---
title: Findings
description: >-
  Review and triage Workload Protection findings to address runtime security
  posture issues.
breadcrumbs: >-
  Docs > Datadog Security > Workload Protection > Investigate and Triage >
  Findings
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Findings

[Workload Protection](https://docs.datadoghq.com/security/workload_protection.md) findings are generated when Agent events from a resource (a host or container) match a [finding rule](https://docs.datadoghq.com/security/workload_protection/detect_and_monitor/detection_and_finding_rules/finding_rules.md). View, filter, and triage findings in the [Findings Explorer](https://app.datadoghq.com/security/workload-protection/findings) to assess and improve your runtime security posture.

Datadog stores a complete history of findings for investigation and audit.

## Findings Explorer{% #findings-explorer %}

The [Findings Explorer](https://app.datadoghq.com/security/workload-protection/findings) lists findings across your infrastructure. Each entry shows the affected resource, the finding rule that generated the finding, when the issue was first reported, its current status, and the responsible team or service.

Click View All to see a complete list of resources affected by the same finding rule.

### Filter findings{% #filter-findings %}

Use the search bar and facet panel to narrow findings by severity, triage state, rule, host, or container.

To filter by triage state, use the search query `@workflow.triage.status:(open OR in-progress)`.

### Group findings{% #group-findings %}

Use Group by to organize the list:

- Rule Name: Groups resources by finding rule.
- Resource Name: Groups findings by host or container.
- None: Shows a flat list of findings.

### Save views{% #save-views %}

To save your current search and filter settings for future use, hover over Views and click Save as new view.

## Finding details{% #finding-details %}

Click any finding to open the side panel with detailed information about the resource and the finding rule that generated it.

{% image
   source="https://docs.dd-static.net/images/security/workload_protection/investigate_and_triage/findings/findings_side_panel.cfa4467583e7ee8a5c5cdd990dda5bbe.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/security/workload_protection/investigate_and_triage/findings/findings_side_panel.cfa4467583e7ee8a5c5cdd990dda5bbe.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="Finding side panel showing What Happened section and triage controls" /%}

The What Happened section shows:

- When the finding was first reported.
- The location of the affected resource.
- The finding rule that matched.

Select the Trigger Event tab to review the Agent event associated with the finding.

### Remediation guidance{% #remediation-guidance %}

Each OOTB finding rule includes remediation guidance authored by the Datadog security team. Select the Remediation tab to review the remediation steps and address the underlying misconfiguration.

{% image
   source="https://docs.dd-static.net/images/security/workload_protection/investigate_and_triage/findings/findings_remediation.2b84aeae2600de476f179bba81f84eff.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/security/workload_protection/investigate_and_triage/findings/findings_remediation.2b84aeae2600de476f179bba81f84eff.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="Finding details showing remediation steps for an affected resource" /%}

## Triage findings{% #triage-findings %}

Use Next Steps in the finding side panel to manage findings:

- Status: Update the finding's status to reflect investigation progress.
- Mute: Suppress a finding for a specified duration when the behavior is expected or acceptable.
- Add Ticket: Add the finding to a ticket for follow-up.
