Event Actions
4 min
Overview
Event Actions represent what happens when an event is raised. Actions are specific to a rule set and the role that rule set is associated with. In other words, 2 different sets of agents can have 2 different sets of actions take place for the same event.
There are 3 common sets of event actions used with a given event which increase in aggressiveness based on the desired handling of the event:
- Just log the event for viewing by the supervisor and reporting purposes (insertToDB)
- Log the event and put the agent's Windows screen to sleep (insertToDB + lockScreen)
- Log the event, lock the agent's screen, and require a one time passcode/OTP to be entered (insertToDB + blackOut)
Managing Event Actions
Once you have accessed Remote Security Rules and selected the desired role, click on the Event Action tab. For more info on getting to this point, see Remote Security Rulesīģŋ.

This page contains a list of all configurable events on your system.
- To manage the actions for a specific event, click on the arrow at the left end of the event.
- To add a new action to that event, click on "Add New Action Record".
- To modify an existing action, click on the pen button to the left of the existing action.
- To remove an action from an event, click on the trash can to the left of the existing action.

Event Action Settings
When you add a new or edit an existing event action, the following window will appear.

- Name - represents the type of action to take. There are 4 types of actions:
- report - logging of the event
- SCREENBLOCKER - putting the screen to sleep or locking it
- MONITORPROCESSES - killing a detected application/process
- CLIPBOARDMONITOR - clearing the clipboard
- Enable - check this box to enable the action
- State - for Secure Work from Home actions, this can always be set to "na"
- Trigger Action - there are 6 actions which are used by Secure Work from Home (with there associated Name/action type in parens):
- insertToDB (report) - log the action to the database for viewing / reporting
- lockScreen (SCREENBLOCKER) - put the agent's screen to sleep
- blackOut (SCREENBLOCKER) - lock the agent's screen and require a one-time passcode (OTP) be entered
- RELEASEBLACKOUT (SCREENBLOCKER) - release the blackOut - this can be used in conjunction with the NetworkConnectionDetected event in case a blackOut was implemented on NetworkDisconnectionDetected
- kill (MONITORPROCESSES) - kills the specified process (see Arguments)
- restartCamera (SCREENBLOCKER) - used with the CameraBlockDetected event to restart the camera should a USB camera be plugged / unplugged.
- clearClipboard (CLIPBOARDMONITOR) - clears the clipboard
- Count - number of additional times the event must be detected in Duration seconds for this action to be taken.
- Count = -1 or 0 - perform this action the 1st time this event occurs (Duration not used)
- Count = 1 - perform this action the 2nd time this event occurs within Duration seconds
- Count = 2 - perform this action the 3rd time this event occurs within Duration seconds
- and so on for 3, 4, 5, etc
- Duration - represents seconds - used in conjunction with Count above
- Arguments - currently only used with the "kill" trigger action to specify the process to be killed
- Message Type - not currently used
- Message Text - not currently used
- Modify Reason - used for change auditing purposes. Required when an existing event action is modified.