Workload Protection findings are generated when Agent events from a resource (a host or container) match a finding rule. View, filter, and triage findings in the Findings Explorer to assess and improve your runtime security posture.

Datadog stores a complete history of findings for investigation and audit.

Findings Explorer

The Findings Explorer lists findings across your infrastructure. Each entry shows the affected resource, the finding rule that generated the finding, when the issue was first reported, its current status, and the responsible team or service.

Click View All to see a complete list of resources affected by the same finding rule.

Filter findings

Use the search bar and facet panel to narrow findings by severity, triage state, rule, host, or container.

To filter by triage state, use the search query @workflow.triage.status:(open OR in-progress).

Group findings

Use Group by to organize the list:

  • Rule Name: Groups resources by finding rule.
  • Resource Name: Groups findings by host or container.
  • None: Shows a flat list of findings.

Save views

To save your current search and filter settings for future use, hover over Views and click Save as new view.

Finding details

Click any finding to open the side panel with detailed information about the resource and the finding rule that generated it.

Finding side panel showing What Happened section and triage controls

The What Happened section shows:

  • When the finding was first reported.
  • The location of the affected resource.
  • The finding rule that matched.

Select the Trigger Event tab to review the Agent event associated with the finding.

Remediation guidance

Each OOTB finding rule includes remediation guidance authored by the Datadog security team. Select the Remediation tab to review the remediation steps and address the underlying misconfiguration.

Finding details showing remediation steps for an affected resource

Triage findings

Use Next Steps in the finding side panel to manage findings:

  • Status: Update the finding’s status to reflect investigation progress.
  • Mute: Suppress a finding for a specified duration when the behavior is expected or acceptable.
  • Add Ticket: Add the finding to a ticket for follow-up.