Viewing quarantined files

Prev Next

You can use the Endpoint Security (HX) Web UI or the API to view quarantined files. You cannot use the CLI to view them.

To view quarantined files using the Alerts page in the Web UI:
  1. Select Alerts at the top of the Endpoint Security (HX) Web UI page.

  2. Select a malware alert for which you want to see quarantined files. The alert details page opens.

    Tip

    You can filter results on the Alerts page to see only the alerts that have quarantined files.

    Alerts_FilterQuar.png
  3. Select the Quarantines tab. The quarantined files are listed.

To view quarantined files using the Hosts page in the Web UI:
  1. Select Hosts at the top of the Endpoint Security (HX) Web UI page.

  2. Verify that the Hosts with Alerts tab is selected.

  3. In the grid, click the expand icon (ExpandIcon.png) next to the host for which you want alert detail information.

    The host alert details page appears. Detailed information about the alerts is shown on the Alerts tab on this page. Information about quarantined files is shown on the Quarantines tab on this page.

  4. Select the Quarantines tabQuarantines tab. The quarantined files are listed.

    Hosts_DetailQuar.png

    Note

    The list of quarantined files does not show malware found in boot sectors. (ENDPT-9014/ENDPT-8088)