Procedure
- Go to one of the following:
-
- In the agent tree, click the root domain icon () to include all agents or select specific domains or agents.
- Go to the C&C Callback Log Criteria
screen:
-
From the Security Risk Logs screen, click.
-
From the Agent Management screen, click.
-
- Specify the log criteria and then click Display Logs.
- View logs. Logs contain the following information:ItemDescriptionDate/TimeThe time the detection occurredUserThe user logged on at the time of the detectionCompromised HostThe endpoint from which the callback originatedIP AddressThe IP address of the compromised hostDomainThe domain of the endpoint on which the detection occurredCallback AddressThe address to which the endpoint sent the callbackC&C List SourceThe C&C list source that identified the C&C serverC&C Risk LevelThe risk level of the C&C serverProtocolThe Internet Protocol used for the transmissionProcessThe process that initiated the transmission (path\application_name)ActionThe action taken on the detection
- If Web Reputation blocked a URL that you do not want blocked,
click the Add to Web Reputation Approved List button to
add the address to the Web Reputation Approved List.
Note
Apex One can only add URLs to the Web Reputation Approved List. For detections made by the Global C&C IP List or the Virtual Analyzer (IP) C&C List, manually add these IP addresses to the User-defined Approved C&C IP List.For details, see Configuring Global User-defined IP List Settings. - To save logs to a comma-separated value (
CSV
) file, click Export All to CSV. Open the file or save it to a specific location.