This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ActionTaken field in ThreatEvents table

Where can I locate all the possible values for field ActionTaken in table ThreatEvents for Sophos AV?

I'm particularly interested to know what values after 116 mean

:29055


This thread was automatically locked due to age.
Parents
  • Did you look in the Enumerations table?  This exists in the SOPHOS51 database (SEC 5.1) by default, prior to that you had to install the SRI to get it.

    Regards,

    Jak

    :29131
  • I'm looking for the exact same thing, as I'm currently logging a sophos av database. I have zero idea what these actiontaken=116,117,101,etc. mean, and would like a list or some sort of feedback as to where to get this info. 

    Note, I maybe pretty ignorant here, but I've used google for the past 2 hours trying to find a list and don't see anything pertaining to Sophos and actiontaken lists.

Reply
  • I'm looking for the exact same thing, as I'm currently logging a sophos av database. I have zero idea what these actiontaken=116,117,101,etc. mean, and would like a list or some sort of feedback as to where to get this info. 

    Note, I maybe pretty ignorant here, but I've used google for the past 2 hours trying to find a list and don't see anything pertaining to Sophos and actiontaken lists.

Children
  • Hello JacobAnderson,

    I've used google
    Google is your friend but Google isn't God. Neither is  (no derision intended, Jak [;)]) but I'd rather ask him than Google on these matters and moreover I'd definitely trust him. He has already given the answer: the Enumerations table. Not all values are unique though so you might want to consult the EnumNames table for the applicable EnumID.

    Christian