Documentation Center
AlienVault® USM Central™

Search and Filter Alarms

USM Central includes several filters displayed by default. These filters allow you to search for your items of interest. You can either filter your search, or type what you are looking for in the search box, in the upper left-hand corner of the page.

If you want to analyze the data and see the additional columns without having to scroll left and right, you can maximize the screen and hide the filter panel. Click the Expanded Filter Panel icon () to hide the filter panel. Click the Collapsed Filter Panel icon () to expand the filter panel.

Searching Alarms by Using the Search Box

To search Alarms using the search box

  1. Go to ALARMS.
  2. Type your search in the Enter search phrase box.
  3. Note: If you want to search for an exact phrase having two or more words, you will need to put quotation marks around the words in the phrase.

  4. Click the Magnifying Glass icon ().
  5. The result of your search displays with the items identified.

Filters Alarms

You can use filters to delimit the number of alarms that are displayed in the alarm lists. Any active filters will be displayed at the top of the page. You can remove individual filters by clicking the Close icon () next to the filter, or you can clear all filters by clicking the Clear All Filters link. You can also save filter views to easily load up later. Your active filters will be used for reports exports.

Filters displayed by default in the main Alarms page

Filter Name Meaning
Created during Identify alarmsAlarms provide notification of an event or sequence of events that require attention or investigation. triggered in the last hour, last 24 hours, last 7 days, last 30 days, or last 90 days. You can also configure your own period of time by clicking the Custom Range icon (). This option allows you to customize a range and narrow it to delimit your search per minutes and seconds.
Suppressed

Filter suppressed alarms.

Not Suppressed Filter hiding suppressed alarms. The suppressed alarms are hidden by default.
Deployment Filter alarms by the connected individual instances of USM Anywhere or USM Appliance.
Labels Filter alarms by the applied label(s), see Labeling the Alarms for more information.
Intent Filter alarms by the purpose of the alarm. It can be Delivery & Attack, Environmental Awareness, Exploitation & Installation, Reconnaissance & Probing, and System CompromiseState or indication that an intruder has bypassed security measures and gained unauthorized access to resources, installed malicious software, or modified existing software or configurations in an attempt to cause damage or steal information.. See Intent for further information.
Strategy Filter alarms by the type of attack. See Strategy for further information.
Method If known, filter alarms by the method of attack or infiltrationIndicator that specifies method of attack that generated an alarm. For OTX pulses, this method is the pulse name. associated with the indicator that generated the alarm. See Method for further information.
Sensors Filter alarms by the associated sensor, see USM Anywhere Sensor Management for more information.

The displayed number close to each filter between brackets indicates the number of items that matches the filter. You can also use the filter controls to provide a method of organizing your search and filtered results. The icons below each filter box are

Icons below filters
Icon Meaning
Toggle the ability to select multiple values as an OR statement.
You can view and toggle between the currently filtered item, and other filtered items without the need to reset the search.
Toggle values with (0) matches.
Sort the information alphabetically.
Sort the filters by number of items that matches them.
Reset Resets to the default values.

Note: When applying filters, the search uses the logical AND operator if the used filters are different. However, when the filter is of the same type, the search uses the logical OR.

To search alarms using a filter

  1. Go to ALARMS.
  2. Click on a filter.

    The result of your search displays with alarms identified.

To save a filter configuration

  1. Go to ALARMS and select the filters you want to use in your saved view.
  2. Click the Save dropdown menu and click Save as.
  3. Type a name for the view and click Save. You can now load this view from the dropdown menu to the left of the Save button.

Note: If you have changed the configuration of the alarms columns, this configuration will be also saved together with the filter configuration. See Views

To add or delete filters from the Search & Filters area

  1. Go to ALARMS.
  2. Click the Configure Filters link at the bottom of the Search & Filters sidebar to open the Filters Configuration window.
  3. Click the arrow icons () and () to pass the items from the Available Filters and Selected Filters columns, then click Apply.