CRS Logging & Troubleshooting

This topic provides information about CRS logs.

Periodic Event and Policy Logging

CRS periodically records runtime activity statistics in its logs.
The statistics are written every minute and include the following information.

  • Network event count
  • File event count
  • Process event count
  • Number of active policies

Benefits

With the CRS logs, you can,

  • Monitor runtime activity
  • Verify policy deployment
  • Troubleshoot event processing
  • Analyze sensor workload

Example 

See an example of a CRS log.

2026-02-25T13:26:43.682Z INFO Event counts - Network: 0, File: 12, Process: 5. Number of active Policies: 1

Shutdown Summary Logging

When CRS shuts down gracefully, it records a summary of the total events processed during the sensor session.
Example

2026-02-25T13:26:55.119Z INFO Event counter logger stopped. Final counts - Network: 0, File: 12, Process: 5, Number of last active Policies: 1

The shutdown summary is generated only when CRS exits gracefully.