---
title: "Threat View"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35406075/Threat%20View"
format: markdown
---
The <span style="color: #000000">*Threat View *</span>tab includes all data that was previously published in the old *Security Report* and displays it in a highly usable format. <span style="color: #000000">The </span><span style="color: #000000">*Threat View *</span><span style="color: #000000">tab provides comprehensive security data about the malicious hits within your networks over a specific time period. The default report displays a bar chart that shows the distribution of malicious hits throughout your networks within a 24-hour time frame by default but can be customized to display a specific time period. To export the </span><span style="color: #000000">*Threat View*</span><span style="color: #000000"> table data in csv format, click </span><span style="color: #000000">**Export**</span><span style="color: #000000">. The default file name is </span><span style="color: #000000">*security-activity_threat-view.csv*</span><span style="color: #000000">. Exported data is limited to 10,000 records.</span>

## <span style="color: #000000">Performing Search Queries </span>

<span style="color: #000000">The search feature supports using queries to perform searches using the integrated search query language.  Using the search query language, you can search all records in the </span><span style="color: #000000">*Security Events*</span><span style="color: #000000"> report with customized queries. Using the search query options available in the </span><span style="color: #000000">*Threat View *</span><span style="color: #000000">report, you can:</span>

- <span style="color: #000000">Run a search on any of the following fields:</span>
  - <span style="color: #000000">**REQUESTS**</span>
  - <span style="color: #000000">**DEVICES**</span>
  - <span style="color: #000000">**PROPERTY**</span>
  - <span style="color: #000000">**USERS**</span>
- <span style="color: #000000">The</span><span style="color: #000000">** =**</span><span style="color: #000000"> and the </span><span style="color: #000000">**NOT (!=)**</span><span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span><span style="color: #000000">**AND**</span><span style="color: #000000"> and </span><span style="color: #000000">**OR**</span><span style="color: #000000"> operators.</span>
- <span style="color: #000000">Use </span><span style="color: #000000">**single**</span><span style="color: #000000"> and </span><span style="color: #000000">**double **</span><span style="color: #000000">quoted to enter values with spaces.</span>
- <span style="color: #000000">Use parentheses to group search parts. </span>
- <span style="color: #000000">Use the </span><span style="color: #000000">**wildcard symbol (*) **</span><span style="color: #000000">as the last character of the search value for a partial match.</span>
- <span style="color: #000000">Use the </span><span style="color: #000000">**ENTER**</span><span style="color: #000000"> key to apply search.</span>
- <span style="color: #000000">Use the </span><span style="color: #000000">**TAB**</span><span style="color: #000000"> key to autocomplete search with the first available suggestion.</span>

## <span style="color: #000000">Sample Search Queries</span>

<span style="color: #000000">The following are search query examples:</span>

- <span style="color: #000000">*target_domain=domain.**</span>
- <span style="color: #000000">target_domain=domain.* AND confidence=High</span>

<span style="color: #000000">Search by the target_domain field matches values by subdomains. E.g. target_domain = domain.com </span>  
<span style="color: #000000">matches</span>  
<span style="color: #000000">'domain.com', 'office.domain.com', 'space.office.domain.com</span>

> ⚠️ ### Note
> ⚠️ 
> ⚠️ <span style="color: #000000">All search values are case sensitive. A maximum of five operators can be used when constructing a query search.</span>

## <span style="color: #000000">Filtering the Threat View Tab</span>

<span style="color: #000000">To filter </span><span style="color: #000000">*Threat Insight*</span><span style="color: #000000"> events by specific criteria, select the applicable objects from the following drop-down menus located below the top action menu:</span>

- <span style="color: #000000">**Class**</span><span style="color: #000000">: The threat class associated with the target domain.</span>
- <span style="color: #000000">**Level**</span><span style="color: #000000">: The target domain's threat level rating. This can be High, Medium, Low, or Info.</span>
- <span style="color: #000000">**Policy**</span><span style="color: #000000">: The security policy against which the malicious hit triggered.</span>
- <span style="color: #000000">**Property**</span><span style="color: #000000">: The property or nature of the threat. By default, the portal includes all threat properties.</span>
- <span style="color: #000000">**Source**</span><span style="color: #000000">: The location of the device within the network infrastructure. For example, the device can be an </span><span style="color: #000000">**on-prem**</span><span style="color: #000000"> appliance or an </span><span style="color: #000000">**endpoint**</span><span style="color: #000000"> device. You can select which records to view by selecting or deselecting from among the options available. </span>
- <span style="color: #000000">**Show**</span><span style="color: #000000">: Security and activity events can be filtered by choosing an option from the </span><span style="color: #000000">**Show**</span><span style="color: #000000"> drop-down menu. </span>

<span style="color: #000000">The </span><span style="color: #000000">*Threat Insight *</span><span style="color: #000000">table displays the following information by specific criteria. Select the applicable objects from the following column drop-down menus:</span>

- <span style="color: #000000">**REQUESTS**</span><span style="color: #000000">: The number of detections associated with the report. Clicking on a record's number of detections will display a table of the detections associated with the target domain. </span>
- <span style="color: #000000">**DEVICES**</span><span style="color: #000000">: The devices that triggered the hits. Clicking the number of devices in the </span><span style="color: #000000">**DEVICE**</span><span style="color: #000000"> column associated with a user allows you to pivot off the record and display all devices associated with the user.</span>
- <span style="color: #000000">**PROPERTY**</span><span style="color: #000000">: The property or nature of the threat. By default, the portal includes all threat properties.</span>
- <span style="color: #000000">**USERS**</span><span style="color: #000000">: The users that triggered the event. For remote offices, the portal displays </span><span style="color: #000000">**Unknown**</span><span style="color: #000000"> for these users. If you have configured access authentication, this displays the authenticated user who triggered the event.</span>
  ***Export Records***
  Click **Export** to download a CSV file of report records. The maximum number of exported Threat View report records is **10,000**.