---
title: Investigate and Triage
description: >-
  Investigate Workload Protection Agent events, security signals, and findings
  in Datadog.
breadcrumbs: Docs > Datadog Security > Workload Protection > Investigate and Triage
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Investigate and Triage

As Workload Protection evaluates runtime activity, it produces agent events, signals, and findings. Use the Agent Events Explorer to investigate runtime activity, the Signals Explorer to investigate threats, and the Findings Explorer to review runtime security posture issues.

For how each one is produced, see [How Workload Protection works](https://docs.datadoghq.com/security/workload_protection.md#evaluating-activity).

## Agent events{% #agent-events %}

[Agent events](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/agent_events.md) are the raw telemetry generated by the Datadog Agent when runtime activity matches an agent rule. Use the Agent Events Explorer to investigate this activity.

## Signals{% #signals %}

[Signals](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_signals.md) are generated when agent events match a backend detection rule. Use the Signals Explorer to investigate threats, triage signals, and take response actions.

Explore Workload Protection signals:

- [Investigate signals](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_signals/investigate.md)
- [Triage and act on signals](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_signals/actions.md)
 
## Findings{% #findings %}

[Findings](https://docs.datadoghq.com/security/workload_protection/investigate_and_triage/security_findings.md) are generated when agent events match a finding rule. Use the Findings Explorer to review runtime security posture issues.
