CRS Logging & Troubleshooting
This topic provides information about CRS logs.
Periodic Event and Policy Logging
CRS periodically records runtime activity statistics in its logs.
The statistics are written every minute and include the following information.
- Network event count
- File event count
- Process event count
- Number of active policies
Benefits
With the CRS logs, you can,
- Monitor runtime activity
- Verify policy deployment
- Troubleshoot event processing
- Analyze sensor workload
Example
See an example of a CRS log.
2026-02-25T13:26:43.682Z INFO Event counts - Network: 0, File: 12, Process: 5. Number of active Policies: 1
Shutdown Summary Logging
When CRS shuts down gracefully, it records a summary of the total events processed during the sensor session.
Example
2026-02-25T13:26:55.119Z INFO Event counter logger stopped. Final counts - Network: 0, File: 12, Process: 5, Number of last active Policies: 1
The shutdown summary is generated only when CRS exits gracefully.