Endpoint system logs

The endpoint system log includes system user change log, system group change log, system log, system state change log, and user login/logout log.

System user change logs

The system user change log records system user name changes.

To view system user change logs:

  1. From the left navigation pane, select Policies > Behavior Policies > Logs > Endpoint System Logs.

  1. Click the System User Change Logs tab.

The page that opens displays the system user change logs.

To filter the system user change logs, specify the filtering criteria. You can export the displayed logs on the page.

System group change logs

The system group change log records system group changes on endpoint OSs.

To view system group change logs:

  1. From the left navigation pane, select Policies > Behavior Policies > Logs > Endpoint System Logs.

  1. Click the System Group Change Logs tab.

The page that opens displays the system group change logs.

To filter the system group change logs, specify the filtering criteria. You can export the displayed logs on the page.

System logs

The system log records the system logs generated by endpoint OSs.

To view system logs:

  1. From the left navigation pane, select Policies > Behavior Policies > Logs > Endpoint System Logs.

  1. Click the System Logs tab.

The page that opens displays the system logs.

To filter the system logs, specify the filtering criteria. You can export the displayed logs on the page.

System state change logs

The system state change log records endpoint OS state changes, such as shutdown, boot, unexpected shutdown, hibernation, and wakeup.

To view system state change logs:

  1. From the left navigation pane, select Policies > Behavior Policies > Logs > Endpoint System Logs.

  1. Click the System State Change Logs tab.

The page that opens displays the system state change logs.

To filter the system state change logs, specify the filtering criteria. You can export the displayed logs on the page.

User login/logout logs

The user login/logout log records user logins and logouts, and domain login and logouts.

To view user login/logout logs:

  1. From the left navigation pane, select Policies > Behavior Policies > Logs > Endpoint System Logs.

  1. Click the User Login/Logout Logs tab.

The page that opens displays the user login/logout logs.

To filter the user login/logout logs, specify the filtering criteria. You can export the displayed logs on the page.