top of page

Process Logs

Process Log INGLESE.png

In this screen, the Process Logs grid, available only with a dedicated license, displays all events related to processes detected on the monitored machines.

For each event, a wide range of information is available, including the event date and time, machine, user, domain, execution token, process name, and the executable involved.

This section allows you to monitor process creation and termination, analyze activities performed on workstations, and identify the execution of potentially suspicious or unauthorized applications.

Thanks to the integrated filters and search tools, you can perform targeted investigations and quickly reconstruct the history of recorded events.

Explain Selected Log

The Explain Selected Log button uses an Artificial Intelligence engine to automatically analyze the selected log and provide an interpretation in natural language.

Its purpose is to help the operator quickly understand the meaning of the event without having to manually interpret the technical details of the log. The analysis is divided into several sections:

  • What happened: Describes the detected event, highlighting the main available information, such as the process, user, machine, device involved, or any other relevant details needed to understand what occurred.

  • Why it matters: Explains the significance of the event from both an operational and security perspective, highlighting potential risks, unusual behavior, or aspects that may require further attention.

  • Actions: When applicable, suggests checks, verifications, or recommended actions to further investigate the event or address any identified issues.

At the bottom of the window, the Wiki section provides additional information related to the analyzed event, the process, the executable, or any other involved elements.

When the Artificial Intelligence engine does not have sufficient information to produce a complete analysis, the Wiki section offers technical information, operational guidance, and useful references to support further investigation of the event.

Process Log INGLESE 2.png

The generated explanation can be printed or saved using the commands available at the bottom of the window.

Log
Archives

bottom of page