To tune your deployment, analyze client rules created in Adaptive mode, and events triggered by activity on the clients.
From client rules data, you can:
See which rules are being created.
Aggregate rules to find the most common rules.
Move the rules directly to a policy for application to other clients.
From event data, you can see firewall intrusions and block events. Drill down to the details of an event to see:
Which process triggered the event
When the event was generated
Which client generated the event
Use ePO - On-prem queries and reports to gather information about client rules. Use the Threat Event Log to view all threat events that ePO - On-prem receives from managed systems. Analyze the event and take the appropriate action to tune the Host Intrusion Prevention deployment to provide better response to attacks.