- 20 Mar 2024
- 1 Minute to read
- PDF
Filter Identities
- Updated on 20 Mar 2024
- 1 Minute to read
- PDF
Identities are the users who operate on endpoints and other systems in your organization. These users can be humans interacting with your systems or the built-in system and service users that are part of every operating system.
To better understand and group your identities, you can filter them by attribute.
From the navigation menu, click Identities.
Enter attributes in the Identities filter bar, and then hit Return or Enter.
Supported filter attributes
Attribute | Description | Example |
Username | The identity's username. |
|
UID | The identity's unique identifier. |
|
Type | The identity type, for example, "endpoint domain account." |
|
Logon domain | The logon domain, which is any string in the identity preceded by a double backslash ( |
|
Reporting tag | Current |
|
Latest detection time | The last time when Red Canary identified a threat associated with an identity. |
|
A note on dates and times:
Date filters are specified with a from..to
syntax where either from
or to
can be unbounded:
2020-01-01..
filters for matches on or after (>=)thefrom
date..2020-01-01
filters for matches on or before (<=)theto
date2020-01-01..2020-01-31
filters for matches on or after (>=)thefrom
date and on or before (<=) theto
date