View the details of an event in the Threat Event Log.
Option | Definition |
|---|---|
Event Received Time | Time the ePO - On-prem server received notification of the event using the default time zone. |
Event Generated Time | Time of the event using the default time zone. |
Preferred Event Time | Time of the event using the preferred local time zone. |
Agent GUID | Unique identifier of the agent that forwarded the event. |
Detecting Prod ID (deprecated) | ID of the detecting product. |
Detecting Product Name | Name of the detecting managed product. |
Detecting Product Version | Version number of the detecting product. |
Detecting Product Host Name | Name of the system hosting the detecting product. |
Detecting Product IPv4 Address | IPv4 address of the system hosting the detecting product (if given in the event). |
Detecting Product IP Address | IP address of the system hosting the detecting product (if given in the event). |
Detecting Product MAC Address | MAC address of the system hosting the detecting product. |
DAT Version | DAT version on the system that sent the event. |
Engine Version | Version number of the detecting product’s engine (if given in the event). |
Threat Source Host Name | System name from which the threat originated (if given in the event). |
Threat Source IPv4 Address | IPv4 address of the system from which the threat originated (if given in the event). |
Threat Source IP | IP address of the system from which the threat originated (if given in the event). |
Threat Source MAC Address | MAC address of the system from which the threat originated (if given in the event). |
Threat Source User Name | User name from which the threat originated (if given in the event). |
Threat Source Process Name | The process name from which the threat originated. |
Threat Source URL | URL from which the threat originated (if given in the event). |
Threat Target Host Name | Name of the system that created the event. |
Threat Target IPv4 Address | IPv4 address of the system that sent the event. |
Threat Target IP Address | IP address of the system that sent the event. |
Threat Target MAC Address | MAC address of the system that sent the event. |
Threat Target User Name | The threat source user name or email address. |
Threat Target Port Number | The threat target port for threat classes. |
Threat Target Network Protocol | The threat target protocol for threat classes. |
Threat Target Process Name | The target process name (if given in the event). |
Threat Target File Path | Location of the threat on the detecting system. |
Event Category | Category of the event. Possible categories depend on the product. |
Event ID | Unique identifier of the event class. |
Threat Severity | The severity of the detected threat as defined by each managed product. |
Threat Name | Name of the threat. |
Threat Type | Class of the threat. |
Action Taken | The action taken by the product in response to the threat. |
Threat Handled | Specifies whether the action taken was successful. |
Analyzer Detection Method | The name of the task or task type that was responsible for detecting the threat. |
Actions menu | Specifies the actions that can be taken on this event, including:
|