Filter event data

There are a number of methods available to filter threat and Acceptable Use Policy (AUP) event data. If Enterprise Security Connector is configured in your organization, you can also filter Security Connector event data.

How to

  1. To filter threat or AUP events, in the navigation menu select Monitoring > Events. Click the Threat Events tab or the AUP Events tab.
    Note: If you are trying the new Enterprise Center interface, in the navigation menu, select Threat Analytics > Events. Select the event type.
  2. If a Security Connector is configured for your organization and you want to find Security Connector event data, in the navigation menu, select Monitoring > Activity. Click the Security Connector tab.
    Note: If you are trying the new Enterprise Center interface, in the navigation menu, select Threat Analytics > Activity > Security Connector.
  3. To filter events based on date and time, see Filter data based on date and time.
  4. To configure and apply a filter, see Configure and apply a filter.
  5. To further narrow the date and time that you want to report on, move the slider handles of the provided graph to select the desired area or the date and time you want to focus on. For example, you may want to focus on the time when most events occurred.
  6. Select a dimension or event criteria to define what event data is shown.
  7. To hide data shown in the top 6, click one of top 6 items. This data is hidden from the Top 6 graph. Likewise, you can click it again to show this data in the graph.
  8. To search events that are grouped by the selected dimension, see Search for events.