Aggregated Events
These events are grouped into categories, providing a count and path. Click the path to find the Computer Events view.
•File modifications
•File reads
•Registry modifications
•Network connections
•URL connections
•Dropped Executables
•DNS resolutions
Character limitations are set at 260 to limit database growth. |
The process tree on the right side
The process tree reflects the parent-child relationship between processes where child processes are shown directly beneath their parent and right-indented. Processes on the left are orphans, and their parent has exited.
Show Sub-Process Events—Click to see the child process events.
Argument—Search by event argument; depending on the event type you can find a patch, filename, directory name or IP address.
If there are too many results, only a subset is loaded. Click Load more or Load all to display more events; loading all results may take considerable time.