Skip to main content

Filter events that were associated with an alert or case

  • June 10, 2026
  • 0 replies
  • 9 views

bitshock1015
Forum|alt.badge.img+3

Hello team,

Β 

Is it possible to use UDM filters to filter the events that triggered a rule?

In QRadar, you can apply this type of filter to determine which event actually triggered the rule, and I’d like to know if SecOps has the same search mechanism, since we use this data to create a report.


Regards,

Renato Ferreira​​​​​​​