Kaspersky Anti Targeted Attack (KATA) Platform

Filtering and searching alerts by technology name

8 November 2023

ID 247609

You can filter alerts and search the alerts table for specific alerts based on the Technologies criterion, which indicates the names of program modules or components that generated the alert.

To filter alerts by technology name:

  1. Select the Alerts section in the window of the application web interface.

    This opens the table of alerts.

  2. Click the Technologies link to open the filter configuration window.
  3. In the drop-down list, select one of the following alert filtering operators:
    • Contain if you want the application to display alerts generated by an application module or component that you specify.
    • Not contain if you want the application to hide alerts generated by an application module or component that you specify.
    • Equal to if you want the application to display alerts generated by an application module or component that you specify.
    • Not equal to if you want the application to hide alerts generated by an application module or component that you specify.
  4. In the drop-down list to the right of the alert filtering operator that you have selected, select the name of the technology which you want to filter alerts:
    • (YARA) YARA.
    • (SB) Sandbox.
    • (URL) URL Reputation.
    • (IDS) Intrusion Detection System.
    • (AM) Anti-Malware Engine.
    • (TAA) Targeted Attack Analyzer.
    • (IOC) IOC.

    For example, if you want the application to display alerts generated by the Sandbox component, select the Contain filtering operator and the name of the (SB) Sandbox component.

  5. To add a filter condition using a different criterion, click Apt_icon_alerts_add_filter and specify the filter condition.
  6. Click Apply.

The table of alerts displays only alerts matching the filter criteria you have set.

See also

Filtering, sorting, and searching alerts

Filtering alerts by VIP status

Filtering and searching alerts by time

Filtering alerts by level of importance

Filtering and searching alerts by categories of objects detected

Filtering and searching alerts by obtained information

Filtering and searching alerts by source address

Filtering and searching alerts by destination address

Filtering and searching alerts by server name

Filtering and searching alerts by the status of their processing by the user

Sorting alerts in the table

Quickly creating an alert filter

Clearing an alert filter

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.