Threat event counts differ depending on the time unit used in a single-line chart query
Last Modified: 2023-08-02 06:53:29 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Threat event counts differ depending on the time unit used in a single-line chart query
Technical Articles ID:
KB92385
Last Modified: 2023-08-02 06:53:29 Etc/GMT Environment
ePolicy Orchestrator (ePO) 5.x
Problem
When you modify the default Endpoint Security:Threats detected in the last 7 days report, the total value is different for the hour and day time units. For example: For a two-week period, the total shows 4,844 detections when Day is used as a time unit. If you change it to Hour, the total drops to 1,300. The actual data points in the graph are only from the shorter date range and not from the whole two-week period. The chart type selected is Single-Line Chart. Cause
Both Day and Hour impose a limit on groups of 50. This limit is configured in the Endpoint Security extension.
SolutionThis issue is resolved in ePolicy Orchestrator 5.10.0 Update 7, which is available from the Product Downloads site.
NOTE: You need a valid Grant Number to access the update. To view other known and resolved issues, see KB90382 - ePolicy Orchestrator 5.10.x Known Issues. WorkaroundWe investigated this issue and a Proof of Concept (POC) Build is currently available to resolve the issue. To obtain the POC Build, log on to the ServicePortal and create a Service Request. Include this article number in the Problem Description field.
Affected ProductsLanguages:This article is available in the following languages: |
|