Manage Tables

Filter page results, manage columns and rows, and save and share the filters.
Most pages in Cortex XDR present data in table format and provide controls to help you manage and filter the results. If additional views or actions are available for a specific value, you can pivot (right-click) from the value in the table. For example, you can view the incident details, or pivot to the Causality View for an alert or you can pivot to the results for a query.
On most pages, you can also refresh ( refresh.png ) the content on the page.
To manage tables in the app:

Filter Page Results

To reduce the number of results, you can filter by any heading and value. When you apply a filter, Cortex XDR displays the filter criteria above the results table. You can also filter individual columns for specific values using the icon to the right of the column heading.
Some fields also support additional operators such as
=
,
!=
,
Contains
,
not Contains
,
*
,
!*
.
There are three ways you can filter results:
  • By column using the filter next to a field heading
  • By building a filter query for one or more fields using the filter builder
  • By pivoting from the contents of a cell (show or hide rows containing)
Filters are persistent. When you navigate away from the page and return, any filter you added remain active.
To build a filter using one or more fields:
  1. From a Cortex XDR page, select
    Filter
    .
    Cortex XDR adds the filter criteria above the top of the table. For example, on the filter page:
    alerts-filter.png
  2. For each field you want to filter:
    1. Select or search the field.
    2. Select the operator by which to match the criteria.
      In most cases this will be
      =
      to include results that match the value you specify, or
      !=
      to exclude results that match the value.
    3. Enter a value to complete the filter criteria.
      CMD fields have a 128 character limit. Shorten longer query strings to 127 characters and add an asterisk (*).
      Alternatively, you can select
      Include empty values
      to create a filter that excludes or includes results when the field has an empty values.
  3. To add additional filters, click
    +AND
    (within the filter brackets) to display results that must match all specified criteria, or
    +OR
    to display results that match any of the criteria.
  4. Click out of the filter area into the results table to see the results.
  5. Next steps:
    • If at any time you want to remove the filter, click the
      X
      next to it. To remove all filters, click the trash icon.

Export Results to File

If needed, you can export the page results for most pages in Cortex XDR to a tab separated values (TSV) file.
  1. (
    Optional
    ) Filter Page Results to reduce the number of results for export.
  2. To the left of the refresh icon ( refresh.png ),
    Export to file
    .
    Cortex XDR exports any results matching your applied filters in TSV format. The TSV format requires a tab separator, automatic detection does not work in case of multi-event exports.

Save and Share Filters

You can save and share filters across your organization.
  • Save a filter:
    Saved filters are listed on the Filters tab for the table layout and filter manager menu.
    1. Save ( save-icon.png ) the active filter.
    2. Enter a name to identify the filter.
      You can create multiple filters with the same name. Saving a filter with an existing name will not override the existing filter.
    3. Choose whether to
      Share this filter
      or whether to keep it private for your own use only.
  • Share a filter:
    You can share a filter across your organization.
    1. Select the table layout and filter menu indicated by the three vertical dots, then select
      Filters
      .
      filter-share.png
    2. Select the filter to share and click the share icon.
    3. If needed, you can later unshare ( filter-unshare-icon.png ) or delete ( trash-icon.png ) a filter.
      Unsharing a filter will turn a public filter private. Deleting a shared filter will remove it for all users.

Show or Hide Results

As an alternative to building a filter query from scratch or using the column filters, you can pivot from rows and specific values to define the match criteria to fine tune the results in the table. You can also pivot on empty values to show only results with empty values or only results that do not have empty values in the column from which you pivot.
CMD fields are limited to 128 characters. If you pivot on a CMD field with a truncated value, the app shows or hides all results that match the first 128 characters.
The show or hide action is a temporary means of filtering the results: If you navigate away from the page and later return, any results you previously hid will appear again.
This option is available for fields which have a finite list of options.
To hide or show only results that match a specific field value:
  1. Right-click the matching field value by which you want to hide or show.
  2. Select the desired action:
    • Hide rows with
      <field value>
    • Show rows with
      <field value>
    • Hide empty rows
    • Show empty rows

Manage Columns and Rows

From Cortex XDR pages, you can manage how you want to view the results table and what information you want XDR app to display.
Any adjustments you make to the columns or rows persist when you navigate away from and later return to the page.
  • Adjust the row height:
    1. On the Cortex XDR page select the menu indicated by three vertical dots to the right of the
      Filter
      button.
    2. Select the desired
      ROW VIEW
      option.
      alerts-rows-columns.png
      Cortex XDR updates the table to present the results in the desired row height view ranging from short to tall.
  • Adjust the column width:
    1. On the Cortex XDR page, select the menu indicated by three vertical dots to the right of the
      Filter
      button.
    2. Select the desired column width option from the
      COLUMN MANAGER
      .
      alerts-rows-columns.png
      Cortex XDR updates the table to present the results in the desired view: narrow, fixed width, or scaled to the column heading.
  • Add or remove fields in the table:
    1. On an Cortex XDR page, select the menu indicated by three vertical dots to the right of the
      Filter
      button.
    2. Below the column manager, search for a column by name, or select the fields you want to add or clear any fields you want to hide.
      Cortex XDR adds or removes the fields to the table as you select or clear the fields.
    3. If desired, drag and drop the fields to change the order in which they appear in the table.

Recommended For You