<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Retrospective Quarantine Attempt Failed alerts in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181107#M5814</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1018896"&gt;@pavan1989&lt;/a&gt;, is it happening to one machine only?&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17788"&gt;@ckuwajima&lt;/a&gt;&amp;nbsp;is right, it usually happens when the file it's trying to quarantine is no longer found in the same location it was found by the connector originally. But I can't explain the spike without details and logs. The empty file info is strange too.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please open a TAC case so it can be investigated.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2020 19:38:52 GMT</pubDate>
    <dc:creator>DaphneG</dc:creator>
    <dc:date>2020-11-09T19:38:52Z</dc:date>
    <item>
      <title>Retrospective Quarantine Attempt Failed alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4180235#M5804</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are observing huge sipke in&amp;nbsp;Retrospective Quarantine Attempt Failed alerts from past 2 days. Also, in the Event types not showing files affected. Could anyone please suggest what could be the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 08:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4180235#M5804</guid>
      <dc:creator>pavan1989</dc:creator>
      <dc:date>2020-11-09T08:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Quarantine Attempt Failed alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4180920#M5810</link>
      <description>&lt;P&gt;My experience with retrospective quarantine attempt failed events is that I could not locate the culprit file anywhere in the target system.&lt;/P&gt;&lt;P&gt;In my case, every instance was a file in temporary file directory, probably deleted by OS or application, long before AMP flagged as a compromise.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 15:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4180920#M5810</guid>
      <dc:creator>ckuwajima</dc:creator>
      <dc:date>2020-11-09T15:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Quarantine Attempt Failed alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181107#M5814</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1018896"&gt;@pavan1989&lt;/a&gt;, is it happening to one machine only?&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17788"&gt;@ckuwajima&lt;/a&gt;&amp;nbsp;is right, it usually happens when the file it's trying to quarantine is no longer found in the same location it was found by the connector originally. But I can't explain the spike without details and logs. The empty file info is strange too.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please open a TAC case so it can be investigated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 19:38:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181107#M5814</guid>
      <dc:creator>DaphneG</dc:creator>
      <dc:date>2020-11-09T19:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Quarantine Attempt Failed alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181372#M5818</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/415197"&gt;@DaphneG&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's showing for all the machines when I see in the event type for the compromised machine the file is empty.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 04:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181372#M5818</guid>
      <dc:creator>pavan1989</dc:creator>
      <dc:date>2020-11-10T04:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Quarantine Attempt Failed alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181384#M5819</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/415197"&gt;@DaphneG&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17788"&gt;@ckuwajima&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I click on File Analysis for the same alert I am observing an error as&amp;nbsp;Tsv Not Enabled Html. Could you please guide me what could be the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 05:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181384#M5819</guid>
      <dc:creator>pavan1989</dc:creator>
      <dc:date>2020-11-10T05:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Retrospective Quarantine Attempt Failed alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181547#M5820</link>
      <description>&lt;P&gt;Never saw such problem and do not have deep understanding of AMP for Endpoints. You'd better open a TAC case as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/415197"&gt;@DaphneG&lt;/a&gt;&amp;nbsp;said.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 12:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/retrospective-quarantine-attempt-failed-alerts/m-p/4181547#M5820</guid>
      <dc:creator>ckuwajima</dc:creator>
      <dc:date>2020-11-10T12:01:04Z</dc:date>
    </item>
  </channel>
</rss>

