Detection finding events represent alerts or detections generated by security tools or Dynatrace detection rules. Detections are available for both Dynatrace-generated and third-party ingested data.
Provides an overview of detection findings by normalized risk level.
fetch security.events| filter event.type == "DETECTION_FINDING"| summarize {findings = count()}, by: {dt.security.risk.level}| sort findings desc
Lists the most recent detection findings across the domain.
fetch security.events| filter event.type == "DETECTION_FINDING"| sort timestamp desc
Counts detection findings by provider and product.
fetch security.events| filter event.type == "DETECTION_FINDING"| summarize {findings = count()}, by: {event.provider, product.name}| sort findings desc
A detection finding is an alert raised by a security tool or a Dynatrace detection rule when it observes suspicious or malicious activity—for example, an exploit attempt, a policy violation, or anomalous behavior. Detection findings are available for both Dynatrace-generated data and findings ingested from third-party security tools, and are primarily consumed in the Threats & Exploits app. Unlike a vulnerability finding, which reports a known weakness in a scanned object, a detection finding reports activity that was observed. Native Dynatrace findings (produced by the Automated Detections capability) additionally carry detection.* fields (the configured detection strategy) and scan.* fields (the scan that produced them); ingested third-party findings do not.
Lists the most recent detection findings.
fetch security.events| filter event.type == "DETECTION_FINDING"| sort timestamp desc
Counts detection findings by normalized risk level.
fetch security.events| filter event.type == "DETECTION_FINDING"| summarize {findings = count()}, by: {dt.security.risk.level}| sort findings desc
Counts critical and high detection findings by finding type and risk level.
fetch security.events| filter event.type == "DETECTION_FINDING"| filter in(dt.security.risk.level, {"CRITICAL", "HIGH"})| summarize {findings = count()}, by: {finding.type, dt.security.risk.level}| sort findings desc
Core event metadata. These fields identify the event record and are added automatically by Dynatrace during ingest.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stable |
|
| string | stable |
|
| string | stable |
|
| timestamp | stable |
|
Information about the security finding.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stable |
|
| timestamp | stable |
|
| string | stable |
|
| string | stable |
|
Information about the object in which the detection finding was raised.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | resource experimental |
|
| string | resource experimental |
|
| string | resource experimental |
|
Information about the product or tool that raised the detection finding.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stable |
|
| string | resource experimental |
|
| string | resource experimental |
|
Optional fields for detection findings (their existence in an event does not influence if they're displayed in T&E or not).
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stable |
|
| string | stable |
|
| string[] | experimental |
|
| string[] | experimental |
|
| string[] | experimental |
|
| string[] | experimental |
|
| string[] | experimental |
|
| string[] | experimental |
|
| string | experimental |
|
Fields added by Dynatrace to normalize and enrich the finding with platform-level risk assessment and Smartscape entity resolution.
| Attribute | Type | Description | Examples |
|---|---|---|---|
| string | stable |
|
| smartscapeId | resource stable |
|
| string | stable |
|
The value of this field will be based on the value of one of the dt.smartscape.<type> fields. That means that the dt.smartscape_source.id and dt.smartscape.<type> fields will both be set to the same ID.
A detection finding generated by Dynatrace Runtime Application Protection, reporting a blocked SQL injection attempt against a Node.js process. Dynatrace resolves the targeted process to a Smartscape entity and adds dt.smartscape_source.* during ingest.
{"event.kind": "SECURITY_EVENT","event.type": "DETECTION_FINDING","event.provider": "OneAgent","product.vendor": "Dynatrace","product.name": "Runtime Application Protection","finding.id": "A-35VEHCHS","finding.title": "Blocked SQL injection attempt at Query.ErrorPacket() (Query.js:83:17)","finding.type": "SQL injection","finding.action": "denied","finding.time.created": "2026-07-14T18:07:39.274000000Z","dt.security.risk.level": "CRITICAL","object.id": "PROCESS-87234EE293F14F76","object.type": "PROCESS","object.name": "BloatedNodeJsSoftwareGroup-IG-1","dt.smartscape_source.id": "PROCESS-87234EE293F14F76","dt.smartscape_source.type": "PROCESS"}
A detection finding ingested from Akamai SIEM reporting a cross-site scripting attempt against a web endpoint, showing the finding metadata, the affected object (the targeted URL), and the normalized Dynatrace risk level.
