Advanced Search Techniques

  • Updated

The Query module provides more than basic keyword searching. In addition to running standard data queries, it supports powerful investigation capabilities such as searching across multiple OWL products, performing multi-jump pivot searches, exploring structured data stored in OWLvault, visualizing relationships through Link Analysis, and creating Monitoring tasks to automatically track future matches.

These capabilities help investigators discover relationships between entities, expand searches across connected records, and continuously monitor data for new activity.
 

Capabilities of the Query Module

The Query module supports the following capabilities:

  • Search across multiple OWL products and external vendor data sources.
  • Perform multi-jump pivot searches to follow relationships between connected entities across different data products.
  • Search structured data imported into OWLvault.
  • Filter searches by specific imported data sources.
  • Explore relationships using Link Analysis.
  • Review complete record details in Tabular View.
  • Analyze relationship strength using the Relationship Matrix.
  • View results in Geospatial View when address or location information is available.
  • Create Monitoring tasks from search results for continuous tracking.

OWL Internal Product Searches

The Query module can search across your organization's own OWL data, depending on the collaboration settings configured for you and your organization. These internal products search records that your team has already created or imported into the system.
 

OWL Products

  1. Cases - Searching Cases returns any Case records containing your search criteria and all records attached to them, including Subjects linked to the Case, as well as any Forms, Tips, and Reports. The search criteria are matched against Case Notes, custom field values, Template data, and the content of attached records. This provides a comprehensive view of everything related to a matching Case.
  2. Subject - Searches Subject records in your OWL instance, whether linked to a Case or standalone. Matches against Subject name, Notes, and Subject Template values.

  3. Query - Searches previously-run searches that are not linked to any Case or Subject. Matches against the search variable of existing Query records.

  4. Forms - Searches Form records and their field values. Matches against individual field entries within completed forms.
  5. Tips - Searches Tips records submitted through the Tips module.
  6. Docs - Searches documents uploaded to Cases or Subjects. Searches extracted text content, and transcriptions -- not just file names. Returns matching documents with their parent Case or Subject context.

  7. Vault - Searches through structured records imported via OWLimport (Excel, CSV, JSON). Each row or object is an individually searchable record.

  8. Reports - Searches Report records stored in the system.
     

Why Search OWL Internal Products?

  • Avoid duplicating investigations. Before starting a new Case, search OWL Cases and Subjects to check whether someone has already investigated the same person or entity.
  • Connect new findings to existing work. When an external vendor search reveals a new name or identifier, search OWL Subjects and Cases to check whether another investigator has already created a record for that person. If so, you can collaborate with that investigator to build upon the investigation.
  • Leverage previously imported data. OWLvault records from prior imports may contain relevant information that external sources do not have.
  • Find supporting documentation. OWLdocs may contain scanned documents, investigator notes, or uploaded evidence related to your search criteria.

Key Differences from External Products

  • No third-party subscription required - OWL internal products are always available to users with both Query and Case/Record Management access.
  • Your data, your records - Results come from data your organization has entered or imported, not third-party databases.
  • Cross-product discovery - Searching multiple OWL products simultaneously reveals connections between Cases, Subjects, documents, and imported data that might otherwise go unnoticed.
  • Pivot-compatible - Results from OWL internal searches can be pivoted into external products (and vice versa), bridging your internal knowledge with external data sources.

Searching Multiple OWL Products Simultaneously

You can select multiple OWL products in a single search. For example, searching a name across Cases, Subjects, Vault, and Docs simultaneously returns all internal matches in one result set. This eliminates the need to run separate searches against each record type.
 

