Endpoint Protection

 View Only
  • 1.  Data Insight event question

    Posted Oct 02, 2013 11:10 AM

    Hello,

    I have an event for Data Insight in the Risk Logs for a particular downloaded executable.  The actual action in the event is "Moved Back."  What does "Moved Back" mean?  

    Thanks in advance,

    Bob



  • 2.  RE: Data Insight event question

    Posted Oct 02, 2013 11:13 AM

    I believe it may have been restored from quarantine by the user:

    https://www-secure.symantec.com/connect/forums/sep-12-actual-action-moved-back

    you may want to question them about it to see if this was the case



  • 3.  RE: Data Insight event question
    Best Answer

    Broadcom Employee
    Posted Oct 02, 2013 11:17 AM

    can you please post the risk log?

     



  • 4.  RE: Data Insight event question

    Posted Oct 02, 2013 11:55 AM

    Here's a screenprint.  My concern highlighted in green.  Thanks.

    10-2-2013 10-22-15.jpg



  • 5.  RE: Data Insight event question

    Posted Oct 02, 2013 12:09 PM

    Check to see if it was restored from the quarantine



  • 6.  RE: Data Insight event question

    Posted Oct 02, 2013 03:36 PM

    So what was it??



  • 7.  RE: Data Insight event question

    Posted Oct 03, 2013 04:36 AM

    Hello Blzbob,

    If a file is quarantined ( lets image that it was false positive) and user has moved that file from Quaratine, then you will get the action as "Moved back" hope it was helpful.



  • 8.  RE: Data Insight event question

    Posted Oct 08, 2013 10:06 AM

    Restoring from quarantine.



  • 9.  RE: Data Insight event question

    Posted Oct 08, 2013 10:44 AM

    Sorry was just confused by the marked answer



  • 10.  RE: Data Insight event question

    Posted Oct 08, 2013 11:42 AM

    Brian, my hand is a bit jumpy and I clicked the wrong solution.  



  • 11.  RE: Data Insight event question

    Posted Oct 08, 2013 11:48 AM

    No worries. I was particularly interested in the solution just for confirmation of what the action actually meant. I've seen a few like these before in the past and after some troubleshooting that was my suspicion but I think this fully confirms it.