Collecting Event Viewer logs
Article ID: 286875


Carbon Black App Control (formerly Cb Protection) Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter) Carbon Black EDR (formerly Cb Response)


To collect Event Viewer logs


  • Microsoft Windows: All Supported Versions


  1. Click Start > Run > eventvwr > OK.
  2. In the left hand pane expand Windows Logs > right click Application > Save All Events As...
  3. Specify a location for the Application Logs.evtx file > Save.
  4. Choose: Display information for these languages > English > OK.
  5. In the left hand pane > Windows Logs > right click System > Save All Events As...
  6. Specify a location for the System Logs.evtx file > Save.
  7. Choose: Display information for these languages > English > OK.