Detections Table
The Detections Table is where you can view all detections. Whereas the Triage Rule and Detections Triage views show detections by rule or device, the Detections Table shows detections by rule and device over time. By default, the table displays detections for the last two weeks. A color-coded bar at the left side of the table indicates active and resolved detections. A green bar indicates an active detection. A red bar indicates a resolved detection.
To access the Detections Table:
-
Go to Detections > Detections Table.
-
On the Dashboard:
- In the MITRE ATT&CK widget, click a bar in the chart.
- In the Resolved Detections widget, click Total or click a data point in the chart.
Filtering events
By default, the Detections Table displays detections by all severities and detection statuses for the previous two weeks ending on the current date. You can use any column header to sort the detections. Filters allow you to view detections for a specific IP, refine the list by Severity and Detection Status. You can also toggle between table and graph view.
1 |
Device IP to search | Enter the IP of a specific device. | ||||||||||||||||||||||||
2 |
Time range |
Click to open the date picker. Use the calender to set the start and end date or select an option from the Quick Ranges (Last Hour to Last 90 days). Click Resolution Date to show all detections resolved within the time range. This will disable the buttons in the Severity area. |
||||||||||||||||||||||||
3 |
Severity |
Select High (H), Medium (M), or Low (L). |
||||||||||||||||||||||||
4 |
Detection Status |
|
||||||||||||||||||||||||
5 |
Additional filters |
|
||||||||||||||||||||||||
6 |
Columns selectors |
|
||||||||||||||||||||||||
7 |
CSV | Click to export the list as a CSV file. | ||||||||||||||||||||||||
8 |
Table View | Click for table view (default). | ||||||||||||||||||||||||
9 |
Graph View | Click to open the Visualizer. | ||||||||||||||||||||||||
10 |
Actions menu |
Select one of the following options:
|