EDR: What Type of Audit Logging is Supported?
search cancel

EDR: What Type of Audit Logging is Supported?

book

Article ID: 291587

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

What type of audit logging is supported on EDR?

Environment

  • EDR (formerly CB Response): 6.x and Higher

Resolution

  • Only the output of "audit.log.useractivity" is supported at this time.
  • By default, only user actions to log in and log outs are tracked. 
  • To enable user API tracking, which can indicate actions taken within the EDR UI:
  1. On the master server, edit /etc/cb/cb.conf
  2. Add or modify:
EnableExtendedApiAuditLogging=true
  1. Restart services

Additional Information

  • Hosted EDR customers should open Carbon Black support case to enable "EnableExtendedApiAuditLogging"
  • Additional audit logs are planned for future releases, including:
    • audit.log.liveresponse
    • audit.log.isolation
    • audit.log.banning