Current ThreatQ Version Filter
 

About Building Searches with Filter Sets

Filter Sets allow you to create multiple sets of filters that can be applied to the threat library at the same time using AND/OR logic. You can also save your Filter Sets using the Save Search option - see the Saving Searches section in the About Managing Search Results topic for more details.

Adding Filter Sets

  1. Use the NOT checkbox to determine if the filters in the initial filter set will be used to include or exclude Threat Library objects.
  2. Select one or more filters for the search.
    Select one or more filters

    You can use the search box provided at the top of the filters dropdown to narrow down the list of available filters.

  3. Click on Add Another Filter Set.

    A new Filter Set table will load below the first set.
    Create new filter set

  4. Use the Not checkbox to determine if the filters in the new filter set will be used to include or exclude Threat Library objects.
  5. Use the Filters dropdown next to the new filter set to add filters.
    Add new Filters
  6. Click on the And/Or dropdown to set the And/Or logic for the Filter Sets. See the And/Or Order of Operations topic for more details.
    And/Or Dropdown
    Repeat steps 3-6 to add additional filter sets.

Deleting Filter Sets

Deleting a Filter Set removes it from the search results and cannot be undone.

  1. Click on the delete delete icon icon located next to the right of the Filters dropdown.
    Delete filter set
    You can click on Clear Filters, located above the filter sets, to remove all filter sets from the current search.

And/Or Order of Operations

Filter Set AND/OR logic follows the standard mathematical order of operations with ANDs being executed before ORs. The table below provides different scenarios and examples for Filter Sets.

Scenario Order Example
Single AND Filter 1 AND Filter 2 Filter 1 AND Filter 2 example
Single OR Filter 1 OR Filter 2 Filter 1 OR Filter 2 example
Single AND, Single OR (Filter 1 AND Filter 2) OR Filter 3 (Filter 1 AND Filter 2) OR Filter 3 example
Multiple ANDs, Single OR (Filter 1 AND Filter 2 AND Filter 3) OR Filter 4 (Filter 1 AND Filter 2 AND Filter 3) OR Filter 4 example
Multiple ANDs, Multiple ORs (Filter 1 AND Filter 2) OR (Filter 3 AND Filter 4) (Filter 1 AND Filter 2) OR (Filter 3 AND Filter 4) example