After you have analyzed the details of how the campaign has affected the devices in your environment, you can view the event details associated with the affected endpoint devices and resolve an event. You can also resolve multiple events for a device at a time.
Log on to Trellix Insights.
Click
and select Campaigns to view the list of campaigns under the All Campaigns tab. Alternatively, you can search a specific campaign by Campaign name.Click View Details and go to the Your Environment page.
In the Your Environment page, select an endpoint device (or system) under Devices Exposed or All Impacted Devices tabs. The list of events related to the device are displayed on the right-pane.
Select an event to view Event Details, Properties, Detection Details, IOC Details.
Click Process Trace to view details about the processes executed on your endpoints in a graph. If a trace is available for an event, a graph icon is enabled. See Process Trace for more information.
Click Mark this event as resolved. The campaign event details related to the selected event are displayed.
You can view details, enter comments and click Mark as Resolved. A small icon indicating manual resolution appears after an event is marked as resolved.
Select Details → Manual Resolution to view who resolved the event, the timestamp, and additional comments.
You can also resolve multiple events for a device.
Select the device.
On the device details page, under the Events tab, select View → Unresolved. The list of unresolved events are displayed.
Click Mark all as resolved.
Select the events from the list, enter comments and click Mark as Resolved.