Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Working with quick filters

Quick filters are easily accessible filters that are available on, security incidents and response tasks lists.

Before you begin

Role required: sn_si.admin

The SIR Workspace provides quick filters feature that allows you to filter the list of security incidents or response tasks with ease.

You can use quick filters to configure new filters or modify existing filters that appear against these lists. The base system provides the following quick filters for each security incident:

  • Incidents Opened Today
  • Incidents open > 24hrs
  • Open incidents with Priority= Critical
  • Risk >= 80
  • Open Phishing Incidents

The base system provides the following quick filters for each response task:

  • Tasks open > 24h
  • Open Tasks with Priority = Critical

Note: An admin can configure the required list of quick filters according to the organization need.

Procedure

  1. Navigate to System Definition > Tables.

  2. Search for Quick Filters (sn_si_aw_quick_filters).

  3. Go to Related Links > Show List section.

    The Quick Filters list page is displayed. OOTB, following is the list of quick filters shipped with the application.

    NameTableValue
    Tasks opened TodaySecurity Incident Task [sn_si_task]True
    Incidents opened TodaySecurity Incident [sn_si_incident]True
    Tasks open > 24hSecurity Incident Response Task [sn_si_task]True
    Incidents open > 24hSecurity Incident [sn_si_incident]True
    Open Tasks with Priority = CriticalSecurity Incident Response Task [sn_si_incident]True
    Open Incidents with Priority = CriticalSecurity Incident [sn_si_incident]True
    Risk score >= 80Security Incident [sn_si_incident]True
    Open Phishing IncidentsSecurity Incident [sn_si_incident]True

    Note: The security admin can go ahead and configure these quick filters. As per the business need, admin can modify the existing value to false and create a quick filter.

Image omitted: quick-filters-list-view.png
Quick filters list view
  1. Click New to create a new filter.

  2. Enter a name for the filter, select the Table, specify the filter condition.

  3. Click Submit to return to the previous list page.

    You will see the newly added filter listed on the page.

Image omitted: new-filter.png
new filter
**Note:**

-   The quick filter will be applicable only if the **Active** check box is selected.
-   Within the workspace, any logged in user can personalize the active quick filters which are available in the application. Users can hide or unhide the newly created quick filters. This feature is based on their user preference.
-   If a user has modified the preferences for quick filters and a new quick filter is created after that, then if the quick filter is set to active, it will not apply to the user's preference. The user has to manually change the preferences in the personalized view.
  1. Select any existing filter record to modify the existing quick filters.

  2. Modify the name and filter condition.

  3. Click Update.

  4. Add or modify quick filters
    Add or modify quick filters for security incidents or response tasks within the list view.

Parent Topic:List view in SIR Workspace

Related topics

Personalize a list

Apply quick filters on Security Incidents and Response Tasks lists

Assign Security Incidents

Close multiple security incidents

Assign Response Tasks

Report Phish Email

Export Security Incidents or Response Tasks

Manage Shift Handover records