Skip Navigation

View and manage detections

You can use the management console to view and analyze the events detected by the CAE. From the detections dashboard you can see trends in events over varying timeframes, the severity of different detections, and you can access detailed information for each detection.
  1. In the management console, on the menu bar, click
    CylanceOPTICS > Detections
    .
  2. Do any of the following:
    Task
    Steps
    Change the scope of the detections data.
    Click the
    Detections Over Time
    drop-down list and select the desired scope.
    Include or exclude detections of different priority levels.
    The graph provides a count of informational, low, medium, and high priority events. Click any of the counts to exclude those events from the detections data. Click the same item again to include it in the data.
    View the details and artifacts of interest for a detection.
    Click
    View
    .
    Depending on the artifacts associated with the detection, you may be able to select different actions (for example, you can download a file, quarantine a file, view focus data, create a detection exception, and so on). You can click the
    Detection Notes
    section to add notes relevant to your analysis.
    Lock down the device associated with a detection.
    1. Click
      View
      .
    2. In the
      Actions
      drop-down list, click
      Lockdown Device
      .
    3. Select a lockdown period.
    4. Click
      Confirm Lockdown
      .
    For more information, see Lock a device.
    Export detection details to a JSON file.
    1. Click
      View
      .
    2. In the
      Actions
      drop-down list, click
      Export Data
      .
    Set the status of a detection event.
    Do any of the following:
    • Click the
      Status
      drop-down list for a detection and select the appropriate status.
      If you select
      False Positive
      , you are prompted for how you want to handle duplicate detections. Select the appropriate option and click
      Save
      .
    • Select one or more detections and click
      Select Action > Change Status
      . Select the appropriate status and click
      Confirm
      .
    Delete one or more detections.
    Select the detections and click
    Select Action > Delete Detection
    . Click
    Confirm Delete
    .