Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Explorer

Deferred action in Checkpoint

In splunk, some endpoint logs shows the action as deferred where index is checkpoint, what dos it mean? i am new to this security profile.

0 Kudos
Reply
4 Replies
Admin
Admin

A concrete example of such a log would be helpful.

0 Kudos
Reply
Explorer

Deferred is an action for various tags as part of the Endpoint Datamodel:
Endpoint - Splunk Documentation 

These are defined in Enterprise Security > Settings >Data Models > Endpoint
Usually with an eval.

0 Kudos
Reply
Admin
Admin

I meant a concrete example of an actual log you received that's tagged this way.

That said, if this tag is coming from Splunk, it might make more sense to ask on the Splunk Answers community.

0 Kudos
Reply
Explorer

Sorry! I meant to reply to original post.
But yes, you're right.. 
This is something for the Splunk Answers Community.