Carbon Black Cloud: How to Review Blocking Events in Windows Event Viewer (3.0 and above)
book
Article ID: 291571
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
Introuduce how to check CBC blocking events in Windows Event Viewer
Environment
- Carbon Black Cloud Windows Sensor: 3.0 and above
- Windows OS: All Supported Versions
Resolution
- Open Event Viewer
- Go to Windows Logs -> Application
- Search for "CbDefense" or "Carbon Black", and you will see blocking events from CBC.
OR
- Open Event Viewer
- Go to Windows Logs -> Application
- Under "Actions" menu select "Filter Current Log..."
- In the Event Sources drop down select "CbDefense" to view only Cb Defense Events
Additional Information
Search "CbDefense" in Event View can also give you CBC related events like service start, service stop, background scan, etc.
Feedback
thumb_up
Yes
thumb_down
No