Search Methods

The Query Data module provides multiple search methods to suit different investigative needs:
 
Search Method Description Best Used For
Datasource Search Select a specific vendor and product (e.g., Person, Phone, Criminal) and enter product-specific parameters such as SSN, name, address, phone, or email. Targeted lookups, when you know the data type and have specific identifiers.
Keyword Search Search across selected products using structured keyword terms. Finding records that match known values across multiple products simultaneously.
Free Text Search A mode within Keyword Search that enables unstructured text searching across OWL datasets. Toggle the Free Text checkbox to activate it. Broad discovery when you have partial or unstructured information.
Wildcard/Range Search Search using date ranges, numeric ranges, or amount ranges with AND/OR logical operators between multiple criteria fields. Investigating patterns across time periods, finding records within value ranges, or combining multiple flexible criteria.
Geospatial Search Select one or more addresses on a map and search for records associated with those geographic coordinates. Supports searching multiple addresses simultaneously. Location-based investigations, identifying activity near specific addresses, or mapping investigative subjects geographically.
Smart City View
An advanced geospatial capability (available in the Smart City edition) that overlays your OWL search results on map alongside external contextual data layers such as traffic and transportation, weather and environment, demographics, jurisdiction and infrastructure boundaries, and/or satellite imagery. Builds on Geospatial Search with richer situational context.
Enriching investigations with real-world context, improving situational awareness during incident response, and supporting proximity and resource-planning analysis.

Choosing the Right Product for Your Search

The type of information you are investigating should guide your product selection. OWL searches fall into two groups: OWL internal products (your organization's own data) and external Whooster products (third-party data sources that require an active subscription for Whooster Data).
 

OWL Internal Products

Search your organization's own investigative data first, to find prior work and avoid duplicating investigations.
If you are investigating… Recommended OWL products
Whether a person or entity has already been investigated OWL Cases and OWL Subjects
Previously run searches that are not linked to a Case or Subject OWL Query — orphan Data Query records
Your organization’s imported structured data OWLvault, with optional Data Source filtering
Uploaded documents, evidence, or scanned files OWLdocs — searches extracted text, transcriptions, and AI narrations
Completed custom form submissions or records Forms
Tips submitted or created through the Tips module Tips
Previously generated reports Reports
 

External Whooster Products

Use external products to enrich an investigation with third-party data (subscription required).
If you are investigating… Recommended products
A name, email, address, SSN, or phone number, looking for the person’s identity or background Person, Advanced Phone & Person
Phone numbers or communication information, looking for who is associated Basic Phone, Basic Phone Plus
Criminal history or sanctions Arrest Records, National Instant Criminal Comprehensive
Business entities or corporate connections Business Entity, UCC
Property ownership or asset information Real Estate Basic (option to include History), Real Estate Comprehensive,
Medical-provider verification NPI Registry
Your organization’s imported structured data OWLvault, with optional Data Source filtering
Previously captured internal investigative data OWL Cases, Subjects, and available OWL records
Social-media presence and/or breach data Phone, Email, or Username, Facebook or Instagram ID, IP address (for breach data)
Vehicle or driver information Motor Vehicle Information (plate validation), Motor Vehicle Records, Driver and License Records

 

OWLvault Product Search

OWLvault enables you to search structured data that has been imported into OWL through the OWLimport process. Supported file formats include Excel (XLS/XLSX), CSV, and JSON.

When these files are imported:

  • Each row in an Excel or CSV file is converted into an individual OWLvault record.
  • Each object in a JSON file is converted into an individual OWLvault record.
  • Each vault record can be:
    • Linked to a Case.
    • Linked to a Subject.
    • An OWLvault record may be linked to a Case, linked to a Subject, or stored independently when it is not associated with either.

This allows users to search individual imported records instead of treating the uploaded file as a single document.

How OWLvault Product Search Works

During an OWLvault Product Search:

  • OWL compares the search criteria against the imported OWLvault records.
  • Records containing one or more matching values are returned as search results.
  • If the search is initiated from a Case or Subject, OWL also displays any OWLvault records already attached to that Case or Subject that do not match the search criteria. These records are displayed separately as Unmatched OWLvault Records, providing additional context for the investigation.

Steps to Perform an OWLvault Product Search

  1. Open the Query module and choose a search method, such as Datasource, Keyword, Free Text, or Wildcard/Range Search.
  2. Select OWLvault as the product to search.
  3. Enter the search criteria. For example, searching for a full name together with a phone number causes OWL to compare each value against the imported OWLvault records.
  4. (Optional) Select one or more Data Sources from the Datasource drop-down list to limit the search to specific imported datasets.
  5. Click Search

    If matching records are found, they are displayed under the OWLvault datasource in the search results.

