Review requests

Prev Next

You can review the requests received from endpoints.

  1. On the ePO - On-prem console, select MenuApplication ControlPolicy Discovery to open the Policy Discovery page.

  2. Review the listed requests using one of these methods.

    • Specific interval — Select an option from the Time Filter list, then click Update Results to view requests received during a specific interval.

    • Request status — Select a value for the request status from the Approval Status list, then click Update Results to view requests that match the selected status.

    • Activity — Click Additional filters and select a value from the Activity list. Click Update Results to view requests for a certain activity.

    • Reputation — Click Additional filters and select a value from the Final Reputation list. Click Update Results to view requests for files that match the selected reputation value. For more information about how the software determines final reputation for files or certificates, click What's Final Reputation.

    • Specific endpoint — Click Additional filters and enter an endpoint name in the System Name field. Click Update Results to view requests received from the endpoint. Make sure that you specify the complete system name because no partial matches are performed.

    • Multiple criteria — Specify values for the Time Filter, Approval Status, Activity, Final Reputation, and System Name fields, as needed, then click Update Results to perform a search based on the specified criteria.

    • Specific search string — Enter a search string in the Quick find field for Object Name, Application Name, Certificates, and User Comments, then click Apply to view requests that match the specified search string. Partial matches are performed based on the text you specify.

    • Sort — Sort the list based on the global prevalence, final reputation, reputation source, execution time, activity, object name, application name, certificate, or user comments by clicking the column heading.

    • Selected requests — Select requests of interest, then click Show selected rows to review only the selected requests.

    Note

    The Policy Discovery page lists only the requests for which the ePO - On-prem administrator can make rules. To view other requests, such as those for installers with trusted reputation, run the Policy Discovery Requests for Automatically-Approved Installations query. The query lists all files with trusted reputation that were executed automatically on the endpoints with installer permission in the last one month.

  3. (Optional) Add user comments for one or multiple events:

    • One event – click Add a comment.

    • Multiple events – select the requests and click ActionsAdd Comments, then enter your comments and click OK.

  4. Review individual requests that make up a collated request and detailed information for the file.

    1. Click a row to open the Request Details page.

    2. Review file details, such as name, version, path, parent process, files changed, final reputation, and user comments, if any.

    3. Review the checksum information for the file.

    4. Click the file SHA-1 value to review file details about the File Details page.

    5. Review the certificate vendor name for the file. The certificate vendor name for a file is color coded to indicate trusted (green), malicious (red), or unknown (orange) reputation.

    6. Click certificate name to view certificate details, such as issuer, certificate reputation, reputation source, public key algorithm, public key length, public key hash, certificate hash, valid from, and valid to.

    7. Review the individual requests that make up the collated request in the Enterprise Level Activity pane.

    8. Click Close.