In Nebula, an Event is a general term for a threat that has occurred, remediation or other action taken on a threat, and other endpoint-related activity. Similarly, queued or pending endpoint actions are referred to as Tasks. This article provides a brief overview of the Events and Tasks screens and how they are useful for endpoint management.
Events
This screen displays a record of threats, remediation and other activities on endpoints. Use the drop-down lists to filter the entries shown. Event data is stored and displayed for up to 30 days prior across all endpoints.
There are several types of events, varying in severity. The Severity drop-down list has the following event types:
- Severe: A threat has been found.
- Warning: A threat has been cleaned, Suspicious Activity detected, a command has failed, or an item failed to delete from Quarantine.
- Info: A scan has finished, asset information posted, agent information posted, or an item has been deleted from Quarantine.
- Audit: An endpoint has been registered, endpoint deleted, report generated, or an exclusion has happened at the policy level.
Next to an event, click the timestamp to show details. If an event is related to a policy level exclusion, hover over the Policies item to show the policies affected. If the event is a Threat Found, click the View Report link to check out the report for the scan that identified the threat.
Tasks
This screen shows on-demand activities requested on endpoints in the last 90 days. These activities can be asset management scans, malware scans, quarantine restore, or quarantine delete.
The following list shows the possible statuses for a task:
- Pending: The endpoint is waiting to receive the command. Pending tasks can be canceled with the Cancel Pending Tasks button.
- Processing: The action is in progress.
- Success: The action is complete.
- Expired: The endpoint did not receive the command after pending for 3 days.
- Failed: The action has failed. The software may have encountered an issue. Try sending the task again.
- Canceled: The action is aborted.
Use the drop-down menus at the top of the screen to filter by the task status.