Tagging rows of Audit Viewer data

Prev Next

You can tag a row of data in the Audit Viewer grid.

To tag a row of Audit Viewer data:
  1. Review an acquisition in the Audit Viewer. See Viewing the acquisition data .

  2. Make sure the data to which you want to add a tag is visible in the grid. See Selecting data to review .

  3. Select a row in the Audit Viewer grid.

  4. Click the open detail pane button (AVDetails.png) in the upper right corner of the Audit Viewer page.

  5. Locate the Tag and Comment section at the bottom of the Details tab in the detail pane.

    AVTagComment.png
  6. Click the tag you want for the row. Only one tag can be selected per row. The following tags are available:

    Tag Name

    Use

    APT

    Use this to tag a row as indicative of an advanced persistent threat (APT).

    Commodity

    Use this to tag a row as commodity malware. Commodity malware is typically normal malware, not exploits or APTs.

    Escalate

    Use this to tag a row as an escalation.

    False Positive

    Use this to tag a row as a false positive.

    Follow Up

    Use this to tag a row as something you need to follow up on.

    For Report

    Use this to tag a row for a report.

    Suspicious

    Use this to tag a row as suspicious.