Analyzing your system protection is an ongoing process to improve protection and performance of your system.
Analyzing your protection enables you to determine:
Which threats you are facing
What malware was used in the attack
Where the threats are coming from
Where and when the attacks occurred
How often threats are found
Which systems are being targeted
For example, if one system is being continuously attacked, you might move that system to a more secure part of your network and enable increased security.
How the attack affected the system
Protection analysis is also helpful to:
Create reports for IT and managers.
Capture information used to create scripts and queries.
Monitor network access time and Threat Prevention update network usage.
Dashboards and queries
Use dashboards to view information about your environment, including names and number of threats and how infection spreads through the environment. Use queries to determine where and when the attacks occurred.
For information, see the ePO - On-prem Help.
Threat Event Log
Use the Threat Event Log to determine which malware was used in the attack.
Threat Name and Threat Type describe what malware was used in the attack.
Event Description describes how the attack affected the system and which actions were taken on the threat.
Threat Source IP Address and Threat Target IP Address can help you determine which actions to take.
For information, see the ePO - On-prem Help.