Filtering alerts

Prev Next

The Alerts table can be filtered to display the alerts based on date, domain name and other parameters. There are two ways to filter alerts - Basic and Advanced. Use the toggle button to switch between the two modes. In the basic mode you can select a filter by clicking its respective drop-down menu. You can also select the Add More Filters link.

ETP_AlertFilter1.jpg
ETP_Alerts4.png

In the advanced mode, you can use queries to create a filter.

ETP_Alerts6.png

Note

If you using a query to filter alerts and switch between inbound and outbound modes, you will lose the query and you will be redirected to the basic filter mode.

In the advanced mode, click the Search History icon to view past searches, delete individual entries, or clear the entire history.

ETP_AlertFilter2.jpeg

You can filter alerts based on the following criteria:

  • Date

    • Last 1, 7, or 30 days

    • Custom range (click to specify)

  • Domains

    • Select from a list of domains

  • Domain Groups

    • Select from a list of domain groups

  • View

    • Acknowledged

    • Unacknowledged

  • Alert Type

    • ACE

    • Blocked List Match

    • QR Code

    • Retro

    • Riskware

    • Yara

    • Other (Alerts having a type other than the ones listed above will be categorised as Other)

      Note

      Using the Other alert type in an advanced mode query along with parameter and using the AND operator will not generate any result.

      Using the 'Other' alert type together with a different alert type will not produce the expected results. Please avoid combining 'Other' with any other alert type.

      ETP_AdvThreat5.png
  • Threat Type

    • Select from 70 threat types

    • Select Others for threats that do not belong to a specified threat group

  • Add more filters: Add a new entry in a category in which to filter:

    • Alert ID

    • From

    • Recipients

    • Subject

    • MD5

    • URL/attachment

      Note

      If you filter as per a specific URL using the URL/attachment query in advanced mode, it will list alerts added after the release 2025.2.

    • Email server

    • Signature name

    • Riskware Rules (not supported for outbound traffic)

  • Detection Engine (Only in advanced mode)

  • Read (Only in advanced mode)

To reset the filters, click Clear.