USB device logs #169
-
Hi guys, |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 5 replies
-
Hi @barakaldes! USB device events can be consumed using the Falcon Data Replicator (FDR) project. (Please note: the Event Streams API will contain policy changes but not USB device events.) More details on using Falcon Data Replicator can be found in the CrowdStrike documentation repository. Hope this helps! 😄 |
Beta Was this translation helpful? Give feedback.
-
@barakaldes - The USB events are located in the 'Data' folder events. You'll need to decompress them to start and then you can determine what event types they are. The Events Data Dictionary in the Falcon UI (see link above) can help you identify the event types that you're looking for (search for events starting with DcUsb) |
Beta Was this translation helpful? Give feedback.
@barakaldes - The USB events are located in the 'Data' folder events. You'll need to decompress them to start and then you can determine what event types they are. The Events Data Dictionary in the Falcon UI (see link above) can help you identify the event types that you're looking for (search for events starting with DcUsb)