Skip to content

Commit b0cb9b0

Browse files
authored
Merge pull request #1092 from MicrosoftDocs/maccruz-filters
Filters in advanced hunting
2 parents 67bf4fd + 161a0eb commit b0cb9b0

File tree

7 files changed

+23
-1
lines changed

7 files changed

+23
-1
lines changed

defender-xdr/advanced-hunting-query-results.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -111,6 +111,28 @@ After running a query, select **Export** to save the results to local file. Your
111111
- **Table view**—The query results are exported in tabular form as a Microsoft Excel workbook
112112
- **Any chart**—The query results are exported as a JPEG image of the rendered chart
113113

114+
## Filter results
115+
116+
After running a query, select **Filter** to narrow down the results.
117+
118+
:::image type="content" source="/defender/media/add-filter1.png" alt-text="Screenshot of filters in advanced hunting." lightbox="/defender/media/add-filter1.png":::
119+
120+
To add a filter, select the data you want to filter for by selecting one or more of the check boxes. Then select **Add**.
121+
122+
:::image type="content" source="/defender/media/add-filter2.png" alt-text="Screenshot of filters dropdown in advanced hunting." lightbox="/defender/media/add-filter2.png":::
123+
124+
You can narrow the results down even further to specific data by selecting the newly added filter.
125+
126+
:::image type="content" source="/defender/media/add-filter3.png" alt-text="Screenshot of new filter pill in advanced hunting." lightbox="/defender/media/add-filter3.png":::
127+
128+
This opens a dropdown showing the possible filters you can use further. Select one or more of the check boxes, then select **Apply**.
129+
130+
:::image type="content" source="/defender/media/add-filter4.png" alt-text="Screenshot of new filter's dropdown in advanced hunting." lightbox="/defender/media/add-filter4.png":::
131+
132+
Confirm that you have added the filters that you wanted by checking the Filters section.
133+
134+
:::image type="content" source="/defender/media/add-filter5.png" alt-text="Screenshot of filters added advanced hunting." lightbox="/defender/media/add-filter5.png":::
135+
114136
## Drill down from query results
115137

116138
You can also explore the results in-line with the following features:

defender-xdr/whats-new.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ You can also get product updates and important notifications through the [messag
6363
- (Preview) You can now filter your Microsoft Defender for Cloud alerts by the associated **alert subscription ID** in the Incidents and Alerts queues. For more information, see [Microsoft Defender for Cloud in Microsoft Defender XDR](microsoft-365-security-center-defender-cloud.md).
6464

6565

66-
66+
- (GA) You can now **[filter your results](advanced-hunting-query-results.md#filter-results)** in advanced hunting so you can narrow down your investigation on specific data you want to focus on.
6767

6868
## May 2024
6969

defender/media/add-filter1.png

47.1 KB
Loading

defender/media/add-filter2.png

81.9 KB
Loading

defender/media/add-filter3.png

9.96 KB
Loading

defender/media/add-filter4.png

12.4 KB
Loading

defender/media/add-filter5.png

53.9 KB
Loading

0 commit comments

Comments
 (0)