Viewing OS change event distribution in a tree view in the Web UI

Prev Next

You can view OS change event distribution in a tree view. This view shows events that resulted from a prior event nested together, and you can expand and collapse subsequent levels to reveal and hide details. All available details for malicious alerts are shown in a table, including Class, Message, and Triggered Event.

To view the OS change event distribution in a tree view:
  1. In the Web UI, click eAlerts > eAlerts > Alerts.

  2. Select an alert. For alerts that have embedded file attachments, expand the alert and select the alert for the embedded malicious file.

    Note

    Duplicate alerts for files with embedded file attachments cannot be expanded.

  3. In the left navigation bar, click the OS Change Details link for a guest image.

  4. Click the Event Distribution tab.

  5. At the upper right of the Event Distribution tab, select Treeview.

  6. Expand the malicious alerts sections at the top of the view to see the most urgent information. Known malicious alert sections are titled in red.

  7. Expand process sections and drill down into sub-process sections to follow a flow of events.

  8. Click an OS change event type in the upper right of the expanded tree section to reveal that event in the tree.