This topic describes ways to filter your searches on the Observations page.
Note: Search results are subject to a 10,000 result limit.
You can filter search results in the following ways:
Filter | Examples |
---|---|
Type |
|
Event Type |
|
Process |
|
Effective Reputation |
|
Process Hash | |
Device |
|
Username |
|
Parent Effective Reputation |
|
TTP |
|
Location |
|
Application Protocol |
|
ATT&CK Tactic |
|
ATT&CK Technique |
|
Tip: You can exclude search results by clicking the
Exclude icon to the right of a filter. For example: