Chapter 6 - Quarantine Management

 

Applies to: Microsoft Antigen

The Quarantine Manager is used to import Quarantine data from managed Antigen servers for local analysis and management.

Retrieving Quarantined Data

To retrieve and manage Quarantine data, follow these steps:

  1. Click Quarantine Manager in the Job Management section of the Navigator area. The Quarantine Manager work pane will be displayed. Note that no data will be displayed until it has been imported.
  2. Click the Import Data button. The Retrieve Data work pane will open as shown in the image below:
    16a21dba-9d24-4eee-9335-0e18506279f9
  3. Select the machines from which to retrieve Quarantine data.
  4. Select the start date for data retrieval. Either type a date or click the calendar icon and select a date from the calendar. All data, from the start date until today, will be retrieved.
  5. Click the Retrieve Data button to run the job. The data will be retrieved and displayed in the Quarantine Manager work pane.

Filtering Quarantined Data

Once the data has been imported to the local AEM machine, a set of display filters can be used to narrow the scope of the data displayed. To open the filter view, click the View Filter button at the top of the pane. The filters will be displayed as shown in the image below:

48e4a0f4-09fc-4eef-8a02-8f2e72a8bb97

Each filter corresponds to a field in the Quarantine data. To filter based on a file name or type, enter the name or file type into the File filter box.

For example: If you wanted to see how many .exe files were filtered, you can enter “exe” into the File filter box.

You can also filter using multiple fields by using the And or Or Connector radio buttons.

Viewing, Releasing, and Deleting Files

Individual entries in the Quarantine Manager can also be viewed, released, or deleted.

View

Displays the contents of the Quarantine entry.

Release

Allows the administrator to deliver the Quarantined message to recipients that they select. Note that delivered messages will be re-scanned for viruses.

Delete

Permanently deletes the record from the Quarantine database on the remote Antigen server.

Note

Forwarded messages will be re-scanned for viruses.