Dashboard Filtering Options
Dashboard-level filters act as the default filtering mechanism for all cards in the dashboard. They are defined in Settings and Schedules > Configurations and apply uniformly across cards unless individually overridden.
To configure:
- Select date fields for each application (for example, First Created, Last Updated).
- Assign a default time range (for example, Last 7 Days).
Cards that inherit these settings will automatically apply the defined filters.
Example:
- App A has First Created as the selected date field.
- App B has no date field selected.
- Global Date Range: Last 7 Days
Effect:
- Cards based on App A display data from the last 7 days by default.
- Cards based on App B do not apply global filters and show unfiltered data unless configured at the card level.
Card-Level Filters
Each card can override dashboard-level filters.
To apply a card-level filter:
- Select โฎ > Edit Card.
- Disable the Always use the dashboardโs date range selection toggle.
- Choose a custom Date field.
- Set a specific Date range.
This enables focused views within a broader dashboard context.
Example:
Suppose the dashboard-level date range is July 10โ17:
- Card A:
- Inherits dashboard filters and displays data only from July 10 to July 17.
- Card B:
- Overrides with a custom range of July 1 to July 3.
Result:
- Card A maintains dashboard-level consistency.
- Card B shows a tailored view for deeper analysis.
Runtime Filters (Session-Based)
Runtime filters provide a temporary way to explore different data slices without modifying persistent dashboard or card settings. These are ideal for ad-hoc investigations or validations.
To apply a runtime filter:
- From the dashboard or card toolbar, select the calendar icon.
- Choose a quick or custom date range.
- Click Apply.
Note: Runtime filters are session-specific. They are cleared when the page is refreshed or reopened. A padlock icon appears on the card when a runtime filter is active.
Runtime filters empower MSSP analysts and operators to quickly triage based on recent events, adjust time windows on the fly, or pivot their view without impacting team-wide configurations.
Custom Date Range Filtering
Custom date range filtering is a part of runtime filtering. You can apply quick-select ranges or define custom expressions to adjust the data window interactively.
For more information, see Custom and Relative Date Ranges with Time Units๏ปฟ.