Event Details page

Prev Next

Review details for an event. You can access this page when you click an event on the Solidcore Events page.

Option definitions

Option

Definition

Monitoring Events Details

Lists relevant details for the selected event.

  • Agent GUID — Displays the GUID value for the Solidcore Agent installed on the endpoint where the event is generated.

  • Deny Reason — Displays the reason why the action was denied at the endpoint for Execution Denied events.

  • Description — Describes the reason why the execution was denied and provides suggestion on how you can execute the file.

  • Event Command Line — Displays the CLI command executed at the endpoint where the Command Executed event is generated.

  • Event Command User Name — Displays the name of the user who executed the CLI command at the endpoint.

  • Event Display Name — Displays the event name that appears on the ePO - On-prem console.

  • Event File Name — Displays the path to the file name associated with the event.

  • Event Generated Time — Displays the time when the event is generated.

  • Event ID — Indicates the threat event ID displayed on ePO - On-prem.

  • Event Name — Displays the event name displayed at the endpoint.

  • Event Sequence Number — Displays the sequence number for the event.

  • Failed Password Attempts — Displays the number of failed password attempts made by the user. This field is displayed only for the Disabled Local CLI Access event.

  • File MD5 — Displays the MD5 value of the file where the event is generated.

  • File SHA-1 — Displays the SHA-1 value of the file where the event is generated.

  • File SHA-256 — Displays the SHA-256 value of the file where the event is generated.

  • File Type — Displays the type of file such as pe32 or pe64 for Execution Denied events.

  • Generated by an Updater — Indicates whether the event was generated by an updater.

  • Generated in an Update Window — Indicates whether the event was generated in Update mode.

  • Local CLI Disabled Duration — Displays the duration for which the local CLI is disabled due to incorrect password attempts. This field is displayed only for the Disabled Local CLI Access event.

  • Object Name — Displays the path of the object associated with the event. Based on the event type, the path can refer to a file, user, registry key, or process name.

  • Parent Process Name — Displays the path to the parent process for the process associated with the file that tried to execute or make changes where the event is generated.

  • Performed By — Displays the name of the user who was logged on to the endpoint when the event was generated.

  • Process ID — Displays the process ID for the process associated with the event.

  • Process MD5 — Displays the MD5 value for the process associated with the file that tried to execute or make changes where the File Write Denied event is generated.

  • Process Name — Displays the path to the process associated with the file that tried to execute or make changes where the event is generated.

  • Process SHA-1 — Displays the SHA-1 value for the process associated with the file that tried to execute or make changes where the File Write Denied event is generated.

  • Process SHA-256 — Displays the SHA-256 value for the process associated with the file that tried to execute or make changes where the File Write Denied event is generated.

  • Reconciliation Status — Indicates whether the event is manually reconciled.

  • Reconciliation Ticket — Displays change ticket details for the reconciled event.

  • Reputation (at Time of Execution) — Displays the reputation of the file on the endpoint at the time of execution. This value is applicable only for the Execution Denied event. For Execution Denied events where execution is denied due to malicious reputation, this column displays the reputation. Possible values include TIE Malicious Certificate, GTI Malicious Certificate, TIE Malicious Checksum, GTI Malicious Checksum, and Not Applicable.

  • Severity — Displays the event severity.

  • System Name — Displays the endpoint where the event was generated.

  • User Name — Displays the name of the user logged on to the endpoint when the event was generated.

  • User Comments — Displays the additional information recorded for an event.

  • Workflow ID — Displays the workflow ID if the event is generated in Update mode. The workflow ID provides a meaningful description for the update window.

Actions

  • Create Policy — Opens the Events: Create Custom Policy page where you can define custom rules for the file associated with the event. This option is available only for the Execution Denied, ActiveX Installation Prevented, File Write Denied, Installation Denied, Process Hijack Attempted, VASR Violation Detected, and Nx Violation Detected events.

  • View Related Requests — Opens the Policy Discovery Details page that displays detailed information about the requests associated with the event.

  • View File Details — Opens the File Details page that displays detailed information about the file associated with the event.

  • Change File Reputation (TIE) — Opens the TIE Reputations page that displays reputation information for the file associated with the request. If needed, you can edit the file reputation.

  • View Content Change — Open the Comparison page that allows you to review changes made to the file. This option is available only for the File Modified event.

  • Add Comments — Opens Add Comments dialog box where you can record additional information for multiple events.

  • Choose Columns — Opens the Select the Columns to Display page. Use this page to select the columns of data to display on the page.

  • Exclude Events — Excludes or ignores events not needed to meet compliance requirements.

  • Export Table — Opens the Export page. Use this page to specify the format and the package of files to be exported. You can save or email the file list.

  • Reconcile Events — Manually reconciles events by correlating the events with change tickets and marking the events as authorized or unauthorized.

  • Show Related Systems — Takes you to a page where you can view and take action on the systems where selected events occurred.