Previous Topic: Type 1: Local Event

Next Topic: Type 3: Observed Event

Type 2: Remote Event

The second type of event is the remote event. This type of event involves two entities where one of the entities is either the source or destination of the action expressed in the event. This means that the agent and event source are the same entity as either the source or destination of the action expressed in the event.

An example of this type of event is a logon event expressing a connection to a network share from a workstation. The agent is installed on the server hosting the network share.

Source

Destination

Event Source

Agent

Host A

Host B

Host A

Host A

Host A

Host B

Host B

Host B