<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/posture/findings/</link><description>Recent content on Findings</description><language>en</language><lastBuildDate>Thu, 23 Jul 2026 14:30:14 +0100</lastBuildDate><image><url> https://docs.sysdig.com/icons/sysdig-horizontal.png</url><title>Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/posture/findings/</link><description>Sysdig logo</description></image><item><title>Findings - Understand Posture Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/posture/findings/#understand-posture-findings</link><description>The Posture Findings page provides a detailed, table-based view of all posture-related issues detected across your cloud and Kubernetes infrastructure. It is designed for security analysts and engineers to drill down into specific findings, understand their context, and take remediation actions.</description><content:encoded>&lt;p>The &lt;strong>Posture Findings&lt;/strong> page provides a detailed, table-based view of all posture-related issues detected across your cloud and Kubernetes infrastructure. It is designed for security analysts and engineers to drill down into specific findings, understand their context, and take remediation actions.&lt;/p></content:encoded><guid isPermaLink="false">Understand Posture Findings</guid></item><item><title>Findings - Access Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/posture/findings/#access-findings</link><description>Use the filters at the top of the page to narrow the results and focus on the most relevant issues. You can apply a range of posture-specific filters.</description><content:encoded><![CDATA[<ol>

<li>In Sysdig Secure, go to <strong>Posture</strong> &gt; <strong>Findings</strong>.</li>

<li>Use the filters and grouping options at the top to refine the results.</li>
</ol>


<p>Use the filters at the top of the page to narrow the results and focus on the most relevant issues. You can apply a range of posture-specific filters.</p>

<h3 id="default-filters">Default Filters</h3>
<p>The following filters are available by default:</p>

<ul>

<li><strong>Search:</strong> Filter findings by resource name.</li>

<li><strong>Zone:</strong> Filter by one or more <a href="/en/zones/">Zones</a>, logical groupings such as accounts, clusters, or applications.</li>

<li><strong>Severity:</strong> Filter findings by severity: <strong>High</strong>, <strong>Medium</strong>, or <strong>Low</strong>.</li>

<li><strong>Risk Accepted:</strong> Filter findings by whether they have been accepted.</li>
</ul>


<h3 id="additional-filters">Additional Filters</h3>
<p>Click <strong>+ Add</strong> to apply more granular filters, or use filters automatically applied when drilling down from the <a href="/en/sysdig-secure/posture/overview/">Posture Overview</a> dashboard:</p>

<ul>

<li><strong>Account ID</strong>: Cloud account, subscription, or project ID where the resource resides.</li>

<li><strong>Cluster Name</strong>: Kubernetes cluster that hosts the resource.</li>

<li><strong>Control Name</strong>: Name of the evaluated control.</li>

<li><strong>Organization</strong>: Organization that owns the resource.</li>

<li><strong>Owner</strong>: Owner of the evaluated control.</li>

<li><strong>Platform</strong>: Filter by resource platform (for example, AWS, Azure, GCP, OCI, Kubernetes).</li>

<li><strong>Resource Category</strong>: High-level classification of the resource (for example, Compute, Storage, Network).</li>

<li><strong>Resource Family</strong>: Sub-classification within a category (for example, Application, Database, Volume).</li>

<li><strong>Resource ID</strong>: Unique identifier of the resource.</li>

<li><strong>Resource Name</strong>: Human-readable resource name.</li>

<li><strong>Resource Type</strong>: Specific type of resource (for example, Cloud SQL Backup Run, S3 Bucket, IAM Policy).</li>
</ul>]]></content:encoded><guid isPermaLink="false">Access Findings</guid></item><item><title>Findings - Grouping Findings</title><link>https://docs.sysdig.com/en/sysdig-secure/posture/findings/#grouping-findings</link><description>You can group findings to change how data is presented:</description><content:encoded><![CDATA[<p>You can group findings to change how data is presented:</p>

<ul>

<li><strong>None:</strong> Displays individual findings line by line.</li>

<li><strong>Resource:</strong> Groups findings by affected resource, aggregating all findings for that resource into a single row.</li>

