Procedural filtering overview

Supported in:

Procedural filtering allows you to further filter investigation data by attributes including event type, log source, network connection status, and Top Level Domain (TLD). The available filtering options vary based on your current Google Security Operations view and the breadth of security data present in the UI.

This describes how to access and use Procedural Filtering when investigating an alert using Google SecOps for the following views:

Need more help? Get answers from Community members and Google SecOps professionals.