I have created the query report for on demand scan, which when generated shows the Action taken 'Delete' and 'Deleted'.
I would like to understand basic difference between this.
Does 'Delete' means, we have to take action manually ?
And 'Deleted' means, action has been taken automatically?
Will Appretiate your reply !!
Solved! Go to Solution.
@Sachin3 I believe that the difference simply comes down to the fact that VSE and ENS were created by different software engineers, and the coded response for VSE and ENS is different based on what was typed as the output field.
ENS, by using "Delete" instead of "deleted" follows the OS form of the action, i.e. Read, Write, Delete, Execute. It's never referred to a past tense action, despite those actions having the potential to have been in the past.
In short, in terms of the reaction the software is taking, the meaning between "deleted" and "delete" is the same--It was able to take an action to remove the threat at the target file path.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
@Sachin3 It is possible as well that the input for the output from the code perspective could have differed based on what the detection source/type is. I would need the full threat event information to confirm how they differ to give you a more detailed hypothesis.
Either way, you can be assured that both forms mean the files were actioned.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Hi @Sachin3
It's the same action. However in my ePO I see "deleted" for events created by VSE, all events created by ENS are "delete". Do you see a difference within events created by ENS?
Hi @ chealey Thanks for the reply !!
This what i'm getting in the report.
Please find an pic shared.
Certainly interesting... The product guide states the folllowing actions:
Access Denied - Allowed - Blocked - Cleaned - Contained - Continue Scanning - Deleted - Moved - Would Block - Would Clean - Would Contain
Maybe it's a typo? I'll see what I can find out internally! To answer you're question though, I'm fairly confident in saying they are the same action though.
@Sachin3 I believe that the difference simply comes down to the fact that VSE and ENS were created by different software engineers, and the coded response for VSE and ENS is different based on what was typed as the output field.
ENS, by using "Delete" instead of "deleted" follows the OS form of the action, i.e. Read, Write, Delete, Execute. It's never referred to a past tense action, despite those actions having the potential to have been in the past.
In short, in terms of the reaction the software is taking, the meaning between "deleted" and "delete" is the same--It was able to take an action to remove the threat at the target file path.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Hi @jess_arman
Thanks for the reply
I am understood the fact that coded response for VSE and ENS are different. also the meaning between "deleted" and "delete" is the same.
But i would like to mention one thing, we have only ENS in our environment and not VSE.
still the reports are showing 'Deleted' action. How to justify this thing !!
@Sachin3 It is possible as well that the input for the output from the code perspective could have differed based on what the detection source/type is. I would need the full threat event information to confirm how they differ to give you a more detailed hypothesis.
Either way, you can be assured that both forms mean the files were actioned.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: