Filters help you view details about selected items on a view. If you enter filters and refresh the view, the data in the view reflects the filters you added.
On the Trellix ESM console, select the view you want to filter.
In the Filter pane, filter your view in one of the following ways:
Type the filter information in the appropriate field. For example, to filter the view to see only the data that has a source IP address of 161.122.15.13, type the IP address in the Source IP field.
Type a
containsorregexfilter.Click the Display filter list icon
next to the field and select the variables or watchlists to filter on.On the view, select the data you want to use as the filter, then click the field on the Filter pane. If the field is blank, it is auto-populated with the data you selected.
Note
For Average Severity, use a colon (:) to enter a range. For example, 60:80 is a severity range of 60–80.
Specify how to filter the data in your view.
Include or exclude data from the view.
Use regular and OR filters.
Note
At least 2 fields must be selected OR for this filter to work.
To filter data by case, click
.To replace normalized strings with their aliases, click
.
To run the query, click
.
Trellix ESM refreshes the view. An orange filter icon appears in the upper-right corner of the view pane, indicating that the data in the view is a result of filters. If you click the icon, the system removes the filters and the view shows all data.