Event Details

The Events Details page list all the information about the events. To view the Events Details page, click Quick Actions > Event Details.

Events Detail Page

From the Events Details page, you can perform the remediation actions (Quarantine File/ Delete File/ Kill Process) on File, Mutex, Network, and Process events. For more information on remediation action, see Remediation.

Events Detail Page

View event tree

On the Event Details page, we display event tree for File, Process, Mutex, Registry, and Network events. On the event tree, we display all the events that are related to the selected event.

An event of “Process” type will show its parent and child processes along with the mutex and network connection of the process. For the event of Network type, you see network connection of a process and for the event of Mutex type, mutex connection of a process.

In the event tree view, the selected event node is highlighted with the orange border. You can traverse between the nodes by clicking a node in the hierarchy. You can click on the (+) and (-) to expand and collapse the tree nodes and display the related events.

You can click on the event node to view the details of the selected node. These detail are also displayed on the Event Details Page of that particular event.

To help you identify event types of nodes in a hierarchy view, similar events are grouped under a event type (example: Mutex or Network) and respective event icons are added against the node.

Event's tree view displays a zoom bar to zoom in and out the event's tree. Zoom bar has a plus and minus button for this purpose. It has a re-center button to restore the tree to the center of the screen with its original size.

Events Detail Page