How to Read Logs: Antivirus Detection

First thing's first – AV detection is a monitor so don't try to audit the device as a troubleshooting step, as it likely won't change anything

 

You can find AV checks in the logs by searching "built" or "antivirus" within AEMAgent.log. They will look similar to the below:

12.7.0.1113|2024-02-02T14:09:20.030-05|INFO|POLL|{ "logcontext": "Monitoring.Program", "membername": "handler", "httpStatusCode": 200, "definitionName": "AntiVirus", "monitorId": "BUILT-IN", "json": "{\"avProduct\":\"Carbon Black Cloud\",\"avUpToDate\":true,\"avRunning\":true,\"avSource\":\"SecurityCenter\",\"scDisplayName\":\"Carbon Black Cloud\",\"scProductExe\":\"%ProgramFiles%\\\\Confer\\\\RepWAV.exe\",\"scReportingExe\":\"C:\\\\Program Files\\\\Confer\\\\RepWSC.exe\",\"scProductExeDescription\":\"Carbon Black Cloud Sensor AV Remediation x64\",\"scProductExeVersion\":\"3.6.0.2076\",\"scProductExeProductName\":\"Carbon Black Cloud Sensor\",\"scProductExeProductVersion\":\"3.6.0.2076\",\"scReportingExeDescription\":\"Carbon Black Cloud Sensor Security Center Service x64\",\"scReportingExeVersion\":\"3.6.0.2076\",\"scReportingExeProductName\":\"Carbon Black Cloud Sensor\",\"scReportingExeProductVersion\":\"3.6.0.2076\",\"scRunning\":true,\"scUpToDate\":true}" }

 

Useful things to note:
 

  • Make sure the "definitionName" is "Antivirus" and POLL is present in the log entry to be sure you're actually looking at an AV check. "Antivirus" comes up in other log entries that may not be relevant
  • If no AV is found, you will see "DELETE" as the reading, indicating nothing was found and the agent is telling the platofrm to delete any prior AV info
  • Note the "avSource" section. This will read one of three things:
  • The order of detection is override first, then native detection, then security center
  • Server OS's do not typically have Security center, so if AV detection is working on many devices but not finding anything on servers, this could be because the AV is not natively detected and is only reporting on the working devices because of Security Center

Have more questions?

Contact us

Was this article helpful?
0 out of 0 found this helpful

Provide feedback for the Documentation team!

Browse this section