Forum Discussion
Kapildev_C
Dec 25, 2023Copper Contributor
Investigate the exported logs
Hi,
I have exported timeline logs of the offboarded machine to investigate the unusual activity and it was almost 2 months ago. So now I need to investigate the logs of the machine and it is a little hectic to work on Excel to identify the malicious activity. Is there any option available to upload the logs to Defender to investigate? Or any other tool will be helpful.
6 Replies
- rahuljindalBronze ContributorDepending on the nature of your investigation, you can try advanced hunting queries.
- Kapildev_CCopper Contributor
It's been more than 30 days so unable to fetch logs of the machine. Is there any other option to investigate?
- rahuljindalBronze Contributor
Is the device still connected to the internet? Also, if it is offboarded then options become limited. Can you perhaps elaborate on the unusual activity and the current status of device in question?