cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Sachin3
Level 7
Report Inappropriate Content
Message 1 of 7

Epo ENS ODS Reports

Jump to solution

I have created the query report for on demand scan, which when generated shows the Action taken 'Delete' and 'Deleted'.

I would like to understand basic difference between this.

Does 'Delete' means, we have to take action manually ?

And 'Deleted' means, action has been taken automatically?

 

Will Appretiate your reply !!

2 Solutions

Accepted Solutions
jess_arman
Employee
Employee
Report Inappropriate Content
Message 5 of 7

Re: Epo ENS ODS Reports

Jump to solution

@Sachin3 I believe that the difference simply comes down to the fact that VSE and ENS were created by different software engineers, and the coded response for VSE and ENS is different based on what was typed as the output field. 
ENS, by using "Delete" instead of "deleted" follows the OS form of the action, i.e. Read, Write, Delete, Execute. It's never referred to a past tense action, despite those actions having the potential to have been in the past.

In short, in terms of the reaction the software is taking, the meaning between "deleted" and "delete" is the same--It was able to take an action to remove the threat at the target file path.

 

Was my reply helpful?

If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?

View solution in original post

jess_arman
Employee
Employee
Report Inappropriate Content
Message 7 of 7

Re: Epo ENS ODS Reports

Jump to solution

@Sachin3 It is possible as well that the input for the output from the code perspective could have differed based on what the detection source/type is. I would need the full threat event information to confirm how they differ to give you a more detailed hypothesis. 

Either way, you can be assured that both forms mean the files were actioned.

 

Was my reply helpful?

If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?

View solution in original post

6 Replies
Former Member
Not applicable
Report Inappropriate Content
Message 2 of 7

Re: Epo ENS ODS Reports

Jump to solution

Hi @Sachin3

It's the same action. However in my ePO I see "deleted" for events created by VSE, all events created by ENS are "delete". Do you see a difference within events created by ENS?

Sachin3
Level 7
Report Inappropriate Content
Message 3 of 7

Re: Epo ENS ODS Reports

Jump to solution

Hi @ chealey Thanks for the reply !!

This what i'm getting in the report.

Please find an pic shared.

Capture_ens.PNG

 

Former Member
Not applicable
Report Inappropriate Content
Message 4 of 7

Re: Epo ENS ODS Reports

Jump to solution

Certainly interesting... The product guide states the folllowing actions:

Access Denied - Allowed - Blocked - Cleaned - Contained - Continue Scanning - Deleted - Moved - Would Block - Would Clean - Would Contain

Maybe it's a typo? I'll see what I can find out internally! To answer you're question though, I'm fairly confident in saying they are the same action though.

jess_arman
Employee
Employee
Report Inappropriate Content
Message 5 of 7

Re: Epo ENS ODS Reports

Jump to solution

@Sachin3 I believe that the difference simply comes down to the fact that VSE and ENS were created by different software engineers, and the coded response for VSE and ENS is different based on what was typed as the output field. 
ENS, by using "Delete" instead of "deleted" follows the OS form of the action, i.e. Read, Write, Delete, Execute. It's never referred to a past tense action, despite those actions having the potential to have been in the past.

In short, in terms of the reaction the software is taking, the meaning between "deleted" and "delete" is the same--It was able to take an action to remove the threat at the target file path.

 

Was my reply helpful?

If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?

Sachin3
Level 7
Report Inappropriate Content
Message 6 of 7

Re: Epo ENS ODS Reports

Jump to solution

Hi @jess_arman

Thanks for the reply

I am understood the fact that coded response for VSE and ENS are different. also the meaning between "deleted" and "delete" is the same.

But i would like to mention one thing, we have only ENS in our environment and not VSE.

 still the reports are showing 'Deleted' action. How to justify this thing !!

Capture_ens.PNG

jess_arman
Employee
Employee
Report Inappropriate Content
Message 7 of 7

Re: Epo ENS ODS Reports

Jump to solution

@Sachin3 It is possible as well that the input for the output from the code perspective could have differed based on what the detection source/type is. I would need the full threat event information to confirm how they differ to give you a more detailed hypothesis. 

Either way, you can be assured that both forms mean the files were actioned.

 

Was my reply helpful?

If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community