---
title: "View leads"
slug: "view-leads"
updated: 2025-03-05T16:28:51Z
published: 2025-03-05T16:28:51Z
canonical: "docs.hunters.ai/view-leads"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# View leads

You can view leads on Hunters in 2 locations: the SOC Queue and the Leads page. While the Leads page displays a complete list of leads depending on the selected timeframe, the SOC Queue will display only leads that have reached a specific threshold rendering them more pressing or critical.

## On the leads page

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/TC3.png)

On the Leads page, leads are presented in a nested methodology in the following structure:

- Detector
  - Threat cluster
    - Context (optional)
      - Lead

**To view leads on the Leads page:**

1. Navigate to **Threat Hunting> Leads**.  

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/leads%20in%20menu.png)
2. Use the timeframe filter from the upper bar to show only leads in a specific timeframe.
3. Use the Leads page filters and sorting options to show only leads answering a specific set of criteria.  

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/leads%20filters.png)
4. To view leads, expand the detector and cluster levels to expose the leads below it, and then click the lead row to open the Lead details panel.  

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/drilldown%20leads%20page.png)

          📘 Note

          

The leads displayed on the Leads page are limited by any applied filters.

---

## On the SOC Queue

The SOC Queue displays only leads that have reached a specific threshold rendering them more pressing or critical. This setting can be changed using the [Alert generation settings](/v1/docs/define-alert-generation-settings).

          📘 Note

          

The SOC Queue does not display all leads. To view a complete list of all leads in the system, navigate to the Leads page.

You can currently use the SOC Queue to view leads in 2 viewing methods: Clustered and Unclustered. When using Clustered view, all of the leads in the queue will be aggregated into threat clusters and will not appear individually.

          📘Learn more

          

[Learn more](/v1/docs/about-threat-clusters) about threat clusters.

**To view leads on the SOC Queue:**

1. Navigate to **Security Operations > SOC Queue**.  

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/socqueue.png)
2. Use the timeframe filter from the upper bar to show only leads in a specific timeframe.
3. Use the SOC Queue filters to show only leads answering a specific set of criteria. You can filter by assignee, status, and data source.  

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/filter%20socq.png)
4. Continue according to the selected view:
  - **Clustered** - to view leads, expand the cluster level to expose the leads below it, and then click the lead row to open the Lead details panel.  

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/lead%20under%20cluster.png)
  - **Unclustered** - click on any lead row to open the Lead details panel.  

![image](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/lead%20row.png)
