- Using dashboards
- Managing alerts across Cylance Endpoint Security services
- Managing users, devices, and groups
- Manage CylancePROTECT Desktop and CylanceOPTICS devices
- Manage zones
- Manage devices with the CylancePROTECT Mobile app
- Manage CylancePROTECT Mobile app and CylanceGATEWAY users
- View CylanceAVERT user details
- Manage user groups
- Configure device lifecycle management
- View a list of applications installed on CylancePROTECT Desktop devices
- Remove a registered FIDO device for a user account
- Discover unprotected devices
- Managing threats detected by CylancePROTECT Desktop
- Managing safe and unsafe lists for CylancePROTECT Desktop and CylancePROTECT Mobile
- Add a file to the CylancePROTECT Desktop global quarantine or global safe list
- Add a file to the CylancePROTECT Desktop local quarantine or local safe list
- Add a certificate to the CylancePROTECT Desktop global safe list
- Add an app, certificate, IP address, domain, or installer source to the CylancePROTECT Mobile safe or restricted list
- Analyzing data collected by CylanceOPTICS
- Using CylanceOPTICS to detect and respond to events
- Auditing administrator actions
- Managing logs
- Send events to a SIEM solution or syslog server
- Enable access to the Cylance User API
- Troubleshooting Cylance Endpoint Security
- Using the BlackBerry Support Collection Tool
- Using the Report a problem feature
- Removing the BlackBerry Connectivity Node software from Cylance Endpoint Security
- Troubleshooting CylancePROTECT Desktop
- Remove the CylancePROTECT Desktop agent from a device
- Re-register a Linux agent
- Troubleshoot update, status, and connectivity issues with CylancePROTECT Desktop
- A large number of DYLD Injection violations are reported by Linux devices
- Time zone variances for CylancePROTECT Desktop
- Folder exclusions when using CylancePROTECT Desktop with third-party security products
- Linux driver is not loaded. Upgrade the driver package.
- Troubleshooting CylanceOPTICS
- Managing threats detected by CylancePROTECT Mobile
- View mobile OS vulnerabilities
- Monitoring network connections with CylanceGATEWAY
- Monitoring sensitive files with CylanceAVERT
View the audit log
Audit log entries are retained in the management console for one year. After one year, audit log entries are purged automatically and can no longer be viewed. If you want to retain audit log entries, you can export the records to a .csv file, or you can forward events to a SIEM solution or syslog server (for more information, see the Cylance Syslog Guide).
- In the management console, click
>
Audit Log. - In the filter fields, specify the criteria that you want to use to filter the audit log information.
- To export the results to a .csv file, click
. Select the scope of the export and click
Export.You can export a maximum of 50,000 records at once. You can see the number of results at the bottom of the screen. To export more than 50,000 records, you can filter the results (for example, by date) and export, then apply a different filter and export, and so on.