{"event.kind": "SECURITY_EVENT","event.type": "DETECTION_FINDING","event.provider": "Akamai","product.vendor": "Akamai","product.name": "Akamai SIEM","finding.id": "1753176775716859162-86508-3000110-","finding.title": "Cross-site Scripting (XSS) Attack (SmartDetect)","finding.type": "Cross-site scripting","finding.action": "observed","finding.time.created": "2026-04-24T13:19:00.959138000Z","dt.security.risk.level": "MEDIUM","detection.analytic.name": "Cross-site Scripting (XSS) Attack (SmartDetect)","detection.analytic.type": "Rule","object.id": "atlas-int-01-channel-api.sampledomain.com:443/authz/v2/token","object.type": "URL","object.name": "atlas-int-01-channel-api.sampledomain.com:443/authz/v2/token"}
A native finding produced by the Automated Detections capability (a scheduled DQL detection). In addition to the finding metadata, it carries the native detection.* strategy, the detection.analytic.* classification, the scan.* correlation key, and—because the detection has findingEventIncludeExecutedQuery enabled—the per-finding drilldown query fields (finding.query.*, finding.drilldowns). Correlate with the corresponding detection scan event via scan.id.
{"event.kind": "SECURITY_EVENT","event.type": "DETECTION_FINDING","event.provider": "Dynatrace Automated Detections","product.vendor": "Dynatrace","product.name": "Automated Detections","finding.id": "A-4KQ2ZP1M","finding.title": "Brute force login attempts against admin on host prod-web-01","finding.type": "Brute force","finding.action": "observed","finding.time.created": "2026-07-14T18:07:39.274000000Z","dt.security.risk.level": "HIGH","detection.id": "5fd01409-c65b-4d93-8fc5-340259c288df","detection.name": "Brute Force Login Attempts","detection.description": "Detects repeated failed authentication attempts against a single user account from the same source IP within a short window.","detection.owner.id": "team-security-ops","detection.analytic.name": "Brute Force Login Attempts","detection.analytic.type": "Rule","detection.analytic.category": "DQL","detection.analytic.id": "5fd01409-c65b-4d93-8fc5-340259c288df","scan.id": "9f3c2e1a-4b7d-4a8e-bc6f-3d2e9a1f7c4b","scan.actor.id": "srv-threat-detection","finding.query.filter": "filter dt.smartscape_source.id == \"PROCESS_GROUP-E0D8F94D9065F24F\"","finding.query.compiled": "fetch logs | filter log.source == \"windows.security\" | filter dt.smartscape_source.id == \"PROCESS_GROUP-E0D8F94D9065F24F\"","finding.query.timeframe.start": "2026-07-14T18:02:00.000000000Z","finding.query.timeframe.end": "2026-07-14T18:07:00.000000000Z","finding.drilldowns": [{ "title": "Failed logins on affected host", "query": "fetch logs | filter log.source == \"windows.security\" | filter event.type == \"FAILED_LOGIN\" | filter dt.smartscape_source.id == \"PROCESS_GROUP-E0D8F94D9065F24F\"", "timeframe.start": "2026-07-14T18:02:00.000000000Z", "timeframe.end": "2026-07-14T18:07:00.000000000Z" },{ "title": "Source IPs by attempt count", "query": "fetch logs, from: now()-24h | filter log.source == \"windows.security\" | summarize attempts = count(), by: {source.ip} | sort attempts desc" }],"object.id": "PROCESS_GROUP-E0D8F94D9065F24F","object.type": "PROCESS_GROUP","object.name": "prod-web-01 auth service","dt.smartscape_source.id": "PROCESS_GROUP-E0D8F94D9065F24F","dt.smartscape_source.type": "PROCESS_GROUP"}