Windows Event Log Search and Sensor Audit Logs Overview
search cancel

Windows Event Log Search and Sensor Audit Logs Overview

book

Article ID: 445679

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

Explain the use cases and value of the Windows Event Log search page and local Sensor Audit Logs within Carbon Black EDR.

Environment

 

  • Product: Carbon Black EDR
  • Server Versions: 7.9.0 and Higher
  • Client Versions: 7.5.0 and higher

Resolution

Windows Event Log Search (Console-Side)

Introduced in version 7.9.0, this page provides a centralized console to analyze Windows event logs collected from endpoints.

Primary Use Cases:

  • Centralized Visibility: Search across endpoint logs without needing direct access to local machine Event Viewers.
  • Security Auditing: Surfaces Windows Auth Events to identify login patterns, lateral movement, or unauthorized access.

Sensor Audit Logs (Endpoint-Side)

To access these logs, open the Windows Start menu, launch Event Viewer, and navigate to Applications and Service Logs > Carbon Black EDR > Audit., these logs provide an on-endpoint source of truth.

Primary Use Cases:

  • Connectivity Troubleshooting: Records server communication success/failure and heartbeats. This is the only place to verify if an offline sensor is failing due to network issues, certificate errors, or configuration problems.
  • Operational Auditing: Provides a local record of sensor installation, upgrades, and service status (start/stop).
  • Local SIEM Integration: Organizations can use Windows Event Forwarding (WEF) to collect these logs, providing an audit trail independent of the EDR infrastructure.
  • Deployment Visibility: Logs "Enroll/Unenroll" events during fresh installations, helping troubleshoot deployment failures before the sensor can communicate with the server.

Additional Information