Logs and other useful output
Logs are often a great source of information to find out whether everything is going well – or what went wrong.
Useful logs
Here are some of the most useful MDE logs:
- Windows:
C:\Windows\Temp\MpSigStub.log
: This is the update log for Windows DefenderC:\ProgramData\Microsoft\Windows Defender\Support
contains various useful logs – particularly,MPLog
can tell you a lot about what Windows Defender is up to
In the Windows event logs, the following locations are useful sources of information as well:
Microsoft-Windows-SENSE/Operational
: EDR sensor eventsMicrosoft-Windows-Windows Defender/Operational
: Protection events
- Linux:
/var/log/microsoft/mdatp/
: This is the default log output folderinstall.log
contains information about the installationMicrosoft_defender_core_err.log
contains error output logging
- macOS:
/Library/Logs/Microsoft/mdatp/
: This is the default log output folderinstall.log
contains...