queries

Harmony Email & Collaboration stores the metadata of all items (emails, files, user logins, etc.) obtained through the public APIs of the cloud applications you are protecting and inspected by the system.

For items found to be harmless, metadata is retained for two weeks.

For malicious items, the data is stored indefinitely.

Custom Queries give you direct access to this database of metadata.

Use Custom Queries to:

  • Troubleshoot

  • Build custom reports

  • Perform bulk action such as quarantining phishing emails

Creating and Saving a New Query

You can create and save custom queries to analyze a specific SaaS for immediate and future use.

Editing the Query Columns and Conditions

After you have selected a template, use the options in Custom Queries to edit the template for your specific needs.

You can edit the template's predefined columns by choosing to add, remove or rename columns.

In addition, you can set conditions on columns.

Bulk Actions on Query Results

Click on Manual Actions to see options for bulk remediation: quarantine, move to junk or add phishing alert.

If no items in the query's results are selected, the action will be taken on all items. You can select only some items before choosing a manual action to apply that action on those items only.

Additionally, the Send email report option sends an email alert to your email for each item selected in the query's result. A pop-up enables you to configure the template before sending alerts.

Exporting a Query Results

In Custom Queries, you have an option to export the query's results to your email.

This sends an email to your email address with the query's results in any of these file formats.

  • CSV

  • JSON

  • XLSX

Scheduled reports based on Custom Query results

Using a Query as a Detect and Remediate Policy Rule

Sometimes you may want to create an action (such as quarantine) that will apply to future events matching the query's conditions. In such a case, you can use your query as a policy rule in the Detect and Remediate mode.

Note - No action will be taken on the current results of the query, only future results will be impacted.

To use the query as a Detect and Remediate rule:

  1. In Custom Queries, open a saved query.

  2. Click Query Actions.

  3. Choose an action, such as quarantine, from the list of available actions.

  4. In the pop-up window that opens, you can choose to edit the name of the action, and then click OK.

    Afterward, the action should appear in the menu under Query Actions.

    Note - Actions linked to queries are automatically taken from that point forward in the Detect and Remediate mode. However, policy rules keep priority over custom queries.