Create a threat events summary query: best practice

Prev Next

To provide threat notification to your administrators, create a threat events summary query to display threat events sent from your agents to the ePO - On-prem server.

In this example, threat events include a virus found, a Data Loss Protection event triggered, or an intrusion detected.

For details about product features, usage, and best practices, click ? or Help.

  1. To start the query configuration, select MenuReportingQueries & Reports.

  2. From the Queries page, click New Query.

  3. From the Query wizard page, starting with the Result Types tab, click Events in the Features Group and Threat Events in the Result Type, and click Next.

  4. From the Chart page, under Summary, click Single Group Summary Table, to display a total count of all threat events in the events table.

  5. To create a filter with a good human-readable description of the events, click Event Description, in the Labels are list, under Threat Event Descriptions.

    Optionally, you can filter by the Event ID which is the number that represents client event data in ePO - On-prem. For details about managed product generated event IDs listed in ePO - On-prem, see General list of Event IDs sent to ePolicy Orchestrator, KB54677.

  6. If needed, adjust the columns information based on the type that you want displayed, then click Next.

  7. On the Filter page, you do not need any filtering because you want every client event returned in the database. Optionally, you can create a query based on events generated in a certain time, for example the last 24 hours, or the last 7 days. Click Run to display the query report.

  8. To determine about how many events you should have on your network, use the following formula:

    (10,000 nodes) x (5 million events) = estimated number of events

    For example, if you have 50,000 nodes, your range is 25 million total client and threat events.

    Note

    This number varies greatly based on the number of products and policies you have and your data retention rate. Do not panic if you exceed this number.

    If you significantly exceed this number, determine why you have so many events. Sometimes this many events are normal if you receive a significant number of viruses in unrestricted networks, such as universities or college campuses. Another reason for a high event count could be how long you keep the events in your database before purging. Here is what to check:

    • Are you purging your events regularly?

    • Is there a specific event in the query that comprises most of your events?

    Remember, it's common to forget to include a purge task. This causes ePO - On-prem to retain every event that has occurred since the ePO - On-prem server was built. You can fix this simply by creating a purge task.

    If you notice one or two events make up a disproportionate number of your events, you can then determine what they are by drilling down into those events. For example, if you see that the event with the most instances is an access protection rule from Threat Prevention. This is a common event. If you double-click the Access Protection rule event to drill down on the cause, you can see that a few access protection rules are being triggered repeatedly on Threat Prevention.

  9. At this point, determine whether these are important events in your organization and if they are being looked at by administrators. Ignoring some events is common by some administrators.

    Ultimately, when dealing with excessive events in your database, you must follow this process:

    1. Create a query that shows all events you are questioning, then use the information in this section to analyze these threat events.

    2. Determine if anyone is looking at these excessive events in the first place.

    3. If events are not being analyzed, change your policy to stop the event forwarding.

    4. If the event is important, make sure that you are monitoring the number of events.

    If no one is looking at these events, you might consider disabling them completely in the Threat Prevention access protection policy to stop them from being sent to the ePO - On-prem server. Or, you can adjust your policy to send only the access protection events that you are concerned with instead of excessive events that are not being analyzed. If you do want to see these events, you can leave the policy as configured, but confirm that you are following the rules about purging events from the ePO - On-prem server so that these events do not overrun your database.