Reviewer Group Email Scope Advanced Options
TIP
For information on creating this query string, refer to the Aurea Messaging Solutions User Guide.
You can create complex reviewer scopes using an advanced search syntax. Use the fields described in the table below to define searches that:
-
Use specific terms, such as all messages that include the phrase
Quarterly Report
. - Use comparisons, such as all messages sent between December 25 and August 1st, or all messages greater than 4 KB but less than 8 KB.
-
Use the Boolean operators
AND
,OR
, andNOT
to refine searches, such as messages from bob@genericorp.comAND
that are smaller than 4 KB. - Search for terms in proximity to other terms, such as terms that appear within four words of each other in a specified order.
To search for a term in any field, type:
field:term
where
field
is one of the fields in Query Language Fields.term
is the value you want to find. To find a phrase, enclose it in double quotation marks.
For example:
To find all messages that include the phrase Quarterly Report
in the Subject field
mailsubject:”Quarterly Report”
To find all messages sent from the email address bob@genericorp.com
mailfrom:bob@genericorp.com
NOTE
Message envelope searches (Recipients (Envelope) and All Recipients filters, or envrecipients and recipients query language fields) can only search the envelope information that Continuity is able to capture.
For undisclosed recipient information (including Bcc recipients), the only addresses that will be captured are internal addresses included in a retention policy.
When searching for undisclosed recipients, the undisclosed recipient headers will not be visible in the search results but the relevant messages will be included in the result set.
Search For Range of Dates or Sizes
To search for mail using a range of dates or a range of sizes, type
field:range(start, end)
where
field
isemaildate
,receiveddate
,totalsize
, orsize
range
defines the beginning and ending points of the search.min
indicates the minimum size or data, andmax
indicates the maximum size or date.
For example:
To find all messages with a total size that is at least 4 KB but no greater than 8 KB
totalsize:range(4096, 8192)
To find all messages sent between December 25, 2018 and August 1, 2019 (local time)
emaildate:range(2018‑12‑25T05:00:00, 2019-08-01T05:00:00)
To find messages sent before December 25, 2018 (local time)
emaildate:range(min, 2018-12-25T05:00:00)
To find messages received on or after August 2, 2019 (local time)
receiveddate:range(2019-08-02T05:00:00, max)
NEAR
To search for words in proximity to each other, type:
near(arg, arg, n=numericValue)
where:
arg
is a word you want to find (use as many as are required, following each by a comma)n=
numericValue
the slop for the search.
Slop is defined as the cumulative number of places that tokens may be moved in order to be considered a match the given phrase.
For example:
near(big, red, car, n=0)
matches:
-
the exact phrase “
big red car
”
near(big, red, car, n=1) matches:
-
the phrase “
big red * car
” (“car
” moved one token) -
and all phrases matched by
n=0
-
but does NOT match “
big * red car
” (both “red
” and “car
” moved one token, for a total slop of 2) near(big, red, car, n=2)
matches:-
the phrase “
big red * * car
” (car
moved two tokens) -
the phrase “
big * red car
” (both “red
” and “car
” moved one token) -
the phrase “
red big car
” (both “big
” and “red
” moved one token) -
and all phrases matched by
n=1
andn=0
-
but does NOT match “
big * * red car
” (both “red
” and “car
” moved two tokens, for a total slop of 4)
To combine search expressions using Boolean operators (AND
, OR
and NOT
), use:
AND
between terms, to indicate both terms must be matchedOR
between terms, to indicate either term may be matched, but at least one must matchNOT
as a prefix to a term, to find terms that do not match the specified criteria- Use matched parenthesis, ‘(‘ ’)’, to group terms
For example:
To find messages that include either the phrase financial report
or the phrase balance sheet
and were sent before December 25, 2018 or after August 1, 2019, but not between those dates
NOT (emaildate:range (2018-12-25T05:00:00, 2019-08-01T05:00:00)) AND (“financial report” OR “balance sheet”)
Find Partially Indexed Documents
To find only partially indexed documents, such as those that are too large or have damaged metadata, add AND indexlevel:1
to the query.
To find documents sent before December 31, 2018 that have not been fully indexed
emaildate:range(min, 2018-12-31) AND indexlevel:1
- Use Caution When Editing Generated Queries
- Maximum Message Size Limitations
- Message Envelope Search Limitations
- Limitations When Formulating Long Queries
- Special Character Limitations
The generated query may contain unfamiliar query arguments such as linguistics or mode. When editing a generated query, do not change these arguments, or the query may not return the expected search results.
The maximum message size that can be fully indexed in the data center archive is 100 MB. Message bodies or individual attachments that are larger than 100 MB are partially indexed using available header fields and metadata.
Message envelope searches (envrecipients and recipients query language fields) can only search the envelope information that Continuity is able to capture.
For undisclosed recipient information (including Bcc recipients), the only addresses that will be captured are internal addresses included in a retention policy.
When searching for undisclosed recipients, the undisclosed recipient headers will not be visible in the search results but the relevant messages will be included in the result set.
In Internet Explorer, the URL length limit of 2083 characters can cause errors when executing a long discovery query. If a query URL exceeds the character limit, Internet Explorer will display an error message and the query will not execute.
This scenario is most likely when using the Query Language or Query Builder options to build a complex query containing many search parameters. Simple searches are not likely to trigger this issue.
One workaround is to use a web browser with longer URL character limits, such as Mozilla Firefox. Another workaround is to narrow the search to fewer parameters.
If you submit a query containing only a single special character (such as a tilde, parenthesis, or exclamation point), the system returns all messages within your reviewer scope. The workaround for this issue is to use at least one alphanumeric character in your query in addition to the special character.
There is a message I think should be in the archive, but I am unable to find it there. Why can't I find it?
A message may not be archived for one of the following reasons:
- The message never reached your inbound mail server (for example, being quarantined for spam or security reasons).
- The sender or recipient of the message is not covered by any retention policy.
- The date of the message falls outside the range of the retention policy covering the user.
I can find an archived message based on the title or date, but not by searching for words within the message content. Why can’t I find these messages by content?
There are certain categories of content that are archived and the header information indexed, but the content itself cannot be indexed. These categories include:
- XML files
- Media files (audio/video/image type)
- Non-standard binary files
- Password-protected ZIP files
- Message bodies or individual attachments that are larger than 50 MB
- Documents with corrupt or malformed content
- Documents with corrupt or invalid content-type information
- These items can still be recovered.