Download SymDiag to detect product issues
search cancel

Download SymDiag to detect product issues

book

Article ID: 155115

calendar_today

Updated On:

Products

Advanced Threat Protection Platform Data Center Security Server Data Insight for DLP Data Loss Prevention Endpoint Encryption Endpoint Protection Endpoint Protection Small Business Edition (Cloud) Endpoint Protection Cloud Information Centric Tagging Protection Engine for NAS Protection Engine for Cloud Services Cloud Secure Web Gateway - Cloud SWG Symantec Identity Security Platform - IDSP (formerly VIP Authentication Hub) Generic Non Product Support Portal Global Customer Assistance

Issue/Introduction

Download and learn about SymDiag The Symantec Diagnostic Tool which identifies common issues and gathers data / logs for support-assisted troubleshooting.

This article contains information about Version 2 of SymDiag.  For SymDiag Version 3, click here.

Environment

Use SymDiag Version 2 (v2) for products listed in this table.

Endpoint SecurityInformation SecurityNetwork SecurityAdditional Products
  • Endpoint Protection 14.3.x
  • Endpoint Security 14.3.x
  • Endpoint Encryption
  • Encryption Powered by PGP
  • Enterprise Agent
  • Data Center Security Agent
  • Protection Engine
  • Advanced Threat Protection (Linux)
  • Data Loss Prevention 11.0 and later
  • Web Cloud Protection
  • Web Gateway
  • Web Security Service
  • Unified Agent/Web Security Service Agent
  • Optical Character Recognition
  • Auth Connector
  • Authentication and Authorization Agent
  • Data Insight
  • Information Center Analytics
  • Information Centric Tagging
  • Mail Security for Microsoft Exchange 6.5.2 and later*
  • Management Platform
  • VIP Access



For products listed below, visit the SymDiag Version 3 (v3) article.

Endpoint SecurityInformation SecurityNetwork SecurityAdditional Products
  • Endpoint Security Agent v2.5
  • Endpoint Protection 16 (SEP 16)
  • Endpoint Protection 14.3.x
  • Endpoint Security 14.3.x
  • Protection Engine Agent and Console
  • Data Loss Prevention
  • Cloud SWG v10
  • WSS
 

 

Additional Notes

  • Both SymDiag v2 and v3 can be used to gather data for Endpoint Protection 14.3.x and Endpoint Security 14.3.x.

Resolution

 

Download SymDiag

SymDiag for Windows (2.1.324.11293)

  1. Download SymDiag for Windows.
    Save the file to the Windows desktop.
  2. On the Windows desktop, double-click the SymDiag.exe icon.
  3. Follow the on-screen instructions or consult the Table of Contents below to find further instructions for using SymDiag depending on what you want to accomplish with SymDiag

SymDiag for Linux (2.1.11285)

DLP

Use SymDiag.run for gathering data for the DLP linux agent.  For the SEP/SES/DCS Linux agent, see the next section.

  1. Download SymDiag for Linux.
    Right-click this link and choose "Save Target As" or "Save Link As".
  2. Save SymDiag.run to a directory on the computer. 
  3. Mark the file as executable to run as superuser 
    sudo chmod +x ./symdiag.run
    sudo ./symdiag.run
  4. Follow the on-screen instructions

SEP/SES/DCS Linux Agent 

Use the built-in Get Agent Info script to collect SEP, SES or DCS agent logs.  For DLP linux agents, use SymDiag.run (above)

Run the following command from a terminal:

cd /opt/Symantec/sdcssagent/IPS/tools; ./getagentinfo.sh

SymDiag for macOS

SymDiag for macOS is not available. Instead, download one of the following:

  1. Download wssa-diag.sh for issues with WSS Agent or Unified Agent
  2. Download GatherSymantecInfo for issues with other Symantec products

Diagnostic .cloud for Edge Secure Web Gateway (formerly ProxySG)

Additional diagnostic resources are available at Diagnostic .cloud for the following Network Protection products:

  • Edge Secure Web Gateway (formerly ProxySG)

 

About SymDiag

The Symantec Diagnostic Tool (SymDiag) is a multi-product, multi-language diagnostic, and security analysis utility. SymDiag provides self-help support for Symantec product technical issues, zero-day threat analysis, best practice recommendations, and proactive services to customers.

If you require further assistance, SymDiag lowers the level of effort and increases efficiency by automating data gathering and support case submission.

Supported products

See the Environment section of this article for Supported products.

Supported operating systems

Windows

SymDiag runs on the same Windows operating systems that Symantec products that function with SymDiag support.

