EDR: What Type of Audit Logging is Supported?
book
Article ID: 291587
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
What type of audit logging is supported on EDR?
Environment
- EDR (formerly CB Response): 6.x and Higher
Resolution
- Only the output of "audit.log.useractivity" is supported at this time.
- By default, only user actions to log in and log outs are tracked.
- To enable user API tracking, which can indicate actions taken within the EDR UI:
- On the master server, edit /etc/cb/cb.conf
- Add or modify:
EnableExtendedApiAuditLogging=true
- Restart services
Additional Information
- Hosted EDR customers should open Carbon Black support case to enable "EnableExtendedApiAuditLogging"
- Additional audit logs are planned for future releases, including:
- audit.log.liveresponse
- audit.log.isolation
- audit.log.banning
Feedback
thumb_up
Yes
thumb_down
No