Endpoint Detection and Response (EDR)

 View Only
  • 1.  Risk conditions report EDR

    Posted Apr 25, 2022 03:55 PM
    Dear.
    I have searched everywhere and found nothing. I need to get the risk conditions report in Symantec EDR.

    Is there any way to do it. Currently when I enter it only shows me a graph, which also does not send it by mail.
    Any help would be appreciated


  • 2.  RE: Risk conditions report EDR

    Broadcom Employee
    Posted Apr 26, 2022 05:38 AM
    Hi Boris,
    I am not not entirely clear on the "Risk Condition Report" that you are referring to. However the graph shown in the screenshot is showing "Incidents over time" and you can configure email alerts when an incident is triggered. This is configured on a per user basis:

    You can also integrate your SIEM with the EDR appliance REST API to extract Incident creation, update and closure.