Solidcore Events page

Prev Next

View all Solidcore events generated for the managed endpoints.

Option definitions

Option

Definition

Filter

Filters the displayed events based on specified criteria, including:

  • Time Filter — Filters events generated in the specified time period.

  • System Tree Filter — Filters events generated for the specified group or subgroup.

  • Advanced Filters — Opens the Edit Filter Criteria page where you can select properties to filter the content displayed on the Solidcore Events page.

What's reputation-based execution?

Opens a Trellix KnowledgeBase article that explains reputation-based execution.

Deny Reason

Displays the reason for denial for Execution Denied events.

Value

Description

Application Control Policy - File banned by name

Application Control blocked this file because a ban rule exists for the file.

Application Control Policy - File banned by SHA-1

Application Control blocked this file because a ban rule exists for the SHA-1 of the file.

Application Control Policy - File execution denied by user

Application Control blocked this file because its execution was denied by the user.

TIE - Malicious process SHA-1

Application Control blocked this file because the file reputation received from the TIE server is malicious or because Trellix Sandboxing technology (ATD) analyzed it to be suspicious.

GTI - Malicious process SHA-1

Application Control blocked this file because the file reputation received from the GTI server is malicious.

TIE - Malicious Certificate

Application Control blocked this file because the reputation received for the associated certificate from the TIE server is malicious.

GTI - Malicious Certificate

Application Control blocked this file because the reputation received for the associated certificate from the GTI server is malicious.

Local Allow list- File not present in allow list

Application Control blocked this file because it is not allow listed. To execute this file, add the file to the allow list.

Application Control Policy - Network path not trusted

Application Control blocked this file because it was executed from a non-trusted network path.

Application Control Policy - Removable media not trusted

Application Control blocked this file because it was executed from a non-trusted media.

Local Allow list- File SHA-1 mismatch

Application Control blocked this file because the file's checksum in not present in the inventory. This can occur if the file SHA-1 changed.

Reputation (at Time of Execution)

Displays the reputation of the file on the endpoint at the time of execution. This value is applicable only for the Execution Denied events where execution is denied due to malicious reputation. Possible values include TIE Malicious Certificate, GTI Malicious Certificate, TIE Malicious Checksum, GTI Malicious Checksum, and Not Applicable.

Actions

Specifies the actions that you can perform on the selected events, including:

  • Create Policy — Opens the Events: Create Custom Policy page where you can define rules for the file associated with the event. If file SHA-1 is available, corresponding rule is prepopulated on the Events: Create Custom Policy page. Else, you need to manually define relevant rules.

    This option is available only for the Execution Denied, ActiveX Installation Prevented, File Write Denied, Installation Denied, Process Hijack Attempted, VASR Violation Detected, and Nx Violation Detected events.

  • View Related Requests — Opens the Policy Discovery Details page that displays detailed information for the request associated with the event.

  • View File Details — Opens the File Details page that displays detailed information for the file associated with the event.

  • Change File Reputation (TIE) — Opens the TIE Reputations page that displays reputation information for the file associated with the request. If needed, you can edit the file reputation.

  • View Content Change — Open the Comparison page that allows you to review changes made to the file. This option is available only for the File Modified event.

  • Show Suggestions (Deprecated) — Opens the Observations Detail (Deprecated) page that displays details for the observations associated with the event. This option is useful only for endpoints running version 6.1.1 or earlier.

  • Add Comments — Opens the Add Comments dialog box where you can record additional information for multiple events.

  • Choose Columns — Opens the Select the Columns to Display page where you can select the columns of data to display on the Solidcore Events page.

  • Dismiss Observations (Deprecated) — Ignores one or more observations. This option is useful only for endpoints running version 6.1.1 or earlier.

  • Exclude Events — Excludes or ignores events not needed to meet compliance requirements.

  • Export Table — Opens the Export page where you can specify the format and the package of files to be exported. You can save or email event details.

  • Reconcile Events — Manually reconciles events by correlating the events with change tickets and marking them as authorized or unauthorized.

  • Show Related Systems — Takes you to a page where you can view and take action on the systems where selected events occurred.

User Comments

Displays the Add a comment link where you can record additional information for an event.

Select all in this page

Selects all Solidcore events listed on the current page.

Select all in all pages

Selects all Solidcore events displayed on all pages.