Skip to main content

How to run a search

Create and run a communications search in MirrorWeb Insight.

H
Written by Harriet Christie

Summary

To run a search in MirrorWeb Insight, you build a search query using the Basic or Advanced search form and submit it. The Search page lets you "Construct a compliance search across all of your archived communications". This article covers building and submitting a search from the New search page.

Related: see How to view and navigate search results for what happens after a search runs, and How to use AI-assisted search for building a search from a natural-language prompt.

Prerequisites

  • Login credentials to MirrorWeb Insight

  • Access to run a search. If you do not have run access, the Search button shows the tooltip "You don't have access to run a search".

Step-by-Step Instructions

Step 1: Open the Search page

Navigate to the Search page. The page heading reads Search with the description "Construct a compliance search across all of your archived communications".

The Search page with the Basic and Advanced tabs

Step 2: Choose Basic or Advanced

The form has two tabs: Basic and Advanced. Basic offers a streamlined set of fields; Advanced exposes additional sections such as User actions, Review status, and per-condition connectors.

The Basic and Advanced tabs at the top of the search form

Step 3: Enter your search criteria

Complete the fields relevant to your query. Available sections and fields include:

  • Terms — enter keywords or phrases. The Field dropdown offers All fields, Subject, Body, and Attachments. The condition options are Includes and Excludes.

  • People — filter by Senders and Recipients. The field options include Sender and Recipient.

  • Platforms — filter by communication platforms (placeholder "Filter by communication platforms...").

  • Date — set a Start and End date. Quick select shortcuts are available: Today, Yesterday, Last Week, and the previous month.

  • Sampling — choose Percentage or Quantity and enter a sample value.

  • Flagged messages — options are All, Only flagged, and Only non-flagged.

The search form with Terms, People, Platforms and Date sections

Step 4: Estimate results (optional)

Before running, you can click Estimate to calculate an approximate result count for your current criteria. The button shows "Estimating..." while it runs.

The Estimate button in the search actions row

Step 5: Run the search

Click the Search button. While the search runs the button shows "Searching...". When the search completes you are taken to the results page.

The Search button in the search actions row

Notes

  • You can also save your query for later use. Use Save template to save the query as a reusable template, or Save to vault to run the search and store its results in a named vault. See How to create and manage search templates.

  • Large queries may be processed asynchronously. In that case a notice appears: "This query may take a few minutes to complete. We'll send you an email as soon as the search results are ready to view. If you saved this search to a vault, you can view the results there."

  • If too many searches are run in a short period, search is rate limited with the message "You've run too many searches, please wait a few minutes before trying again."

  • If the selected identity or identity group has no associated accounts, you will see "No accounts were found for the selected identity or identity group."

Did this answer your question?