bbahes 29 Posted May 31, 2019 Posted May 31, 2019 HI! We got today a event in THREATS: However, I see action as Detected. If we wanted to change action for this types of threats, which specific policy/rule would we need to modify? Thanks!
Administrators Marcos 5,408 Posted May 31, 2019 Administrators Posted May 31, 2019 This comes from Botnet / Network attack protection module. It was discussed and explained in other topics (e.g. https://forum.eset.com/topic/18343-threat-log-question/?tab=comments#comment-90087) that it's just a matter of wording that will be altered and the action displayed in the ESMC console reads "Detected" even if it means "Detected and blocked". On clients it's logged as "Blocked".
Recommended Posts