I know this has been asked before.
How can I receive a more detailed email regarding warnings?
Like … This morning I got 2 emails (1st: 07:24, 2nd: 08:33):
“EM Warning: New Infection Detected!”
You are receiving this e-mail because you are using Endpoint Manager product.
2020-04-30 05:23:36. New Infection Detected on device #####.
Follow the <link> to see details.
Best Regards,
EM Team
Here in this email I would like to see how urgent this warning is!
What kind of threatlevel and what kind of malware has been detected.
Also a direct link to delete/whitelist the threat.
Not first having to login, and search for the affected device.
Now, I clicked the link and I’m directed to the Malware overview.
But… the last stated item is for over 8 days ago!!
So this is not the item stated in this email!
Now I have to search what could be the trigger.
The other tabs: ‘Threat history’ and ‘Autorun items’ are empty. But ‘Quarantined files’ shows one item from this morning.
So now I’m still wondering if this is the warning because I got 2 seperate warnings.
But, now it’s getting more confusing:
If I open the ‘Quarantined files’, and click on the file, ( in this case named ‘appselector.exe’) , I can see on what devices this file has been found.
And if I select that (‘Device list’), only one (!) device is listed where this file is installed on.
But,… thats a whole other device from another customer. This device, where I got 2 EM warnings from, isn’t mentioned here.
So, long story, but the bottom line is:
Can the EM messages be more specific and detailed about the threat? Better would be with direct links for actions (like whitelist/ delete/ scan/…)
And how can I search for these warnings because I can’t trace them back!
So, after all this checking, I still haven’t found out what the 2 emails were referring to.
Am I doing something wrong?
Regards