[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-02。"],[[["\u003cp\u003eAsset view in Google Security Operations allows users to investigate assets and their interactions with domains, focusing on suspicious activity by filtering out benign data.\u003c/p\u003e\n"],["\u003cp\u003eProcedural Filtering in Asset view enables the filtering of information by event type, log source, network connection status, and Top Level Domain (TLD) to refine the investigation scope.\u003c/p\u003e\n"],["\u003cp\u003eThe Prevalence feature measures the number of assets connected to a specific domain over the past seven days, helping to prioritize investigation efforts by identifying domains with lower prevalence.\u003c/p\u003e\n"],["\u003cp\u003eThe Time slider and Timeline tab, alongside the Asset tab, allow users to adjust the time period under examination, as well as to highlight and focus on specific events or assets.\u003c/p\u003e\n"],["\u003cp\u003eThe user interface provides visual elements like the Prevalence graph, as well as left and right navigation panels with functions such as expanding, collapsing, including, and excluding items, to aid in investigations.\u003c/p\u003e\n"]]],[],null,["# Filter data in Asset view\n=========================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nAsset view lets you to investigate assets within your enterprise and whether\nor not they have interacted with suspicious domains.\nYou can adjust Asset view to hide benign activity and help highlight the data\nrelevant to an investigation.\n\nComplete the following steps to navigate to Asset view page:\n\n1. Enter the asset (ending with a known public suffix) or URL you need to\n investigate in the search bar at the top of the user interface. Click\n **SEARCH**.\n\n2. Select the asset from the **ASSETS** drop-down menu.\n Asset view is displayed.\n\n3. Click the icon in the\n top right corner of the Google Security Operations user interface. The\n **Procedural Filtering** menu opens. Procedural\n Filtering lets you to further filter information pertaining to an asset,\n including by event type, log source, network connection status, and Top\n Level Domain (TLD).\n\n The following Procedural Filtering options are available in Asset view:\n - EVENT TYPE\n - LOG SOURCE\n - NETWORK CONNECTION STATUS\n - TLD\n\nNavigate Asset view\n-------------------\n\nThe asset view has the following components.\n\n### Prevalence\n\nPrevalence measures the number of assets within your enterprise connected to a\nspecific domain over the past seven days. More assets connecting to a domain\nmeans that the domain has greater prevalence within your enterprise. High\nprevalence domains, such as google.com, are unlikely to require\ninvestigation. You can use the Prevalence slider to filter out the high\nprevalence domains and focus on the domains which fewer assets across your\nenterprise have accessed. The minimum Prevalence value is 1, meaning you could\nfocus on the domains which are linked to a single asset within your enterprise.\nThe maximum value varies depending on the number of assets you have within your\nenterprise.\n\nGoogle SecOps provides a graphical representation of the historical prevalence of a\ngiven FQDN and its TLD. This graph can be used to determine whether the domain\nhas been accessed from within the enterprise before, and can provide an\nindication of whether the domain is associated with a particular campaign\ntargeting the enterprise. Typically, less prevalent domains, ones that fewer\nassets have connected to, might represent a greater threat to your enterprise.\n\n### Time slider\n\nThe time slider lets you to adjust the time period under examination. You can\nadjust the slider to view between one minute and one day of events (you can also\nadjust this using the scroll wheel of your mouse over the Prevalence Graph).\nDomains that more assets have accessed are displayed as more prevalent in Asset\nview.\n\n### Timeline tab\n\nSelecting an event in the Timeline tab also highlights the corresponding event\nin the Gradient Heat Map in green. Alerts are indicated by a red triangle and\nred text.\n\n### Asset tab\n\nSelecting an asset highlights it in green in the Asset tab and all activity\ninvolving that asset is also highlighted in green on the Gradient Heat Map. You\ncan pivot to Asset view by clicking on first accessed or last accessed in the\nAssets tab.\n\n### TIMELINE Sidebar List\n\nWhen you search for an asset, activity is returned with a default time window of\n2 hours. Hovering over the header categories row displays the sorting control\nfor each column, enabling you to sort alphabetically or by time depending on the\ncategory. Adjust the time window using the time slider or by scrolling the mouse\nwheel while the cursor is over the Prevalence Graph.\n\n### DOMAINS sidebar list\n\nUse this list to see the first lookup of each distinct domain within a given\ntime window. This helps to hide noise caused by assets frequently connecting to\ndomains.\n\nSummary of Visual elements in the view\n--------------------------------------\n\nGoogle Security Operations includes the following user interface elements to help you investigate\nany issues that might be present within your enterprise:\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]