Event ID 4113 entries in ATP 2.x or 3.x have no value for 'data_source_url'
search cancel

Event ID 4113 entries in ATP 2.x or 3.x have no value for 'data_source_url'

book

Article ID: 172386

calendar_today

Updated On:

Products

Endpoint Detection and Response Advanced Threat Protection Platform

Issue/Introduction

When reviewing the ATP Event search or Incident Event list, you see that some Vantage 4113 Malicious traffic detected events do not have any data for 'data_source_url' or 'data_source_url_domain'.

Cause

The ATP: Network software can find a URI request malicious based on other parts of the request before the full URL is seen. Sometimes this is due to the URL being long enough that it was not included in the same packet.

Resolution

There are different reasons for which a Vantage detection may have a NULL URL. Depending on the technique and protocol used for the detection, the URL may or may not be present.

For example, a detection over SSL3 will not contain the HTTP URL.