How to find events when a file is quarantined in ICDm
book
Article ID: 274361
calendar_today
Updated On:
Products
Endpoint Security
Issue/Introduction
How to find events in Symantec Cloud ICDm portal that show when a file has been quarantined.
Environment
Symantec Endpoint Security Cloud Console (ICDm)
Resolution
- Navigate to the Investigate tab
- Copy and paste the following command:
quick:Malware Protection AND quick:Security AND Event Type Id:8031-File Detection AND Disposition:12
- Select Run Query
Feedback
thumb_up
Yes
thumb_down
No