In the Analysis page of the appliance, you can filter for retroactively detected alerts.
Multiple alerts are displayed in a single row as an alert grouping. If the appliance has identified retroactive detection for an alert, a Retroactive Alert badge appears in the Badges column.
Note
You can filter and sort alerts based on retroactive detection only using the Web UI.
Prerequisites
Administrator, Monitor, or Analyst, access to the appliance
A CONTENT_UPDATES license for security content updates
A two-way sharing CONTENT_UPDATES license (if Advanced URL Defense is enabled)