Processing events

Prev Next

Create relevant rules to process events generated at endpoints. This helps to control the flow of events from endpoints to the ePO - On-prem server by gradually reducing the number of received events.

Create and apply relevant scenario-based rules to process events. If you receive multiple:

  • Registry modified or File modified events — Review and finetune the filter rules for your enterprise. Define rules to exclude specific files or registry entries based on the event type and file name or registry key.

  • Write Denied events — Review the events and define appropriate updater or filter rules. Updater rules are appropriate when the events are for a trusted file. Or, filter (AEF) rules might be relevant if the file is malicious or unknown.

  • Installation Denied events — Review the events and define appropriate updaters.

  • Execution Denied events — The file might not be allow listed or is banned. The file is not allowed when it is added to an endpoint through a non-trusted method. If you receive Execution Denied events:

    • From one host, run an antivirus scan on the system, then resolidify the endpoint.

    • From multiple hosts for the same file, review the file execution status on the Inventory page to verify if and why the file is banned. If the ban rule for the file is legitimate, add filter (AEF) rules for the file.

    Note

    Starting with the version 8.0.0 release, you can use the User Comments field for each event to record additional information for that event.