Using filters in the alerts table

Prev Next

You can refine your alerts table view by using filters to display only the information you want to view. The table below describes the attributes you can use to filter the alert table:

Alert attribute

Description

Acknowledged

Filter alerts by the acknowledge status associated with each alert:

  • All (default)

  • Yes (acknowledged alerts)

  • No (unacknowledged alerts

Acknowledged By

Filter alerts by the username of the administrator, analyst, senior analyst, or investigator who acknowledge the alert.

Acknowledged Date/Time

Filter by the date and time when the alert was acknowledged.

Alert Type

Filter by the alert type by selecting the type from the drop-down list. The selected type is shown in the column header.

  • ALL (default)

  • IOC—Indicators of Compromise

    • PRS—Presence

    • EXC—Execution

  • MAL—Malware

  • XPLT—Exploit

  • PRO—PROCESS_TRACKER

  • GEN—General

Assessment

Filter alerts by assessment in the following ways:

  • Click inside the column header to filter alerts by a full or partial assessment name.

  • Click the column header to sort alerts by assessment name in ascending or descending order.

Disposition

Filter alerts by a subset. Filtering options include:

  • All (default)

  • False Positive

  • Not False Positive

File Full Path

Filter by the file path associated with the latest event for an alert. File paths are always available for MAL alerts and EXD alerts, but not always available for IOC alerts.

First Event

Filter by the timestamp of an alert group. You can filter by a relative time (Today, Yesterday, Last 7 Days, Last 30 Days, This Month, or Last Month)or a custom time. Choose Custom to open a calendar and enter a specific timestamp range.

Hash

Filter by the full or partial hash associated with the alert. NOTE—Not all alerts will have an associated hash.

Host

Filter by the hostname associated with the alert.

  • Click inside the column header to filter alerts by a full or partial hostname.

  • Click the column header to sort alerts by hostname in ascending or descending order.

Host IP

Displays the source or destination IP address associated with the alert.

  • Click inside the column header to filter alerts by a full or partial IP address.

  • Click the column header to sort alerts by IP addresses in ascending or descending order.

Last Event

Filter by the timestamp of the most recent alert in the alert group. You can filter by a relative time (Today, Yesterday, Last 7 Days, Last 30 Days, This Month, or Last Month)or a custom time. Choose Custom to open a calendar and enter a specific timestamp range.

Protection and Remediation

Filter alerts for a particular status by selecting the status from the drop-down list. The selected status is shown in the column header.

  • ALL (default)

  • BLOCK

  • PARTIAL BLOCK

  • QUARANTINED

  • CLEANED

Selected

Allows you to select all, clear all, or select specific alert rows to delete or acknowledge. You can use the column to perform a bulk deletion or acknowledgment of all alerts in the Alert Table.

To filter the alerts table by a specific alert attribute:
  1. Click Alerts from the Dashboard menu to access the Alerts page.

  2. From the alerts table, select the column you want to filter by and enter the alert filter attribute in the filter field.