EventLog Search Page is Empty
search cancel

EventLog Search Page is Empty

book

Article ID: 441118

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

When going to the EventLog search page, the facets are empty and no events are seen. 

Environment

  • Carbon Black EDR: 7.9.0 and Higher
  • Carbon Black EDR Sensor: 7.5.0 and Higher
  • Microsoft Windows: All Versions

Cause

Common causes: 

  • Search button was not clicked on the page.
  • Sensor Groups are not set to collect eventlog data. 
  • Sensor 7.5.0 or higher is not being used. 

Resolution

By design, the EventLog page will not query for results for performance. Clicking "Search" within a timefrae where events happened will start displaying data. 

If the page is still blank.

  • The Event Log Events needs to be enabled per sensor group under the Event Collection tab with in the sensor group settings.
  • Validate the 7.5.0 or Higher Windows sensor is being used.