---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Working with quick filters

# Working with quick filters {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Quick filters are easily accessible filters that are available on, security incidents
and response tasks lists.

## Before you begin

Role required: sn_si.admin

The SIR Workspace provides quick filters feature that allows
you to filter the list of security incidents or response tasks with ease.  
You can use quick filters to configure new filters or modify existing filters that appear against these lists. The base system provides the following quick filters for each security incident:

* Incidents Opened Today
* Incidents open \> 24hrs
* Open incidents with Priority= Critical
* Risk \>= 80
* Open Phishing Incidents
{#configure-quick-filters__ul_bcd_333_kyb}  
The base system provides the following quick filters for each response task:

* Tasks open \> 24h
* Open Tasks with Priority = Critical

{#configure-quick-filters__ul_qfj_qwf_y5b}  
Note:  
An admin can configure the required list of quick filters according to the organization need.

## Procedure

1. Navigate to System DefinitionTables.
2. Search for Quick Filters (sn_si_aw_quick_filters).
3. Go to Related LinksShow List section.  
   The Quick Filters list page is displayed. OOTB, following is the list of quick filters shipped with the application.{#configure-quick-filters__table_gdm_3wm_x5b__entry__3}

   | Name | Table | Value |
   |-|-|-|
   | Tasks opened Today | Security Incident Task \[sn_si_task\] | True |
   | Incidents opened Today | Security Incident \[sn_si_incident\] | True |
   | Tasks open \> 24h | Security Incident Response Task \[sn_si_task\] | True |
   | Incidents open \> 24h | Security Incident \[sn_si_incident\] | True |
   | Open Tasks with Priority = Critical | Security Incident Response Task \[sn_si_incident\] | True |
   | Open Incidents with Priority = Critical | Security Incident \[sn_si_incident\] | True |
   | Risk score \>= 80 | Security Incident \[sn_si_incident\] | True |
   | Open Phishing Incidents | Security Incident \[sn_si_incident\] | True |
   [ ]

   {#configure-quick-filters__table_gdm_3wm_x5b}  
   Note:  
   The security admin can go ahead and configure these quick filters. As per the business need, admin can modify the existing value to false and create a quick filter.
   Figure 1. Quick Filters
4. Click New to create a new filter.
5. Enter a name for the filter, select the Table, specify the filter condition.
6. Click Submit to return to the previous list page.  
   You will see the newly added filter listed on the page.  
   Note:  
   * The quick filter will be applicable only if the Active check box is selected.
   * Within the workspace, any logged in user can personalize the active quick filters which are available in the application. Users can hide or unhide the newly created quick filters. This feature is based on their user preference.
   * If a user has modified the preferences for quick filters and a new quick filter is created after that, then if the quick filter is set to active, it will not apply to the user's preference. The user has to manually change the preferences in the personalized view.
   {#configure-quick-filters__ul_cdy_x35_x5b}
7. Select any existing filter record to modify the existing quick filters.
8. Modify the name and filter condition.
9. Click Update.
* **[Add or modify quick filters](https://servicenow-prod.fluidtopics.net/jE_lAuUCmWdR_5oCVy5TwA)**   
  Add or modify quick filters for security incidents or response tasks within the list view.

**Related tasks**   

* [Personalize a list](https://servicenow-prod.fluidtopics.net/_RxhTpnln1PmOuwEqp9R1g "Security analysts or managers can personalize the security incidents or response tasks or phishing emails custom list view based on their individual preferences.")
* [Apply quick filters on Security Incidents and Response Tasks lists](https://servicenow-prod.fluidtopics.net/35Z73~2baAzbxtNGCt72ew "Apply the predefined quick filters on Security Incidents and Response Tasks lists to get the desired work items.")
* [Assign Security Incidents](https://servicenow-prod.fluidtopics.net/aP2FfEOHr0CacFo6ua40IQ "Assign security incidents.")
* [Close multiple security incidents](https://servicenow-prod.fluidtopics.net/Dvg2PBwYt_q~KLReXA~5sg "Close multiple security incidents at the same time to avoid having to close related incidents individually, such as incidents created with a common root cause or false positive incidents.")
* [Assign Response Tasks](https://servicenow-prod.fluidtopics.net/W_pvOPoYfE6SM60RAY0HNg "Assign Response tasks for a security issue.")
* [Report Phish Email](https://servicenow-prod.fluidtopics.net/Xa19dE_pFpmbf9OFlZFXxg "Report phishing emails from the lists view.")
* [Export Security Incidents or Response Tasks](https://servicenow-prod.fluidtopics.net/JHtI68igM~InPCAaJ594~w "Export the security incidents or response tasks from the list view.")
* [Manage Shift Handover records](https://servicenow-prod.fluidtopics.net/cnHScVK7WGH36Kp9gnPgZw "Use the Shift Handover records list view to create, edit, copy, or delete Shift Handover records. Each Shift Handover record is associated with a Shift Handover Report Template.")

*[\>]: and then


