Configure Automatic Responses to react to threat events.
The Threat Event Log is a log file of all threat events that ePO - On-prem receives from managed systems.
In ePO - On-prem, you can define which events are forwarded to the ePO - On-prem server. To display the complete list of events in ePO - On-prem, select Menu → Configuration → Server Settings, select Event Filtering, then click Edit.
Set up a Purge Threat Event Log server task to purge the Threat Event Log periodically.
You can also view and manage Exploit Prevention events in ePO - On-prem in the Exploit Prevention Events page under Reporting.
You can use events to customize Automatic Responses.
For information about Automatic Responses and working with the Threat Event Log, see the ePO - On-prem Help.