Log files

Log files contain information about all important program events that have occurred and provide an overview of detected threats. Logs are an essential tool in system analysis, threat detection and troubleshooting. Logging is performed actively in the background with no user interaction. Information is recorded based on the current log verbosity settings. It is possible to view text messages and logs directly from the ESET Endpoint Antivirus environment. It is also possible to archive log files.

Log files are accessible from the main program window by clicking Tools > Log files. Select the desired log type from the Log drop-down menu. The following logs are available:

Detected threats – The threat log offers detailed information about infiltrations detected by ESET Endpoint Antivirus modules. The information includes the time of detection, name of infiltration, location, the performed action and the name of the user logged in at the time the infiltration was detected. Double-click any log entry to display its details in a separate window.
Events – All important actions performed by ESET Endpoint Antivirus are recorded in the event log. The event log contains information about events and errors that have occurred in the program. It is designed to help system administrators and users resolve problems. Often the information found here can help you find a solution for a problem occurring in the program.
Computer scan – All scan results are displayed in this window. Each line corresponds to a single computer control. Double-click any entry to view the details of the respective scan.
HIPS – Contains records of specific rules that are marked for recording. The protocol shows the application that called the operation, the result (whether the rule was permitted or prohibited) and the name of the rule created.
Filtered websites – This list is useful if you want to view a list of websites that were blocked by Web access protection. In these logs you can see the time, URL, user and application that opened a connection to the particular website.
Device control – Contains records of removable media or devices that were connected to the computer. Only devices with a Device control rule will be recorded to the log file. If the rule does not match a connected device, a log entry for a connected device will not be created. Here you can also see details such as device type, serial number, vendor name and media size (if available).

In each section, the displayed information can be copied to the clipboard (keyboard shortcut Ctrl + C) by selecting the entry and clicking Copy. The Ctrl and Shift keys can be used to select multiple entries.

Click MODULE_INACTIVE Filtering to open the Log filtering window where you can define the filtering criteria.

You can bring up the context menu by right-clicking a specific record. The following options are available in the context menu:

Show Shows more detailed information about the selected log in a new window.
Filter same records – After activating this filter, you will only see records of the same type (diagnostics, warnings, ...).
Filter.../Find... – After clicking this option, the Search in log window will allow you to define filtering criteria for specific log entries.
Enable filter – Activates filter settings.
Disable filter – Clears all filter settings (as described above).
Copy/Copy all – Copies information about all the records in the window.
Delete/Delete all – Deletes the selected record(s) or all the records displayed – this action requires administrator privileges.
Export... – Exports information about the record(s) in XML format.
Export all... – Export information about all records in XML format.
Scroll log – Leave this option enabled to auto scroll old logs and view active logs in the Log files window.