Filter Events
    • 19 Mar 2024
    • 1 Minute to read
    • PDF

    Filter Events

    • PDF

    Article summary

    You can filter your events by attribute, and then download a CSV of the results.

    1. From the navigation menu, click Events

    2. Enter attributes in the Analyzed events filter bar, and then press Return or Enter.

    3. Click the download button, and then click Download to CSV (last 1500 events).

    Supported filter attributes

    Attribute

    Description

    Example

    MAC address

    A MAC address associated with the event.

    00-14-22-01-23-45

    IP address

    An IP address associated with the event.

    127.0.0.1

    Endpoint users

    A user on an endpoint associated with the event.

    joe

    Command line

    A command line, process hash, or filename associated with the event.

    powershell.exe

    MD5/SHA256

    An MD5 or SHA256 hash associated with the event.

    1a79a4d60de6718e8e5b326e338ae533

    To filter endpoints by operating system, use the operating_system: field. You can either type a word after the colon, for example, operating_system:windows; or multiple words surrounded by double quotes, for example, operating_system:"Windows 10". This field is not case-sensitive, and will match on specific endpoint operating systems, as well as canonicalized names.

    This article provides information on Exposing External Service UUID.

     


    Was this article helpful?