OWL Query Product Search

In OWL, a Query is a Data Query Search created when a user runs a search. A Query record stores the search details and related results.

When you select OWL Query as a search product, OWL searches Data Query records that are not associated with a Case or Subject. These are referred to as orphan Data Query records.

If the entered keyword or search value matches a search variable in an existing orphan Data Query record, OWL returns that Query in the search results. Results are displayed under the Query Data Source node.

What OWL Checks During a Query Search

When searching OWL Query records, OWL checks:

  • Whether the Data Query Search variable matches the entered search criteria.
  • Whether the record is accessible to the user based on their license type and Collaboration.
  • Whether the Query is an orphan Data Query record that is not linked to a Case or Subject.
  • The current search is excluded from its own results.

For example, when an administrator performs an OWL Query Product Search, OWL can search accessible orphan Data Query records across the organization.

Perform an OWL Query Product Search

You can search OWL Query records using Datasource, Keyword, or Free Text searches.

  1. Enter the search criteria.
  2. Select OWL Query as the product to search.
  3. Select Search.

    OWL compares the entered values individually against existing orphan Data Query records.

  4. Review matching Query records in the Results view.

For example, if you search using both a full name and phone number, OWL checks each value against the search variables in eligible Query records.

View Results

In Link Analysis:

  • The OWL Queries Data Source node displays the number of matching Query records.
  • Each returned Query appears as a separate node connected to the datasource node.
  • Returned Query records are orphan Data Query records that are not linked to a Case or Subject.
  • Click on Query node to review the matched values.

In Tabular View:

  • Each row represents a returned Query record.
  • Expand a row to review available search details.
  • Review the matched attributes to understand why the Query was returned.

Multi-Jump Pivot Searches

Pivot searches are one of the most powerful capabilities in the Query module. They allow you to follow connections between entities across different data products, progressively expanding an investigation without needing to start a new search from scratch.

How Pivot Searches Work

  1. After executing a search, locate a node or record of interest in the search results. Pivot Search is available in both Link Analysis and Tabular View.
  2. Click the Pivot Search (spyglass) icon on the node or record.

    A menu displays the searchable values extracted from that record, such as names, phone numbers, email addresses, addresses, dates, and other mapped attributes.

  3. Select a value to pivot on.
  4. Select the available product or products to search with the selected value.
  5. Click Search to execute the Pivot Search.

Only products included in your organization’s subscription and available to your user account can be selected.

Background Execution

Pivot Searches run asynchronously in the background, allowing you to continue working while the search is processed.

  • A notification confirms that the Pivot Search has started.
  • The current screen remains available while the search is processing.
  • The search status appears in the Case Intelligence Workspace.
  • When the search is complete, select View Results to review the returned records.

Multi-Jump Investigations

Each Pivot Search result can be used as the starting point for another Pivot Search. This enables a multi-jump investigation, where each search expands the investigation by following related entities across available data products.

For example, an investigator may start with a vendor name in OWLvault, pivot to a phone number, then use the phone number to search for related people, businesses, or criminal records.

Additional Searches

The spyglass menu may also display Additional Searches. These are product-specific searches that may be available based on the selected record or entity.

Additional Searches differ from Pivot Searches because they are predefined by the system for the selected record type, rather than requiring the user to select a value and target product.

In this example, selecting Victoria Doe under the Whooster Person header will immediately perform a Person search on this particular Victoria Doe, instead of running a Person search on just the first and last name attributes, meaning the Victoria Doe returned will be the same person referenced on the Jon Doe result. To search for all Victoria Doe records, select her name from the Pivot Searches section instead.

Viewing Search Results

Search results can be reviewed in multiple views. Use the available view controls to switch between result views.

Link Analysis View

The Link Analysis view displays search results as an interactive relationship graph.

Use Link Analysis to:

  • Visualize relationships between people, businesses, addresses, phone numbers, and other entities.
  • Review connections between records from different data sources.
  • Start Pivot/Additional Searches from a node.
  • Explore direct and indirect relationships visually.

OWLvault records are grouped under their applicable datasource nodes. Select a node to review available record details and actions.

Tabular View

The Tabular View displays search results in a structured, expandable table.

Use Tabular View to:

  • Review records in a detailed table.
  • Expand records to view available field values.
  • Identify values that match the search criteria.
  • Compare multiple records.
  • Start a Pivot/Additional Search from an available record value.

Each row represents an individual returned record. OWLvault records already associated with the Case or Subject but not matching the current search criteria may appear separately as Unmatched OWLvault Records.

Relationship Matrix View

The Relationship Matrix displays relationships between returned identity records in a matrix format.

Use this view to:

  • Identify entities with stronger or more frequent connections.
  • Review relationships across a larger number of returned entities.
  • Prioritize relationships for further investigation.

Geospatial View

The Geospatial View displays returned records on a map when address or location information is available.

Use this view to:

  • Identify geographic patterns.
  • Compare subject or entity locations.
  • Review records near a particular location.
  • Identify clusters of activity.

 

When to Use Which View

Investigation Goal Recommended View Why
Understanding how entities and queries are connected/related Link Analysis Displays direct and indirect relationships visually.
Reviewing detailed record information Tabular View Displays individual record values in a structured table.
Identifying stronger relationships Relationship Matrix Helps prioritize entities with notable connections.
Identifying geographic patterns Geospatial View Displays address or location information on a map.
Performing a Pivot Search Link Analysis or Tabular View Both views provide access to available Pivot Search actions.
Reviewing imported OWLvault data Tabular View Displays the individual values within imported records.
Presenting investigative connections Link Analysis Provides a visual representation of relationships.

Using Monitoring

Monitoring is available for users of the Enterprise or Smart City editions of OWL.

For step-by-step instructions for creating and managing Monitoring Tasks, please see the Using Monitoring article here.

Use Monitoring for:

  • Ongoing investigations - Monitor a subject across search products for new information, such as arrest records, address updates, changed phone carriers or subscriber names, etc.
  • Data-import tracking - Monitor OWLvault for new records that match selected criteria as additional data is imported.
  • Proactive alerting - Monitor key identifiers, such as phone numbers, addresses, or SSNs, for new activity.
  • Compliance requirements - Monitor sanctions lists or watchlists for matches against known subjects

Scenario Walkthrough: Investigating Insurance Fraud

This walkthrough demonstrates how an investigator uses multi-jump pivot searches, multiple result views, and Monitoring to build a comprehensive picture of a suspected insurance fraud ring.

Background

An insurance SIU analyst receives a tip about a suspicious claim filed by John M. Rivera with phone number (555) 867-5309. The claim involves a vehicle accident at 742 Evergreen Terrace, Springfield, IL. The analyst needs to determine whether this claimant is connected to a broader fraud ring.

Step 1: Initial Search Across OWL Record Types

Action: The analyst opens the Query module, selects Keyword Search, and chooses multiple OWL internal products to search: OWLvault, OWL Cases, OWL Subjects, and OWLdocs. They enter the name “John Rivera” and phone number “5558675309.”

Result:

  • OWLvault returns three matching records from a previously imported claims dataset. One record shows John M. Rivera associated with a prior claim at a different address.
  • OWL Cases returns a hit - an existing case from two years ago that mentions “J. Rivera” in connection with a separate suspicious claim in a neighboring county.
  • OWL Subjects shows no existing subject record for this individual.
  • OWLdocs returns a scanned document uploaded to the older case that references the same phone number.

View used: Tabular View, to review field details and compare data across the different OWL record types.

Why this matters: Searching across multiple internal record types helps the analyst discover a prior case and related documentation that a single-product search may have missed.

Step 2: Pivot into Person Search

Action: From the OWLvault record, the analyst selects the spyglass icon, chooses the name “John M. Rivera,” and selects Person.

