All generated events for managed systems are sent to the ePO - SaaS server. You can review and manage the generated events to monitor the status of the managed endpoints.
On the ePO - SaaS console, select Menu → Reporting → Solidcore Events.
Specify the time duration for which to view events by selecting an option from the Time Filter list.
Choose the endpoints where you want to view events.
Select the required group in the System Tree.
Select an option from the System Tree Filter list.
View only specific events by applying one or more filters.
Click Advanced Filters to open the Edit Filter Criteria page.
Select a listed property.
Specify the comparison operator and property value.
For example, to view only Execution Denied events, select the Event Display Name property, set comparison to Equals, and select the Execution Denied value.
Click Update Filter.
Events matching the specified criteria are displayed.
Add user comments for one event or multiple events.
One event — Click Add a comment link.
Multiple events — Select the events, click Actions → Add Comments, then enter your comments and click OK.
Exclude or ignore events not required to meet compliance requirements.
On the Solidcore Events page, select the events to exclude and click Actions → Exclude Events to open the Events Exclusion wizard.
Select the target platform for the rules and the rule group type, then click Next to open the Define Rules page.
Click Next to open the Select Rule Group page, add the rule to an existing or new rule group, then click Save.
Define rules to allow the execution of a legitimate application.
On the Solidcore Events page, under Actions, click Create Policy for an event.
On the Monitoring Events Details page, click Create Custom Policy and define the rules.
Select Choose existing to add the rules to an existing rule group or select Create new to create a new rule group.
To add the rule group to a policy, select Add rule group to existing policy.
Click Save.