Jamf Protect provides additional helpful information about alerts in the detail view. Click the alert title to open the detail view for that alert. Alternatively, you can click Detail View on the alerts page to view each alert's details in the current filter query.
Jamf recommends to prioritize alerts that are marked as high severity and have a status of new. You can use the information provided in the alert details to assist with remediation.
When you click on an alert the following information is displayed.
- Summary
Describes the detection event and provides remediation suggestions. Includes other general information about the event such as the Host IP, Timestamp, associated Tags, domain information, signing information.
- Processes
Provides detailed information about the processes involved in the event such as the signing information, path, process name and process UUID.
- Files
Provides detailed information about the files involved in the event, such as the path, signing information and hash.
- Binaries
Similar to the information for files. Provides detailed information about the binaries involved in the event, such as the path, signing information and hash.
- Users
Lists the users involved in the event.
- Groups
Lists the user groups involved in the event.
- JSON
Provides the raw alert data in a JSON format.
- Add Exception
Allows you to add an exception for this alert criteria using an exception set.