The following table describes token variables for customizing Known Threat Activity or Outbreak Prevention Service event notification messages.
For the list of standard token variables supported by all event notifications, see Standard Token Variables.
Variable |
Description |
---|---|
%device_ip% |
IP address of an infected endpoint |
%egnver% |
|
%hierarchy% |
|
%ptnver% |
|
%scanmethod% |
The scan method for specific virus actions. This token is only available for the following alerts:
|
%threat_info% |
|
%vcnt% |
|
%vdest% |
|
%vfile% |
Infected file name. Used by the alert event category. |
%vfilepath% |
Infected file directory. Used by the alert event category. |
%vname% |
Virus or malware name. Used by the alert event category. |
%vsrc% |
|