Have you checked ‘CIS>Miscellaneous>Settings>Logging’ and ensured that ‘disable Defense+ logging’ is not ticked?
Did you receive any Defense+ alerts today, which you have blocked?
Defense+ will not log anything when ‘safe’ programs are executed. Defense+ will log only when you block an application from executing or if you have already given a rule to block an application in ‘Computer Security Policy’ and that application tries to execute.
To check your defense+ logging… Open CIS>Defense+>Advanced>Computer Security Policy delete the application rule for a program and then run the application
When defense+ gives an alert… block it and see if it gets logged in …
Yes, I try experiment. When I have alerts and block it manually, then this message append to logfile.
Defense+ will not log anything when 'safe' programs are executed. Defense+ will log only when you block an application from executing or if you have already given a rule to block an application in 'Computer Security Policy' and that application tries to execute.
After any experiments I see that you right. And now I'm understood this, but why D+ log ONLY blocked request? Iin my opinion this have not any logic.