Windows Event Log Search (Console-Side)
Introduced in version 7.9.0, this page provides a centralized console to analyze Windows event logs collected from endpoints.
Primary Use Cases:
- Centralized Visibility: Search across endpoint logs without needing direct access to local machine Event Viewers.
- Security Auditing: Surfaces Windows Auth Events to identify login patterns, lateral movement, or unauthorized access.
Sensor Audit Logs (Endpoint-Side)
To access these logs, open the Windows Start menu, launch Event Viewer, and navigate to Applications and Service Logs > Carbon Black EDR > Audit., these logs provide an on-endpoint source of truth.
Primary Use Cases:
- Connectivity Troubleshooting: Records server communication success/failure and heartbeats. This is the only place to verify if an offline sensor is failing due to network issues, certificate errors, or configuration problems.
- Operational Auditing: Provides a local record of sensor installation, upgrades, and service status (start/stop).
- Local SIEM Integration: Organizations can use Windows Event Forwarding (WEF) to collect these logs, providing an audit trail independent of the EDR infrastructure.
- Deployment Visibility: Logs "Enroll/Unenroll" events during fresh installations, helping troubleshoot deployment failures before the sensor can communicate with the server.