Filtering the Visualizer
Use the filters at the top of the visualizer to change the content displayed in the canvas. Some filter options are static, others are dynamic based on the criteria selected elsewhere. When you modify the filter, the graph will be redrawn per the selected options.
The Visualizer can retrieve up to 10,000 detections from the API regardless of the filter criteria. |
Nodes
Use the Nodes filter to select the types of nodes to display. There are three types of nodes:
- Indicators
- Impacted Devices
- Detectors
When the Indicators option is selected, groups of indicators and impacted devices related to the same detector may be clustered together on the graph. While any combination can be selected, omitting Detection Name will usually result in a disjointed graph. |
Detection Name
Use the Detection Name filter to hide or display detections. The detections displayed will depend on the other criteria selected in the report. Only the detections that are relevant to the rest of the criteria (such as Date Range, Device/Detections/Status, Severity) can be selected.
Date Range
Use the date-range selector to specify the date range to display.
Filter by Status
You can refine the results in the Visualizer by Detection Status, Device Status, or Rule Status. Changing the status filters will initiate a new query to the Detections API and refresh the graph. All other filter changes will filter the existing data and redraw the graph.