Skip to main content

How should Spotter AI handle searches across similar fields?

  • November 17, 2025
  • 1 reply
  • 47 views

Forum|alt.badge.img+1

When searching in Spotter AI, entering a generic field name like “hostname” may not return results from all related attributes. Currently, Spotter AI appears to select one matching field (e.g., hostname) instead of searching across all similar variations such as:

  • devicehostname

  • sourcehostname

  • destinationhostname

  • host

This means a query like:

“Provide me all violations involving the hostname XYZ.acme.com”
may return only a subset of results instead of all logs where that hostname appears in any related field.

 

We’d like to better understand how you’d want Spotter AI to interpret these kinds of queries:

  • Should Spotter AI automatically include all fields with a common root term (e.g., “hostname”) in a single search?

  • Would you want to customize or map which fields are grouped together (e.g., host-related, IP-related, user-related)?

  • How important is this for improving your accuracy and efficiency in investigations?

  • What examples or use cases best illustrate when a broader, context-aware search would be helpful?

Your feedback will help define how Spotter AI could provide smarter, more intuitive search behavior in the future.

👉 If you have a specific design or workflow in mind, please create a new Idea describing how you’d like Spotter AI to handle multi-field or context-aware searches.

1 reply

  • New Member
  • November 19, 2025

I think Spotter AI should understand the specific data sources in use in a customer tenant. It should then inventory the attribute mappings and use that as a start to find what all attributes, even those with different names across data sources, return the same information.
Ideally, another agent then suggests remapping attributes so all data sources use the same attribute mappings.