Result: The Person search returns an identity profile that includes two additional addresses and a relative named “Maria T Rivera.” 

View used: Link Analysis, to view the relationship graph branching from the OWLvault record to the Person results.

Step 3: Pivot into Criminal and Phone Records

Action: From the original OWLvault record, the analyst selects the phone number “5558675309” and pivots into Advanced Phone and National Criminal Data.

Result: The phone search reveals that the number is registered to “JR Consulting LLC.” The Criminal search returns a prior fraud conviction for “Juan Rivera” at an address matching one of those on John's Person results.

View used: Link Analysis, to review connections from the phone number to a business entity and from the name variant to a criminal record.

Step 4: Pivot into Business and Real Estate

Action: The analyst pivots “JR Consulting LLC” into Business Entity and UCC searches. Separately, the analyst pivots the Evergreen Terrace address into Real Estate Comprehensive.

Result: The Business Entity search shows that JR Consulting was registered six months before the first claim. The Real Estate search shows the property at 742 Evergreen Terrace is owned by Maria T. Rivera.

View used: Relationship Matrix, to assess which entities share the most connections.

Step 5: Set Up Monitoring

Action: The analyst creates Monitoring tasks for:

  1. The name “John Rivera” against Criminal Records.
  2. The business name “JR Consulting” against OWLvault.

Result: OWL automatically re-runs the configured searches according to the selected schedule and notifies the analyst when new matches are found.

Summary of Findings

After searching across OWL records and performing Pivot Searches into available external data products, the analyst identified:

  • A prior case involving John Rivera and the same phone number.
  • A name variant, Juan Rivera, with a prior fraud conviction.
  • A phone number registered to a business created shortly before the claims began.
  • A property owned by a related individual.

The combination of internal OWL searches and external product searches helps investigators build a broader picture from one starting search.

Tips for Advanced Users

  1. Start broad, then pivot narrow. Begin with an OWLvault or OWL product search, then pivot into specific products for deeper investigation.
  2. Use product selection strategically. Select products that fit the value you are searching—for example, use Phone products for phone numbers and People or Criminal products for names. If you're not sure which searches are available for your criteria type, use the Keyword search. 
  3. Use multi-jump patterns. Follow relevant connections from a name to an address, from an address to property information, and from property information to related people.
  4. Filter OWLvault by datasource. Select a specific datasource when you know which imported dataset is most relevant.
  5. Set up Monitoring early. Create Monitoring tasks for key search criteria when an investigation will continue over time.
  6. Use Relationship Matrix for large result sets. Use the matrix to identify notable relationships among a larger number of entities.
  7. Switch views for different perspectives. Use Link Analysis for relationships, Tabular View for data validation and review, Relationship Matrix for connection patterns, and Geospatial View for location-based review.
  8. Use Additional Searches when available. These searches can help expand an investigation using relevant product-specific lookups.

Troubleshooting and FAQ

Why did my Pivot Search return no results?

Possible Cause Solution
Inappropriate product selected Make sure the search you're using matching the type of criteria you're using. Example: If you do a business search on a personal phone number, there may not be anything to find.
No data is available Try another product or use broader search criteria.
Product is not included in the subscription Contact your administrator to confirm available products.

Can I pivot into products my organization has not subscribed to?

No. The available Pivot Search products depend on the organization’s active subscriptions, Software Edition, enabled modules, and user access.

Why are some records not available for Pivot Search?

Pivot Search is available only when OWL identifies an eligible searchable value in the selected result. Select another value or parent record if the Pivot Search option is not available.

My Pivot Search seems stuck. What should I do?

Check the Case Intelligence Workspace for the search status. If it is still processing, wait for completion and select View Results once it appears. If the search fails or does not return results, review the displayed status and try again if appropriate.

Why do I see Unmatched OWLvault Records?

These records are already attached to the current Case or Subject but do not match the current search criteria. OWL displays them separately to provide additional investigation context.

Can I export or download search results?

Yes. Use the available Download Report option from the Action menu in the results view or sometimes within spyglass menus for identities.