You can view a comprehensive report for each Predictive Machine Learning log detection by clicking the View link under the Details column.
The Log Details screen consists of two sections:
-
Top banner: Specific details related to this particular log detection
-
Bottom tab controls: Details related to the Predictive Machine Learning threat, including threat probability scores, file information, and other endpoints across your network that have the same detection
The following table discusses the information provided in the top banner.
Section |
Description |
---|---|
Detection time / Action |
Indicates when this specific log detection occurred and the action that the agent took on the threat |
File name |
Indicates the name of the file that triggered the detection on the specified endpoint Important:
The detected file name for this detection may not be the same as the file name detected on other agents. Predictive Machine Learning associates detections according to file hash values, not specific file names. View the Affected Endpoints tab to verify the file name on other endpoints. |
Endpoint information |
Displays the logged on user at the time of the detection, the endpoint name, and the IP address of the endpoint |
Channel information |
Displays the channel from which the threat originated and the folder location on the endpoint the threat transferred to |
The following table discusses the information provided on the bottom tabs.
Tab |
Description |
---|---|
Threat Indicators |
Provides the results of the Predictive Machine Learning analysis
|
File Details |
Provides general details related the file properties and certificate information for this specific detection log |
Affected Endpoints |
Displays a list of other agents on your network with the same Predictive Machine Learning detection and provides specific details about the detections on the other agents |