Events

The Events page lists everything EyalSec has detected on your machines, one list per product, newest first. This page explains how the lists are organised, what each column means and how repeats are counted.

What an event is

An event is one finding: untrusted data reached a risky operation in a program EyalSec watches. Each row names the operation (the sink), where the data came from (the source), how serious it is and how many times it has happened.

Nothing on this page changes what is stored. Filters, the Map layout and the Show control only change what you see. To stop recording something, or to hide it for good, use rules and the Filters page.

One list per product

Each EyalSec product enabled on your account has its own events list, so a browser finding never gets mixed in with a server-side one. You switch lists in the sidebar, not with tabs inside the page.

  • With one product, the sidebar has a single Events link.
  • With both products, each has its own link, named after it (es-python and es-chromium), with its logo.

You only see lists for products enabled on your account. A missing list is not an error: that product is simply not enabled for you. See Products for how products are enabled. Turning a product off hides its list but never deletes its events; they come back when it is turned on again.

Each list keeps its own filters. Switching lists starts the new list with its own controls cleared, except Show, Label and Tag, which apply to every list. Saved searches are also per list (see Saved searches).

The count next to each list

The number beside a product in the sidebar is how many events that list can show you right now. It already has your plan's monthly event quota and the current Show setting applied, so it never promises rows the list cannot display.

The count does not follow the toolbar filters (machine, severity, time and so on): it is the size of the whole list. It refreshes about once a minute while the page is open.

Reading the table

Events are listed newest first. The table loads 100 rows at a time and fetches more as you scroll, so you can keep going back in time without paging. When you reach the end, the last row says end of results, and if your plan limits the list it also says how many events your plan shows.

Click a row to open it in place (see Event detail). Right-click it, or press its ⋮ button, for the row menu. On a narrow screen each row turns into a card with the column names beside each value.

Very long values (a minified script URL, say) are shortened to their start and end with a [+N chars] marker in the middle. Click the marker to show the whole value.

Time

When the event last happened, in your time zone (the zone is shown in the column header and set in Settings). A repeat of an event moves it back to the top of the list with the new time.

Severity

How serious the finding is: Critical, High, Medium, Low or Info. EyalSec works it out on the server from two things: how easily an attacker can control the source (a network request is worse than a file only you can write) and how much damage the sink can do (running a command is worse than writing a log line).

The severity also colours the row's left edge. Some findings have their severity lowered by one level because the data passed through a sanitizer that only protects it in some situations; findings that were fully made safe are hidden instead (see Suppressed events).

Machine

The machine that reported the event, by the name it has on the Machines page. On es-chromium the same column or filter says Browser instead.

By default, the same finding on two of your machines is one row, and this column shows the machine that reported it most recently. To keep each machine's findings apart, turn on Machine in Unique event.

Event

The sink label (what the program did with the data, such as os system or sqlite3 execute), followed by small markers:

Marker Meaning
Coloured pills (sqli, xss, command injection, ...) The impact tags: the class of vulnerability
A number The count: how many times this event has happened
Suppressed The event was proven safe (only shown when Show includes suppressed events)
Coloured chips Your own labels
✎ You wrote a note on this event
⋮ Opens the row menu

Hover the sink label to see its full text. Open the row to see the program call behind it (for es-python, the Python function, such as os.system()).

File

On es-python, the file the program wrote to, for events that are a file write. It is a dash for every other event. The full destination, and whether other users can read it, is in the event detail.

Columns by product

Every list shares Time and Severity. The rest depends on the product, because each answers a slightly different question:

List Columns after Severity
es-python Machine, Event, File
es-chromium Flow (source -> sink, plus the browser extension's name when an extension caused it), Page

es-chromium describes its events in more detail.

Repeats and the count

EyalSec does not store one row per occurrence, which would flood the list. Identical findings are grouped into one row, and the number on the row counts how many times it happened. A high count means something keeps hitting that code path.

By default two findings are the same event when they come from the same product, reach the same sink, carry the same chain of steps from the source, and have the same detail line (for example the same file path or regular expression). You can make this finer or coarser per product and per machine with Unique event.

When the list is narrowed to a single run, the number shows that run's own occurrences instead of the all-time total. Hover it to see which of the two you are looking at.

Impact tags

Every event carries one to three impact tags, the coloured pills beside the sink: the vulnerability class of the flow, such as sqli, xss, command injection or path traversal. They answer "what does an attacker get from this?", which the sink name alone does not.

A tag's colour is the severity of that class in general, not of this event. A command-injection tag stays red on an event graded Low because its source is trusted. On a suppressed event the tags lose their colour. To show one class only, use the Tag filter (see Filtering).

The event tally

Under the toolbar, a short line says how many events this list holds, for example 1,234/5,000 events in this view this month. The second number is your plan's limit for this list. Each product's list has its own allowance, so enabling a second product adds a new allowance rather than splitting the one you have. See Plans.

Live updates

The list reloads itself every two seconds, so new events appear without refreshing the page. The Live · 2s button in the toolbar shows this. Click it to pause (it then reads Paused) and click again to resume.

To keep the list still while you read, the automatic reload waits while you have a row open, a menu open, the pointer over the list, or have scrolled down past the first screen. It catches up as soon as you are done. It also pauses while a slow search is still working through your history.

Where to go next

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo