Windows Defender Advanced Threat Protection log file

David Brown 66 Reputation points
2022-08-31T13:01:56.963+00:00

The log file for Defender ATP is filling up my C Drive on one of my Windows servers, it is 27Gb.

Location C:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection\Temp

Is there any way to configure what is logged, and/or a max size for the log file?

Windows for business | Windows Server | User experience | Other
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Wesley Li-MSFT 4,576 Reputation points Microsoft External Staff
    2022-09-02T09:17:40.603+00:00

    Hi anonymous user-2419

    Thank you for posting your question to Microsoft Q&A forum.

    How did you configure your Windows Defender Advanced Threat Protection? SCCM? Intune?

    You can also try contacting Microsoft Defender for Endpoint support:
    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/contact-support?view=o365-worldwide

    Best Regards,
    Wesley Li

    0 comments No comments

  2. Limitless Technology 39,931 Reputation points
    2022-09-05T07:35:02.897+00:00

    Hi,

    Windows defender files will appear in disk clean up if you click the clean up system files option. This will tidy it up for now.

    There’s no configuration options for what’s logged but if it’s producing so many logs, there’s likely to be something wrong. Have you checked the logs to see if you can remove files or change something else on the server to prevent them being created in the first place?

    I hope this answers your question.

    -------------------------------------------------------------------------------------------------------------------------------------

    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments

  3. Wesley Li-MSFT 4,576 Reputation points Microsoft External Staff
    2022-09-20T07:38:10.467+00:00

    Hello

    Do you have any other questions?

    If the above reply is helpful to you, please mark it as answer.

    Thanks


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.