View Security Events by Device
- Click 'Security' > 'Security Events' > 'Device View.'
Device view shows all events that occurred on a particular device.
- Multiple
security modules can create events on a device at different times.
All these events are grouped together and shown as a single row:
- Click
'+' to view events on the device
Security Dashboards - Device View - Column Descriptions |
|
---|---|
Column Header |
Description |
Date/Time |
The time at which the event occurred. |
OS |
The operating system of the device. |
Device Name |
The device label. Click a link to view its device details. |
Components |
The security module that reported the event. This can be 'Antivirus', 'Containment', 'Application Control' or 'Autoruns Control'. |
Action |
The response to the event. This shows how the
file was handled by the XCS component mentioned above. List of possible actions: Antivirus – Windows, Mac OS, and Linux devices
Application Control - Windows devices
Autoruns Control - Windows devices
|
Last Action |
Indicates what was done last on the device related to a security component, for example, file added, file deleted and so on. See above row for list of actions. |
Number of Files |
Shows how many file events were logged for the device. Click the number to view a list of the events. |
Additional Info |
Provides the current status of the event or the action taken on the affected file. |
Controls |
|
Device Details |
View general information about the device.
|
Sort, Search and Filter Options
- Click the 'Date/Time' column header to sort events in ascending or descending order
- Enter the device name in the search box to filter events involving the device
- Click the funnel icon at top-right to view more filters:
- Use the search fields to filter events by device, date/time, action and other criteria
- By default, 'Security' > 'Security Events' > 'Device View' does not show files which are ignored by auto-containment rules
- Select 'Show containment ignored events' to include these files
- To display all items again, clear any search filters and click 'OK'