Counting malware events provides an overall view of attacks and threats being detected and stopped. With this information, you can gauge the health of your network over time and change it as needed.
Creating a query that counts total infected systems cleaned per week is the first step in creating a benchmark to test your network malware status. This query counts each system as a malware event occurs. It counts the system only once even if it generated thousands of events.
Once this query is created, you can:
Add it as a dashboard to quickly monitor your network malware attacks.
Create a report to provide history of your network status.
Create an Automatic Response to notify you if a threshold of systems is affected by malware.