Shield alert to show more than 90 days
Currently the Shield dashboard only show up to 90 days of alerts.
I would like to have the option to have all of the past alert and be able to filter it by custom date filter.
-
Anonymous
commented
just ran into an issue with shield. we have a file that was uploaded more than a year ago and tagged by shield as malicious (false positive). We marked it safe and moved on. recently a new version of the file was uploaded and tagged malicious (could be seen in the meta data on the file), BUT never showed up in the Shied dashboard because the original was tagged by Shield more than a year ago.
I had to open a case with box so they could locate the alert #, then I was able to find it by changing the number in the shield URL
Without Box support we would have never found the alert and not been able to mark the file a safe. We lost access to that file for 3 days because the filters wouldn't show the alert / they don't create a new alert -
Anonymous
commented
For alerts older than 90 days, you can adjust the URL to extend the date range, for example by setting daysAgo=365 to view alerts from the past year.
-
Anonymous
commented
It should be much more than 90 days and there needs to be filters, search capabilities or at the very least the ability to export out reports with custom time ranges so that we can atleast do the searching or filtering ourself in Excel.
-
Robert Landry
commented
I'm jumping aboard this idea as it has a mass of votes already. Showing more than the past 90 days would be very helpful. But I think there's a broader issue of discoverability for files flagged as malicious.
I'm a Box admin, but Shield issues are routed to InfoSec. When a problem is escalated to me, it's usually something like "file ##### has a malware flag, but I can't find it in the dashboard." That's because the alert is more than 90 days old. It should be a simple matter to pull up an alert page if I have the ID of the affected file.
-
Anonymous
commented
It took Box support 2 days to escalate to an engineer that could give us a simple Alert ID so that we view the alert for a file that was a false positive for malware. Our end user needed this file for a time sensitive report for a client. This needs to addressed!
-
Matt
commented
I agree. It would also be great if we could search shield alerts by file name to make identifying historical detection allot easier.