[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-21 UTC."],[[["\u003cp\u003eHash view enables searching and investigating files based on their hash values within Google Security Operations.\u003c/p\u003e\n"],["\u003cp\u003eYou can directly access Hash view by searching for a specific hash value in the Google Security Operations search field and selecting it from the Hashes menu.\u003c/p\u003e\n"],["\u003cp\u003eHash view can be accessed from Asset view by navigating to a process or file-related event in the Timeline tab and clicking the relevant hash value.\u003c/p\u003e\n"],["\u003cp\u003eHash view supports filtering options including ASSETS, EVENT TYPE, LOG SOURCE, PID, and PROCESS NAME to refine investigations.\u003c/p\u003e\n"]]],[],null,["# Filter data in Hash view\n========================\n\nSupported in: \nGoogle secops [SIEM](/chronicle/docs/secops/google-secops-siem-toc)\n\nHash view lets you search and investigate files based on their hash\nvalue.\n\nOpen Hash view\n--------------\n\nYou can open Hash view the following ways:\n\n- Search for the file hash directly\n- Pivot to Hash view when viewing a process- or file-based event in Asset view\n\n### Search for the file hash directly\n\nTo open Hash view directly:\n\n1. Enter the hash value in the Google Security Operations search field. Click **Search**.\n\n2. Select the hash value from the **Hashes** menu. Hash view is displayed.\n\n### Navigate to Hash view from Asset view\n\nYou can also navigate to Hash view while investigating an asset in Asset view.\n\n1. Search for an asset and view it in Asset view. Asset view is displayed.\n\n2. From the **Timeline** tab to the left, scroll to any event tied to a\n process or file modification, such as PROCESS_LAUNCH.\n\n | **Note:** If you are not able to locate PROCESS_LAUNCH in the Event column, change the start-date on the top left corner to a few days previous to the present date. Also, slide the Time slider on the top right corner to 1 Day. Doing this will refresh the Timeline panel and display the other required events.\n3. Expand the file to view details and investigate.\n\n4. You can open Hash view for the file by clicking the hash value in\n Asset view. Hash view is displayed.\n\nFilter options in Hash view\n---------------------------\n\nThe following Procedural Filtering options are available in Hash view:\n\n- ASSETS\n- EVENT TYPE\n- LOG SOURCE\n- PID\n- PROCESS NAME\n\n**Need more help?** [Get answers from Community members and Google SecOps professionals.](https://security.googlecloudcommunity.com/google-security-operations-2)"]]