You can use the Alert Filters on the left side of the Alert Lists page to narrow your alert results by a specific source IP, target IP, source port, target port, severity, alert status, device, IOC value, Intel source and alert name. A status indicator, located at the top left corner of the Alert page, displays all active alert filters. To view counts for the filter values, simply click on the Alert Filters menu and expand the filter types.
Click
and from INVESTIGATION, select Alerts.On the top-right corner of the Alerts table, click the filter icon. The Filter options are displayed in the left pane.
Expand the filter to add more options.