---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Antivirus metrics

# Antivirus metrics {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

If the Antivirus Scanning plugin is activated, Antivirus Scanning runs in your instance to help protect it against virus infections
from attachments.

The following metrics appear for the last 60 days of activity, and enable you to assess the
effectiveness of the Antivirus Scanning functions.

## Antivirus Events {#instance-sec-center-antivirus-metrics__section_antivirus_metrics}

Antivirus Events indicate the number of antivirus events in your instance, by date. To access the antivirus events, navigate to System SecurityInstance Security Center and select the Metrics tab. Color coded graph lines represent the following types of antivirus events: {#instance-sec-center-antivirus-metrics__table_vdw_n25_yfb__entry__2}

| Color | Description |
|-|-|
| Blue | Number of files quarantined by Antivirus Scanning in this instance for the indicated date. |
| Green | Number of infected files downloaded to the instance, and then quarantined for the indicated date. These files are primarily email attachments that contain a virus or rouge code. |
| Yellow | Number of quarantined files in the instance that were deleted for the indicated date. |
| Orange | Number of quarantined files in the instance that were restored for the indicated date. Hinweis: After Antivirus Scanning runs and finds any false positives, you can restore a quarantined file and make it accessible in the instance. |
[ ]

{#instance-sec-center-antivirus-metrics__table_vdw_n25_yfb}

* To access the KPI Details page and view the analytics information for a specific date, click a colored line in the Antivirus Events graph. For example, click the blue graphics line to view analytics information for files quarantined for a specific date.
* To view the following breakdowns in the KPI Details page, click ![Breakdown icon](), then click:{#instance-sec-center-antivirus-metrics__table_wvf_v5t_1jb__entry__2}

  | Breakdown | Description |
  |-|-|
  | AppSec - Antivirus Event Source | Source of the antivirus event. * On Upload: Occurred due to an upload of an infected file, usually an attachment. * From Quarantine: Occurred due to the quarantine of an infected file, usually an attachment. * On Download: Occurred due to a download of an infected file, usually an attachment. * From Record: Occurred due to an infected record in a table. {#instance-sec-center-antivirus-metrics__ul_f15_s1k_cjb} |
  | AppSec - Antivirus Event Type | Type of antivirus event. * Quarantined: Occurred due to the quarantine of a file, usually an attachment. * Downloaded: Occurred due to a download of a file, usually an attachment. * Restored: Occurred due to the restoration of a quarantined file. * Deleted: Occurred due to the deletion of a quarantined file. {#instance-sec-center-antivirus-metrics__ul_p5s_lbk_cjb} |
  | AppSec - Antivirus Uploader | Name of the logged in user who uploaded the files that were the source of virus infections detected by the Antivirus Scanning application. |
  [ ]

  {#instance-sec-center-antivirus-metrics__table_wvf_v5t_1jb}
{#instance-sec-center-antivirus-metrics__ul_jbz_rhf_1jb}

## Quarantined Files {#instance-sec-center-antivirus-metrics__section_t5k_xrh_3nb}

Lists the infected files in the instance quarantined by Antivirus Scanning:{#instance-sec-center-antivirus-metrics__table_zxh_1wj_cjb__entry__2}

| Field | Description |
|-|-|
| File name | Name of the infected file. |
| Content type | Type of content that was infected in the file. For example, application/x-dosexec is an infected application or DOS executable file, while text/plain is an infected .txt file. |
| Table | Name of the table that contains the infected file. For example, incident appears for an incident file record. |
| Virus | Name of the file quarantined by Antivirus Scanning. |
| Detected | Date and time the infected file was detected. |
| Created By | Name of the user who quarantined the infected file. |
| Created | Date and time the quarantine file record was created. |
| Table sys ID | Table system identifier assigned to the quarantine file record. |
[ ]

{#instance-sec-center-antivirus-metrics__table_zxh_1wj_cjb}  
Hinweis:  
You can also add Quarantined Files and Virus Types tiles to the Event ribbon. To learn more, see [Monitor security events](https://servicenow-prod.fluidtopics.net/eYc1gyx3yMCPgkrQxx0KKg "Analyze the event metrics in your instance so that you can identify and prevent potential security events.") and [Configure the security event ribbon](https://servicenow-prod.fluidtopics.net/_jaFMz0U0VHIjZUHEJ2qoA "Configure the security event ribbon on the Instance Security Center homepage to include only those events that are relevant for tracking instance security in your operations. You can also change the order in which the security event tiles appear on the ribbon.").
**Zugehörige Konzepte**   

* [Antivirus Scanning](https://servicenow-prod.fluidtopics.net/9Jg1~qjwhmfUsffwm2p77w "Use Antivirus Scanning to help protect your instance against virus infections that can be introduced by file attachments to your system records, such as incidents, problems, and stories.")  
**Zugehörige Tasks**   

* [Configuring Antivirus Scanning](https://servicenow-prod.fluidtopics.net/3RKVQ0TbS3KdcBmLOLufjw "Configure Antivirus Scanning across your instance and at the table level.")
* [Reviewing quarantined files](https://servicenow-prod.fluidtopics.net/uG_cbAirs1VCl8OeRArX~A "Review quarantined file attachments and take further action as needed.")
* [Review antivirus activity](https://servicenow-prod.fluidtopics.net/UQ5Mv6LglVAuUhPhGJSfmg "Review the Antivirus Activities log that tracks all activities that occur on potentially-infected files from the point that they are discovered and placed into quarantine.")  
**Zugehörige Informationen**   

* [Analytics Hub](https://www.servicenow.com/docs/access?context=c_UsePerformanceAnalyticsScorecards&version=australia&pubname=australia-now-intelligence&ft:locale=en-US)
* [Performance Analytics breakdowns](https://www.servicenow.com/docs/access?context=c_CreatingBreakdowns&version=australia&pubname=australia-now-intelligence&ft:locale=en-US)
* [Analytics, Intelligence, and Reporting](https://www.servicenow.com/docs/access?context=c_performanceAnalyticsAndReporting&version=australia&pubname=australia-now-intelligence&ft:locale=en-US)

