campaignWe've reorganized our documentation navigation structure to align directly with your operational workflows. See the
release notes and the
walkthrough video for more information.
Stay organized with collections
Save and categorize content based on your preferences.
Procedural filtering overview
Procedural filtering allows you to further filter investigation data by attributes including event type, log source, network connection status, and Top Level Domain (TLD). The available filtering options vary based on your current Google Security Operations view and the breadth of security data present in the UI.
This describes how to access and use Procedural Filtering when investigating an alert using Google SecOps for the following views:
Need more help? Get answers from Community members and Google SecOps professionals.
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-08-26 UTC.
[null,null,["Last updated 2026-08-26 UTC."],[],[]]