cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

Deferred action in Checkpoint

In splunk, some endpoint logs shows the action as deferred where index is checkpoint, what dos it mean? i am new to this security profile.

0 Kudos
4 Replies
Admin
Admin

Re: Deferred action in Checkpoint

A concrete example of such a log would be helpful.

0 Kudos

Re: Deferred action in Checkpoint

Deferred is an action for various tags as part of the Endpoint Datamodel:
Endpoint - Splunk Documentation 

These are defined in Enterprise Security > Settings >Data Models > Endpoint
Usually with an eval.

0 Kudos
Admin
Admin

Re: Deferred action in Checkpoint

I meant a concrete example of an actual log you received that's tagged this way.

That said, if this tag is coming from Splunk, it might make more sense to ask on the Splunk Answers community.

0 Kudos

Re: Deferred action in Checkpoint

Sorry! I meant to reply to original post.
But yes, you're right.. 
This is something for the Splunk Answers Community.