You can view the details of actions performed by Trellix EDR users on the Monitoring and Investigating dashboards and actions taken from the Real-time Search dashboard.
The Action History page displays the list of threats, investigation name, the time when an action was taken, the type of action taken, status of an action, and the number of affected devices.
You can select a threat name and view the details of the device and the action.
The page includes these details:
Action Taken — Actions taken from the Monitoring and the Investigating dashboards (Stop and Remove, Quarantine, End Quarantine, Exclude from threats, and Dismiss).
Number of threats — Number of threats available in the Monitoring and Investigating dashboards.
Action Taken On — Date and time when the user initiated the action.
Action Status — States whether the action was completed successfully or resulted in an error.
Threat Name — Name of the threat on which the action was taken from the Monitoring dashboard. When an action is taken from outside of the Monitoring dashboard, the Threat name field appears blank. If there is an investigation, the threat name appears as a hyperlink that takes you to the Threat Details page in the Monitoring dashboard.
Investigation name — Name of an investigation for which an action is taken from the Investigating dashboard.
Note
Both the Threat name and Investigation name fields are blank when you take action from the Real-time Search dashboard.
Devices — Number of devices impacted by some actions such as quarantine and end quarantine.
Note
If the action is Exclude or Dismiss a threat, then the number of devices column is not populated as these actions have no impact on devices.
User — Email address of the user who initiated the action.
When you select a row, details of the affected devices are displayed. Details include device name, action status, the time when the user initiated the action, operating system details, ePO - On-prem tags associated with the device, MAC address, and the internal IP address of the device.
Note
You can view audit log entries using the Audit Log (Menu → Reporting → Audit Log) page for endpoint-related actions that are triggered from the cloud.