Threat Event Log Details page

Prev Next

View the details of an event in the Threat Event Log.

Option definitions

Option

Definition

Event Received Time

Time the ePO - On-prem server received notification of the event using the default time zone.

Event Generated Time

Time of the event using the default time zone.

Preferred Event Time

Time of the event using the preferred local time zone.

Agent GUID

Unique identifier of the agent that forwarded the event.

Detecting Prod ID (deprecated)

ID of the detecting product.

Detecting Product Name

Name of the detecting managed product.

Detecting Product Version

Version number of the detecting product.

Detecting Product Host Name

Name of the system hosting the detecting product.

Detecting Product IPv4 Address

IPv4 address of the system hosting the detecting product (if given in the event).

Detecting Product IP Address

IP address of the system hosting the detecting product (if given in the event).

Detecting Product MAC Address

MAC address of the system hosting the detecting product.

DAT Version

DAT version on the system that sent the event.

Engine Version

Version number of the detecting product’s engine (if given in the event).

Threat Source Host Name

System name from which the threat originated (if given in the event).

Threat Source IPv4 Address

IPv4 address of the system from which the threat originated (if given in the event).

Threat Source IP

IP address of the system from which the threat originated (if given in the event).

Threat Source MAC Address

MAC address of the system from which the threat originated (if given in the event).

Threat Source User Name

User name from which the threat originated (if given in the event).

Threat Source Process Name

The process name from which the threat originated.

Threat Source URL

URL from which the threat originated (if given in the event).

Threat Target Host Name

Name of the system that created the event.

Threat Target IPv4 Address

IPv4 address of the system that sent the event.

Threat Target IP Address

IP address of the system that sent the event.

Threat Target MAC Address

MAC address of the system that sent the event.

Threat Target User Name

The threat source user name or email address.

Threat Target Port Number

The threat target port for threat classes.

Threat Target Network Protocol

The threat target protocol for threat classes.

Threat Target Process Name

The target process name (if given in the event).

Threat Target File Path

Location of the threat on the detecting system.

Event Category

Category of the event. Possible categories depend on the product.

Event ID

Unique identifier of the event class.

Threat Severity

The severity of the detected threat as defined by each managed product.

Threat Name

Name of the threat.

Threat Type

Class of the threat.

Action Taken

The action taken by the product in response to the threat.

Threat Handled

Specifies whether the action taken was successful.

Analyzer Detection Method

The name of the task or task type that was responsible for detecting the threat.

Actions menu

Specifies the actions that can be taken on this event, including:

  • Show Related Systems — View and take action on the systems where selected events occurred.

  • Show Source Systems — View systems that were the source of the selected event.

  • Show Targeted Subsystem — View systems targeted for the selected event.