Environment
- Carbon Black Cloud Windows Sensor: 3.0 and above
- Windows OS: All Supported Versions
Objective
Introuduce how to check CBC blocking events in Windows Event Viewer
Resolution
- Open Event Viewer
- Go to Windows Logs -> Application
- Search for "CbDefense" or "Carbon Black", and you will see blocking events from CBC.
OR
- Open Event Viewer
- Go to Windows Logs -> Application
- Under "Actions" menu select "Filter Current Log..."
- In the Event Sources drop down select "CbDefense" to view only Cb Defense Events
Additional Notes
Search "CbDefense" in Event View can also give you CBC related events like service start, service stop, background scan, etc.
Related Content