<li><strong>Control:</strong> Groups findings by evaluated control, aggregating all findings for that control into a single row.</li>
</ul>]]></content:encoded><guid isPermaLink="false">Grouping Findings</guid></item><item><title>Findings - Findings Table Columns</title><link>https://docs.sysdig.com/en/sysdig-secure/posture/findings/#findings-table-columns</link><description>Column definitions vary depending on how the data is grouped.</description><content:encoded><![CDATA[<p>Column definitions vary depending on how the data is grouped.</p>

<h3 id="group-by-none">Group by None</h3>
<p>No grouping is applied. The following columns are displayed:</p>
<table>
	<thead>
			<tr>
					<th>Column</th>
					<th>Description</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>Control</strong></td>
					<td>Name of the control.</td>
			</tr>
			<tr>
					<td><strong>Resource</strong></td>
					<td>Affected resource (for example, <code>rtb-1234567890abcdef0</code>, <code>aks-agentpool-20481852-vmss</code>).</td>
			</tr>
			<tr>
					<td><strong>Platform</strong></td>
					<td>Resource platform (for example, AWS, Azure, GCP, Kubernetes, Linux).</td>
			</tr>
			<tr>
					<td><strong>Resource Context</strong></td>
					<td>Additional context about the resource (for example, organization, subscription).</td>
			</tr>
			<tr>
					<td><strong>Severity</strong></td>
					<td>Severity of the finding.</td>
			</tr>
			<tr>
					<td><strong>Accepted</strong></td>
					<td>Whether the finding risk is accepted.</td>
			</tr>
			<tr>
					<td><strong>Zones</strong></td>
					<td>Relevant <a href="/en/zones/">Zones</a>.</td>
			</tr>
			<tr>
					<td><strong>First Seen</strong></td>
					<td>Timestamp when the finding was first observed for the resource.</td>
			</tr>
	</tbody>
</table>

<h3 id="group-by-resource">Group by Resource</h3><table>
	<thead>
			<tr>
					<th>Column</th>
					<th>Description</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>Resource</strong></td>
					<td>Affected resource (for example, <code>rtb-1234567890abcdef0</code>, <code>aks-agentpool-20481852-vmss</code>).</td>
			</tr>
			<tr>
					<td><strong>Platform</strong></td>
					<td>Resource platform (for example, AWS, Azure, GCP, Kubernetes, Linux).</td>
			</tr>
			<tr>
					<td><strong>Resource Context</strong></td>
					<td>Additional context about the resource (for example, organization, subscription).</td>
			</tr>
			<tr>
					<td><strong>Passing Score</strong></td>
					<td>Passing score for the resource.</td>
			</tr>
			<tr>
					<td><strong>Findings</strong></td>
					<td>Number of findings affecting the resource.</td>
			</tr>
			<tr>
					<td><strong>Zones</strong></td>
					<td>Relevant <a href="/en/zones/">Zones</a>.</td>
			</tr>
	</tbody>
</table>]]></content:encoded><guid isPermaLink="false">Findings Table Columns</guid></item><item><title>Findings - Review Findings in Detail</title><link>https://docs.sysdig.com/en/sysdig-secure/posture/findings/#review-findings-in-detail</link><description>Click a row to open a contextual side panel:</description><content:encoded><![CDATA[<p>Click a row to open a contextual side panel:</p>

<ul>

<li>

<p><strong>Flat List (No Grouping):</strong> Opens the <strong>Findings Detail</strong> panel, which includes:</p>

<ul>

<li>Resource details.</li>

<li>Finding specifics: description, severity, and configuration summary.</li>

<li>Remediation guidance.</li>
</ul>

</li>

<li>

<p><strong>Grouped by Resource:</strong> Opens the <strong>Resource</strong> panel, which includes:</p>

<ul>

<li>All configuration findings associated with the resource.</li>

<li>Remediation options for each finding.</li>
</ul>

</li>
</ul>


<p>These detailed views provide full context for prioritizing and resolving issues, supporting effective security posture enforcement across your cloud environment.</p>]]></content:encoded><guid isPermaLink="false">Review Findings in Detail</guid></item></channel></rss>