Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Filip_Wennerhul
Participant

Threat emulation log Detect

Hi we have seen an issue with a file being allowed through threat emulation as detect instead of prevent at a customer. We have looked over the SKs but cant seem to find one that is applicable except maybe a timeout issue to ted daemon we found in an SK. 

 

We have background mode in Anti virus/anti-bot under Manage settings/threat prevention settings but at the profile for threat emulation we have hold. Can this mismatch cause an issue? We thought Threat emulation would always hold but can it be affected by having background on antivirus?

 

Here is the logs of TE on the GW and TEAppliance aswell as antivirus. Anti virus is set to background so it gets detect correctly. But emulation is hold, it also just says detect without a reason.

 

TECONF.PNGAVdetect.PNGTedetectGW.PNGTEdetect.PNG

We found something regarding a timeout value for ted in an sk and it might be the case, the logs had been rotated out when we saw the issue so cant inspect further. We are wondering if this mismatch can cause this issue or if it must be the timeout issue to ted daemon or if it can be something else.

 

 

0 Kudos
3 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events