Forum Discussion

Kapildev_C's avatar
Kapildev_C
Copper Contributor
Dec 25, 2023

Investigate the exported logs

Hi,

I have exported timeline logs of the offboarded machine to investigate the unusual activity and it was almost 2 months ago. So now I need to investigate the logs of the machine and it is a little hectic to work on Excel to identify the malicious activity. Is there any option available to upload the logs to Defender to investigate? Or any other tool will be helpful.

6 Replies

  • rahuljindal's avatar
    rahuljindal
    Bronze Contributor
    Depending on the nature of your investigation, you can try advanced hunting queries.
    • Kapildev_C's avatar
      Kapildev_C
      Copper Contributor

      It's been more than 30 days so unable to fetch logs of the machine. Is there any other option to investigate?

      • rahuljindal's avatar
        rahuljindal
        Bronze Contributor

        Is the device still connected to the internet? Also, if it is offboarded then options become limited. Can you perhaps elaborate on the unusual activity and the current status of device in question?