Event states and severities explained

Modified on Wed, Sep 23 at 10:15 AM

On the Events page, every security event carries a State (what has happened to it) and a Severity (how serious it is), along with a note on who remediated it. Reading these correctly tells you at a glance whether something needs your attention or has already been handled. Here is what each value means.

Event states

The State column tells you where an event is in its lifecycle:

StateWhat it means
PendingThe event needs an administrator to act on it. A common example is a policy in Monitor mode that has detected a phishing email sitting in a user's mailbox. Pending is not a delivery status, the mail may already be in the inbox; it simply means no remediation has been taken yet.
RemediatedThe event has been dealt with, automatically by the policy or manually by an admin. Remediation can mean quarantining the email, removing attachments, or moving it to the Junk/Spam folder.
DetectedA security event happened, but there is nothing for an admin to manually remediate. For example, a malicious email sent by one of your own internal users to an external recipient.
DismissedAn admin manually dismissed the event to clear it from the open list. Dismissed events still appear in the Security Checkup report.

Severity

Each event is rated for how serious it is, from most to least severe:

  • Critical
  • High
  • Medium
  • Low
  • Very Low

Severity is about how serious the detection is, not what has been done about it. A Critical event that shows as Remediated has already been handled; a lower-severity event left Pending may still be the one that needs a look.

Who remediated it

The Events table also records who took the action, under Remediated by:

  • Check Point (shown without a name): Email Security took the action automatically based on the policy.
  • Microsoft: Microsoft took the action automatically.
  • Admin: an administrator acted manually, for example quarantining an email after delivery.
  • analyst: a Check Point analyst handled it. This only applies if you have the Incident Response as a Service add-on.

Related

Graymail and spam explained

Need Help with Check Point Harmony?

We deploy, configure, and manage Check Point Harmony Email & Collaboration for businesses, making sure your policies, engines, and protection modes are set up correctly so your organisation is fully covered.

Speak to an expert

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article