<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP - Actions made after Require Attention option in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810085#M3106</link>
    <description>&lt;P&gt;Juan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct that they will remain In Progress until you mark them as Resolved.&amp;nbsp; As for the Malware Executed, there are a number of reasons you may see this, most common being that the policy was in Audit mode.&amp;nbsp; If you would like someone to take a closer look, I recommend opening a TAC case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
    <pubDate>Tue, 26 Feb 2019 16:03:57 GMT</pubDate>
    <dc:creator>Matthew Franks</dc:creator>
    <dc:date>2019-02-26T16:03:57Z</dc:date>
    <item>
      <title>AMP -</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp/m-p/3809466#M3103</link>
      <description>&lt;P&gt;Hello, evaluating AMP for Endpoints first configuring policy to Audit, and after that first scan I change computers to group of Protect, check image attached, and my question is, how to apply the actions??&amp;nbsp; There are files detected that I delete it and still being reported by AMP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Requiere Attention I enabled, but it´s been more than 4 days with events In Progress but nothing does.&amp;nbsp; How can I apply actions to take AMP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Juan Carlos Arias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp/m-p/3809466#M3103</guid>
      <dc:creator>Juan Carlos Arias Perez</dc:creator>
      <dc:date>2020-02-21T05:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: AMP -</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp/m-p/3809477#M3104</link>
      <description>&lt;P&gt;Juan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Those will not automatically be marked as Resolved.&amp;nbsp; When there is an event in the Requires Attention section, you can click the Begin Work button which will move it into the In Progress section.&amp;nbsp; Then, you can click Mark Resolved when you are finished.&amp;nbsp; This is done manually by a user as a way to track tasks, not automatically by anything on AMP's side.&amp;nbsp; I hope that clears things up for you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 00:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp/m-p/3809477#M3104</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2019-02-26T00:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Actions made after Require Attention option</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp/m-p/3809984#M3105</link>
      <description>&lt;P&gt;Hello Matthew, thanks for your comments, I made the steps you mention, but events remain In Progress tab until you select it and Mark Resolved, is this correct??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, on events of this Computer, I can see that some events actions like Policy Update, Scan Clean, Scan Started, and I can see one that it says Executed Malware, what are the recommended actions for this event??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AMP2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/30950iB4D903FF113BAEDB/image-size/large?v=v2&amp;amp;px=999" role="button" title="AMP2.jpg" alt="AMP2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Juan Carlos Arias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 14:41:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp/m-p/3809984#M3105</guid>
      <dc:creator>Juan Carlos Arias Perez</dc:creator>
      <dc:date>2019-02-26T14:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Actions made after Require Attention option</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810085#M3106</link>
      <description>&lt;P&gt;Juan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct that they will remain In Progress until you mark them as Resolved.&amp;nbsp; As for the Malware Executed, there are a number of reasons you may see this, most common being that the policy was in Audit mode.&amp;nbsp; If you would like someone to take a closer look, I recommend opening a TAC case.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 16:03:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810085#M3106</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2019-02-26T16:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Actions made after Require Attention option</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810392#M3107</link>
      <description>&lt;P&gt;Matthew, I´m evaluating the solution so I can´t open a case on TAC yet and my policy is to Protect.&amp;nbsp; What I can see is that you need another software to complement the solution, like an AV or FW, is this correct??&amp;nbsp;&amp;nbsp; I´m saying this based on the actions that can be made after detecting malware or virus or something else, just trying to understand, thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 22:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810392#M3107</guid>
      <dc:creator>Juan Carlos Arias Perez</dc:creator>
      <dc:date>2019-02-26T22:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Actions made after Require Attention option</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810395#M3108</link>
      <description>&lt;P&gt;Juan,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you are in a POV, you can ask your Account Manager to open a case on your behalf with the appropriate logs from the system.&amp;nbsp; With Malware Executed events, what typically takes place is a malicious process attempted to execute and AMP quarantined it.&amp;nbsp; Look for a Quarantine event at the same time for the same file.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 26 Feb 2019 22:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810395#M3108</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2019-02-26T22:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - Actions made after Require Attention option</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810397#M3109</link>
      <description>You´re right Matthew, some files have been moved to Quarantine, I didn´t notice that before.&lt;BR /&gt;Regards,</description>
      <pubDate>Tue, 26 Feb 2019 22:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp/m-p/3810397#M3109</guid>
      <dc:creator>Juan Carlos Arias Perez</dc:creator>
      <dc:date>2019-02-26T22:15:47Z</dc:date>
    </item>
  </channel>
</rss>

