EDR: How to Enable Verbose Audit Logging
search cancel

EDR: How to Enable Verbose Audit Logging

book

Article ID: 288034

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

How to enable verbose audit logging

Environment

  • EDR: All Versions

Resolution

  1. Log onto the EDR Server through ssh/terminal
  2. Open /etc/cb/cb/cb.conf
  3. Add the following line anywhere in the file
    EnableExtendedApiAuditLogging=True
  4. Restart the Server Services EDR: How to restart the server services

Additional Information

  • This will capture the API calls being made within the console
  • Log location: /var/log/cb/audit