Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Dinesh_Buddha
Explorer

Deferred action in Checkpoint

In splunk, some endpoint logs shows the action as deferred where index is checkpoint, what dos it mean? i am new to this security profile.

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

A concrete example of such a log would be helpful.

0 Kudos
Richard_Phung
Explorer

Deferred is an action for various tags as part of the Endpoint Datamodel:
Endpoint - Splunk Documentation 

These are defined in Enterprise Security > Settings >Data Models > Endpoint
Usually with an eval.

0 Kudos
PhoneBoy
Admin
Admin

I meant a concrete example of an actual log you received that's tagged this way.

That said, if this tag is coming from Splunk, it might make more sense to ask on the Splunk Answers community.

0 Kudos
Richard_Phung
Explorer

Sorry! I meant to reply to original post.
But yes, you're right.. 
This is something for the Splunk Answers Community.