> For the complete documentation index, see [llms.txt](https://knowledge.whiteintel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://knowledge.whiteintel.io/monitoring/watchlist-events.md).

# Watchlist Events

Watchlist Events is the continuous alert feed for the assets you monitor. Every detection against a watchlist identifier appears here as an event, ready for review and triage.

**Availability:** All plans, for the identifiers your subscription permits.

<figure><img src="/files/saWbgbQpUOY1oWY1yFm0" alt=""><figcaption></figcaption></figure>

### Event-type tabs

A tab strip below the page header filters the feed by event type:

* **All** — every event.
* **Leaks** — credential leaks from stealer and combolist sources.
* **Mentions** — dark web mentions.
* **Exposed Secrets** — exposed repository secrets.

The selected tab and sub-tab are reflected in the page URL, so a view can be bookmarked or refreshed in place.

<div align="left"><figure><img src="/files/kZPCO6wk4PWsGxPjDHu9" alt=""><figcaption></figcaption></figure></div>

### Filters

The toolbar refines the feed by:

* **Identifier** — a specific monitored domain, keyword, or watchlist group.
* **Date range** — a quick range such as the last 7, 30, or 90 days.
* **Status** — open, resolved, or unresolved.

A time-series card alongside the list summarizes event volume over the selected range, with a day, week, or month bucket selector.

### Reading an event

Each event is presented as a card with a generated title that states the audience, the action, and the subject, along with the credential count, the entry, tags for type and status, and the affected log-date window. While the feed loads, skeleton placeholders preserve the layout.

Selecting an event opens its detail sidebar, where the full record is available subject to your entitlements.

<figure><img src="/files/xHW3FPx8d8AZ4y0DQWKK" alt=""><figcaption></figcaption></figure>

### Status and resolution

Events carry a status so they can be triaged. You can change an event's status as you work through the feed, and filter by status to focus on what remains open.

### Exporting

The feed can be exported to CSV under the current filters for offline reporting.
