Reports

Seqrite EDR has a variety of reports that give you a bird’s eye view of the security situation in your network infrastructure, specific to alerts. The information is presented in 2 widgets, you can scroll down to view the reports. Navigate to the Reports tab on the EDR console.

Reports can be exported immediately or scheduled for export.

Alerts Report

The first widget gives information about the number of Alerts and severity over a 7, 15, or 30 day -period on a line chart. The count by severity and total number of devices/endpoints is displayed in upper right corner. Use the Severity filter to display the alerts by severity as required.

Tip: You can navigate directly to the Alerts page with the filter that is applied by clicking the forward facing caret highlighted in yellow as shown below.

Endpoints

The second part has two widgets as follows: One gives information about the count of affected endpoints over a 7-day period.
The second widget gives other information about the top 5 affected endpoints along with the Hostname. A table in the widget displays the count of alerts based on their current status and severity for respective host.

Remediation

In this widget, counts for remediation by Delete or Kill action are displayed date-wise for the past 7 days.
The Total count for devices is displayed in upper right corner. Hover above each graph to view Remediation activity counts for that date.

Active Endpoints

A widget in the 4th part of the reports page displays the count of the active endpoints over the dates for a 7- day period along with the total endpoint count displayed on upper right corner.
Active endpoints are those endpoints that have communicated with Seqrite EDR portal over the past 7 days.

Quarantine Files

Seqrite EDR generates alerts and you can see them all in EDR UI. You may require to Quarantine some of the alerted processes. To Quarantine the alerts, select the desired alert and click the Quarantine button available at the bottom of the right panel opened for the selected alert.

The quarantined files can be seen in the under the Reports section. Once you quarantine the file, it gets deposited to the Quarantined folder on sensors installed system.
To view the list of Quarantine files, click the Quarantined Files under Reports.

Here you can see the Quarantined files with the following details-

  • File Name
  • Hash
  • Original File path
  • Endpoint
  • Alert ID
  • Restore

You can sort the list based on the time by choosing the Time sorter available at the right side of the grid.

To add filters to the Quarantined files’ list, click the Add button available near the filter search bar and you can choose the filters to see the desired files.

Restore quarantined files

To restore a quarantined file:

  1. Go to Reports > Quarantined Files.
  2. Locate the required file.
  3. Click the Restore icon.
  4. Click the Restore button on the confirmation pop-up window.
  5. The status appears as Restoring.

Note: To export the Quarantined file details, click ‘Export’ button.

Isolated Devices

The Isolated Devices page displays all endpoints that are currently isolated from the network. It provides a centralized view of isolated endpoints and allows authorized administrators to review their status, update isolation settings, and reconnect one or more endpoints when required.

View Isolated Devices

The Isolated Devices page displays the following information for each isolated endpoint:

  • Device Name
  • OS
  • Group
  • IP Address
  • Status
  • Isolation Time
  • Reconnect
  • Search and Filter Endpoints

Use the search box to locate endpoints by:

  • Device Name
  • Group
  • IP address
  • OS

Reconnect an Isolated Endpoint

To reconnect an isolated endpoint:

  1. Go to Reports > Isolated Devices.
  2. Locate the required endpoint.
  3. Click the Reconnect icon in the Actions column.
  4. Click the Reconnect button on the confirmation pop-up window.
  5. The status appears as Reconnecting.

The endpoint is reconnected to the network after the request is processed successfully, and the endpoint status is updated automatically.

Note: If the endpoint has active critical detections, the system displays a warning before reconnecting the endpoint.

Isolation Status

The following isolation statuses are displayed for each endpoint:

Status Description
Reconnected The endpoint is now reconnected
Isolated The endpoint is currently isolated from the network
Reconnecting The reconnect request is in progress

The endpoint status is refreshed automatically.

Was this page helpful?