Create relevant rules to process events generated at endpoints. This helps to control the flow of events from endpoints to the ePO - SaaS server by gradually reducing the number of received events.
Create and apply relevant scenario-based rules to process events. If you receive multiple:
Write Denied events — Review the events and define appropriate updater or filter rules. Updater rules are appropriate when the events are for a trusted file. Or, filter (AEF) rules might be relevant if the file is malicious or unknown.
Installation Denied events — Review the events and define appropriate updaters.
Execution Denied events — The file might not be allow listed or is banned. The file is not allowed when it is added to an endpoint through a non-trusted method. If you receive Execution Denied events:
From one host, run an antivirus scan on the system, then resolidify the endpoint.
From multiple hosts for the same file, review the file execution status on the Inventory page to verify if and why the file is banned. If the ban rule for the file is legitimate, add filter (AEF) rules for the file.