How to export event logs in ThreatLocker?

This document outlines the step-by-step process of how to export event logs in ThreatLocker Dashboard.

This article is a part of our ThreatLocker How-to Guides series, Chapter 10 – Monitoring, Logs and Reports.

Introduction

ThreatLocker allows you to export event logs from the Unified Audit for reporting, investigation, or record-keeping purposes. Exporting logs to a CSV file lets you analyze and store them outside of the portal.

Implementation

Step 1: Locate the Log You Want to Export

  1. Log in to the ThreatLocker Portal.
  2. Navigate to Unified Audit from the left-hand menu.
  3. Use the Filter options to find the logs you want:
  • Set Start Date and End Date.
  • Apply additional filters such as Action, Action Type, or Application Name if needed.
  • Click Search to display the results.
export event logs in ThreatLocker

Step 2: Export the Log

  1. Click the Export Logs button in the top-right corner of the page.
export event logs in ThreatLocker

2. The system will generate a CSV file, which will be downloaded automatically to your device.

export event logs in ThreatLocker

Conclusion

Exporting logs from the Unified Audit in ThreatLocker is quick and straightforward. This feature ensures you can easily share, archive, or analyze security events outside the ThreatLocker platform.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top