Skip Navigation

Manage threat events

You can manage threats found on devices in your organization on the Threat Events page.
  1. In the console, on the menu bar, click
    Events > Threat Events
    . Optionally, you can also click the Threat Events widget on the Dashboard.
  2. Do any of the following:
    Task
    Steps
    View removed threats.
    Click
    <number> Removed Threats
    above the right side of the list to view the total number of threat events automatically removed by the agent. If your policy has
    Auto Delete Quarantine
    enabled for a specified number of days in Threat Settings, files automatically quarantined by the Agent will be deleted after a specified number of days and will be removed from the Threat Events page. This button allows you to view all removed threats that were automatically deleted by the Agent since the beginning of time.
    Add a threat to the Global Quarantine list.
    1. Select one or more events from the list.
    2. Click
      Globally Quarantine
      . These events are automatically quarantined on all devices in your organization. The event status is also set to
      Acknowledged
      .
    Add a threat to the Global Safelist.
    1. Select one or more events from the list.
    2. Click
      Globally Safelist
      . These events are allowed on all devices in your organization. The event status is also set to
      Acknowledged
      .
    Acknowledge a threat.
    1. Select one or more events from the list.
    2. Click Acknowledge. This changes the event status from
      No
      to
      Acknowledged
      . This means that a user has manually acknowledged an event and lowers the threat in the list, allowing you to focus on events that require more attention. By default, the events list displays events that have not been acknowledged first.
To filter entries in this list to find information faster, click .
To export the entries in this list to be used in other applications, click .