Previous Topic: Antivirus Status ActionNext Topic: File Exclude Action


File Block Action

The File Block action occurs when detecting a file blocked by an antivirus product on a given host.

Information

Level

Source - User Information

Tertiary

Source - Host Information

Secondary

Source - Object Information

Tertiary

Source - Process Information

Secondary

Source - Group Information

Tertiary

Dest - User Information

Tertiary

Dest - Host Information

Primary

Dest - Object Information

Primary

Dest - Process Information

Tertiary

Dest - Group Information

Tertiary

Agent - Information

Primary

Agent - Host Information

Primary

Event Source - Host Information

Primary

Event Source - Information

Tertiary

Event - Information

Primary

Result - Information

Primary

The important information for this action is which file was blocked on which host. The event information was expressed on which host and recorded by which agent on which host.

Result

event_result

event_severity

Success

S

2