The analysis of Antivirus events can be a tedious task in big organizations with hundreds of events per day. Usually security teams fall back to a mode of operation in which they only analyze events in which a cleanup process has failed or something went wrong.
This is definitely the wrong approach for a security team. You should instead focus on highly relevant events.
This cheat sheet helps you select these highly relevant Antivirus alerts.
Download the Antivirus Event Analysis Cheat Sheet version 1.8.2 here.