To detect threats quickly and keep the protection level of a client device up to date, you have to regularly update databases and application modules on the device.
You can update databases on a device in one of the following ways:
This option is available if the investigation graph is built.
You can also configure the response action to run automatically when creating or editing a playbook.
To update databases on a device, you must have one of the following XDR roles: Main administrator, Tenant administrator, Junior analyst, Tier 1 analyst, Tier 2 analyst.
It might take up to 15 minutes to launch a response action due to the synchronization interval between the managed device and the Administration Server.
To update databases on a device:
If you want to update databases from an investigation graph, select the Incidents section.
You can select several devices, if necessary.
If the operation is completed successfully, an appropriate message is displayed on the screen. Otherwise, an error message is displayed.