Kaspersky Anti Targeted Attack Platform
Filtering by registered events

On the network interactions map, you can display nodes and links whose information is stored in events associated with the selected nodes.

You can use the filtering functionality if no more than 200 nodes are selected on the network interactions map. You can select nodes either individually or as part of collapsed groups that include the required devices. When you select a collapsed group, all devices in child groups at all nesting levels also end up in the selection.

You can use the following ways of filtering by events:

  • Initial filtering by events. Use this method to filter objects by events associated only with the selected nodes.
  • Additional filtering by events. Use this method when the initial filtering by events already has been performed (for example, when going to the network interactions map from the table of events) and you need to supplement the filter with events associated with additional selected nodes from among the network interactions displayed on the network interactions map.

To display nodes and links based on initial event filtering:

  1. On the network interactions map, select one or more nodes and/or collapsed groups.

    To select multiple nodes and/or groups, do one of the following:

    • Press and hold the SHIFT key, then use the mouse to select a rectangular area with the objects that you want to select.
    • Press and hold the CTRL key and click every object that you want to select.
  2. In the toolbar above the network interactions map, open the Event filter drop-down list.
  3. In the drop-down list, select Filter.

The network interaction map displays only nodes and links whose information is contained in events associated with the selected nodes. In the toolbar above the network interactions map, a list is displayed with event IDs (the IDs are listed in the chronological order of detection of the associated events).

To add nodes and links to the displayed objects using additional filtering by events:

  1. Make sure the initial filtering by events already has been performed. To do so, look for the list of event IDs in the toolbar above the network interactions map.
  2. From among the displayed nodes on the network interactions map, select nodes whose associated events you want to add to the filter.

    The details area is displayed in the right part of the web interface window.

  3. In the toolbar above the network interactions map, open the Event filter drop-down list.
  4. In the drop-down list, select Add to filter.

The network interaction map additionally displays nodes and links whose information is contained in the events associated with the selected nodes. IDs of detected events are added to the list of IDs in the toolbar.