---
title: Signals
description: >-
  Search, filter, and triage the security signals that Workload Protection
  detection rules generate.
breadcrumbs: >-
  Docs > Datadog Security > Workload Protection > Investigate and Triage >
  Signals
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Signals

[Workload Protection](https://docs.datadoghq.com/security/workload_protection.md) security signals are created when Datadog detects a threat based on a security rule. View, search, filter, and investigate security signals in the [Signals Explorer](https://app.datadoghq.com/security/workload-protection/signals), or configure [Notification Rules](https://docs.datadoghq.com/security/notifications/rules.md) to send signals to third-party tools.

## Signals Explorer{% #signals-explorer %}

The [Signals Explorer](https://app.datadoghq.com/security/workload-protection/signals) lists Workload Protection security signals generated by [detection rules](https://docs.datadoghq.com/security/workload_protection/detect_and_monitor/detection_and_finding_rules/detection_rules.md). Use the search bar or facet panel to filter signals by severity, triage state, detection rule, host, container, and other attributes. For example, to filter by triage state, use `@workflow.triage.state:<status>`, where `<status>` is the state you want (`open`, `under_review`, or `archived`). You can also use the Signal State facet on the facet panel.

Select a signal to open the side panel. From there, you can [investigate the threat](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_signals/investigate.md) using the investigation graph, timeline, context, and Signal JSON, or [take action](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_signals/actions.md) to triage, escalate, automate, or respond to the signal.

## Next steps{% #next-steps %}

Learn how to investigate and respond to Workload Protection signals:

- [Investigate signals with the investigation graph, timeline, and Signal JSON](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_signals/investigate.md)
- [Triage and act on signals: assign, escalate, automate, and enforce](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_signals/actions.md)
 