When Exploit Prevention detects security violations, as defined by signatures or rules, it triggers events and sends them to the ePO - On-prem server.
Exploit Prevention Events page
ePO - On-prem displays buffer overflow and illegal API use events in the Exploit Prevention Events page under Reporting.
Review the list of events to determine which events are allowable and which indicate suspicious behavior. Under certain circumstances, behavior that is interpreted as an attack can be a normal part of a user’s work routine. When this occurs, you can create an exclusion for that behavior. Creating exclusions allows you to reduce false positive alerts, and helps ensure that the notifications you receive are meaningful.
In the Exploit Prevention Events page, you can:
Use filters to reduce the list to only those events that satisfy the filter criteria.
Aggregate events to generate a list of events grouped by the value associated with selected criteria.
Create exclusions from events.
Threat Event Log page
All Exploit Prevention events, including Network IPS events, appear in the Threat Event Log under Reporting with the events for all products managed by ePO - On-prem.