Research Query Pivots
While viewing any application details tab, selecting any object displayed in green takes you to the Research Query page, automatically entering the proper LQL query for the object in the search area. Example: Selecting one of the IP Flow data values on the Dynamic Analysis page takes you to the Research query page, and enters the LQL query:
dynamicSessions.ipFlows.source:"<IP_Value>" AND dynamicSessions.ipFlows.sourcePort:"<Port_Value>".
The query results area lists all applications where the same source IP and Port values were observed during dynamic analysis.
This behavior allows you to easily pivot off of the various application data elements and perform additional research queries without needing to manually transfer the information and enter it into the research query search area.
Within the Research section, each action taken, such as submitting a research query, becomes its own historical checkpoint in the browser. As a result, the user can use the browser back button or history list to return to the research application page to select a different application data element to pivot on.