[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-18 UTC."],[[["\u003cp\u003eThe Rule Detections view displays rule metadata and a graph of recent detections.\u003c/p\u003e\n"],["\u003cp\u003eAccess the Rule Detections view by navigating to \u003cstrong\u003eRules & Detections\u003c/strong\u003e and selecting a rule name, then click the right arrow in the Detections column.\u003c/p\u003e\n"],["\u003cp\u003eThe \u003cstrong\u003eProcedural Filtering\u003c/strong\u003e menu, accessed via an icon in the top right corner, allows users to filter detection data.\u003c/p\u003e\n"],["\u003cp\u003eAvailable filtering options in Rule Detections view include \u003ccode\u003eMETADATA.EVENT_TYPE\u003c/code\u003e, \u003ccode\u003eMETADATA.PRODUCT_NAME\u003c/code\u003e, and various network-related parameters like \u003ccode\u003eNETWORK.APPLICATION_PROTOCOL\u003c/code\u003e and DNS details.\u003c/p\u003e\n"],["\u003cp\u003eThe fields available for Procedural Filtering are determined by the specific events returned for a detection.\u003c/p\u003e\n"]]],[],null,[]]