Skip to content

Commit 671e77e

Browse files
committed
add filters
1 parent c65970d commit 671e77e

File tree

2 files changed

+16
-2
lines changed

2 files changed

+16
-2
lines changed

defender-xdr/advanced-hunting-query-results.md

Lines changed: 15 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -113,12 +113,26 @@ After running a query, select **Export** to save the results to local file. Your
113113

114114
## Filter results
115115

116-
After running a query, select **Filter** to narrow down the results to specific
116+
After running a query, select **Filter** to narrow down the results.
117117

118118
:::image type="content" source="/defender/media/add-filter1.png" alt-text="Screenshot of filters in advanced hunting." lightbox="/defender/media/add-filter1.png":::
119119

120+
To add a filter, select the data you want to filter for by selecting one or more of the check boxes. Then select **Add**.
121+
120122
:::image type="content" source="/defender/media/add-filter2.png" alt-text="Screenshot of filters dropdown in advanced hunting." lightbox="/defender/media/add-filter2.png":::
121123

124+
You can narrow the results down even further to specific data by selecting the newly added filter.
125+
126+
:::image type="content" source="/defender/media/add-filter3.png" alt-text="Screenshot of new filter pill in advanced hunting." lightbox="/defender/media/add-filter3.png":::
127+
128+
This opens a dropdown showing the possible filters you can use further. Select one or more of the check boxes, then select **Apply**.
129+
130+
:::image type="content" source="/defender/media/add-filter4.png" alt-text="Screenshot of new filter's dropdown in advanced hunting." lightbox="/defender/media/add-filter4.png":::
131+
132+
Confirm that you have added the filters that you wanted by checking the Filters section.
133+
134+
:::image type="content" source="/defender/media/add-filter5.png" alt-text="Screenshot of filters added advanced hunting." lightbox="/defender/media/add-filter5.png":::
135+
122136
## Drill down from query results
123137

124138
You can also explore the results in-line with the following features:

defender-xdr/whats-new.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ You can also get product updates and important notifications through the [messag
5454

5555
- (GA) You can now **release or move email messages from quarantine** back to the user's inbox directly from [Take actions in advanced hunting](advanced-hunting-take-action.md#take-various-actions-on-emails) and in [custom detections](custom-detection-rules.md#actions-on-emails). This allows security operators to manage false positives more efficiently and without losing context.
5656

57-
57+
- (GA) You can now **[filter your results](advanced-hunting-query-results.md#filter-results)** in advanced hunting so you can zoom in on your
5858

5959
## June 2024
6060

0 commit comments

Comments
 (0)