How to Identify the Affected Endpoint from a Threat Alert.

Description

This article explains how to determine which endpoint triggered a threat alert by reviewing the endpoint information on the Threat Details page.

Applies To:
SonicWall Endpoint Security (SES)

Cause

An article that provides guidance for identifying the endpoint associated with a threat alert.

Resolution

1. Log in to the SES Console.

2. Navigate to:
Dashboard → Threats

3. Open the detected threat.

4. Review the Endpoint Information section.

5. Verify the following details:
• Hostname
• Username
• IP Address
• OS Details
• Agent Version

Screenshot Attached: Threat Details page highlighting Endpoint Information.

Related Articles

  • Capture Client – Getting CC API token via MSW API key
    Read More
  • Integrating with 3rd Party Syslog and Threat Detection Platforms
    Read More
  • How to Generate a Capture Client (SentinelOne) API Key Using a Service User
    Read More
not finding your answers?