1 of 1 people found this helpful
use the "threat handled" parameter and select "equals" "false"
Attached you will find some queries that should help you. You can import them in your ePO and also put them in a new Dashboard.
Monitoring Threat Sources of last 24 hours (who is spreading malware to your network) and also all of the 'not handled' infections are things that you should review constantly.
queries.zip 2.2 K
Thanks for your answer
Thanks for your queries.
And is it possible to run a query on a specific container in the System Tree?
For example on "Country A", or "Country B"