You can look at recent events to see information about any identified threats to your systems.
You can view enforced or observed events:
Enforcement Events — Events that occur as a result of an enforced Adaptive Threat Protection server policy.
Observation Events — Events, such as Would Block, that indicate what the action would be if the policy were enforced. It allows you to view, evaluate, and adjust policy and configuration settings before enforcing them. You can see which files or certificates are causing events, and change their reputation settings so they no longer generate an event.
You can view threat events in several ways and drill down for more information:
Past 30 days —Event summary information for the past 30 days.
Top 10 — The top 10 events by system, file, or certificate.
Certificate — The certificate name, its SHA-1 hash value, and the number of certificates that were cleaned, contained, blocked, or prompted.
File Hash — The file name and SHA-1 hash value, and the number of files that were cleaned, contained, blocked, or prompted.
Rule — The rule name, events where the rule was applied, and the number of rules that were cleaned, contained, blocked, or prompted.
System — The system name, total events for that system, and the number of events that were cleaned, contained, blocked, or prompted on a particular system.
Examples
You can then see details about the specific files or certificates that are causing the prompts. Select individual files or certificates from the Events page and change their reputation levels to allow or block them so that they no longer generate a prompt.
If a specific file generates events, select it from the list on the Events page and see which systems tried to run it and what action was taken. You can then change the file's reputation so that it no longer generates events. For example, if the file generates a prompt and you want it blocked, change its reputation so that it is blocked and does not generate an event.