On Windows 2008 R2 Server Core, run SymDiag with the following command-line switch:

-net2

Command-line and remote deployment

SymDiag comes with many command-line parameters, and you can remotely deploy SymDiag.

Self-help reporting

Before contacting Support, you can identify Symantec product issues, licensing status and identify best-practice configurations of your Symantec product. You can also attempt to identify suspicious files and start an investigation into whether they are zero-day threats.

Proactive Services - Best Practice Reporting

Threat Analysis Scan

Licensing Dashboard

Data collection for Support

You can run SymDiag on computers to produce self-help solutions, as well as collect data for support cases with Symantec.

Debug Logging

Delivering data to Support

Use SymDiag to gather data on relevant computers for support cases with Symantec. SymDiag lets you deliver that data directly into a new or existing support case.

Windows Root Certificate Requirement

SymDiag requires a root certificate to be auto installed by the Windows OS and that the OS supports SHA-2 code signing certificates.

If these requirements are not met, SymDiag will display an error message of "Failed to launch Symantec Diagnostic Tool".

This issue can be resolved by following the steps in the article Failed to launch Symantec Diagnostic Tool.

SymDiag Viewer for Windows

Current Version: 2.1.324.11291

  1. Download SymDiag Viewer for Windows.
    Save the file to the Windows desktop.
  2. On the Windows desktop, double-click the SymDiagViewer.msi icon.
  3. Follow the on-screen instructions to install the SymDiag Viewer
  4. Double click on any *.sdbz file and the file will be opened in the SymDiag Viewer

Related terms: symhelp, symhelpexe, symantec help

Additional Information

Release Notes

Build 2.1.324.11293 (02/07/2025) - SymDiag

KeyComponent/sSummary
SUPOPS-1608SEPSEP SDS defs are listed twice in the definition report
SUPOPS-1610SEPCollect ccSettings GEH sections
SUPOPS-1581SymDiagRemove Licensing Overview Panel information
SUPOPS-1583SymDiagIdentify Server 2025
SUPOPS-923WSSEnsure windows capture driver loaded for netsh

Build 2.1.324.11291 (02/07/2025) - Viewer

KeyComponent/sSummary
SUPOPS-1082SEPM Config ReviewUpdate SONAR high risk detection information
SUPOPS-1581ViewerRemove Licensing Overview Panel information

Build 2.1.322.11287 (08/19/2024)

KeyComponent/sSummary
SUPOPS-895SymDiagRemove debug message for download failure
SUPOPS-1104SymDiagNull value in ScDeviceGuard.SetDeviceGuard
SUPOPS-1093SymDiagRemove v2 reports that are not used in v3
SUPOPS-1359WSSPickup new files wss-agent-routing-*.log

Build 2.1.320.11285 (10/31/2023)

KeyComponent/sOSSummary
SUPOPS-880SymDiag, ViewerAllUnable to update to newer versions
SUPOPS-882SymDiagWindowsRemove uploading to a Wolken case
SUPOPS-869ViewerWindowsChange Viewer Menu location
SUPOPS-726SEP, SEPMWindowsUpdate version checking for 14.3 RU7 and RU8
SUPOPS-810PEWindowsUnable to detect PE if symcscan service ImagePath has -debug
SUPOPS-883DLPWindowsDatabase is locked error is logged after testing DLP Enforce password
SUPOPS-735DLPWindowsIncorrect version of DLP detected after upgrade

 

Build 2.1.318.11278 (06/14/2023)

KeyComponent/sOSSummary
SUPOPS-423SEDWindowsCollect the encryption status of PGP
SUPOPS-422SEEWindowsCollect the encryption status of SEE
SUPOPS-661SEPWindowsAdd additional logging details to the error "Unable to validate ccSettings database"
SUPOPS-700SEPWindowsAdd Edge Browser Extension related info
SUPOPS-725SEPWindowsAdd SETTDAD-TRAPS wpp provider with a default of disabled
SUPOPS-664SEPM Config ReviewWindowsProtection Overview has sections that only show 52 rows.  Display the full data in the Viewer.
SUPOPS-636SymDiagWindowsCapture native/wow64 registry key and values from ...\Windows NT\CurrentVersion\AeDebug

 

Build 2.1.316.11253 (01/30/2023)

KeyComponent/sOSSummary
SUPOPS-632DLPWindowsUnable to parse DLP version from path that has a number in a sub directory
SUPOPS-627DLPWindowsCapture the Data Loss Prevention registry key and values
SUPOPS-580DLPLinuxUpdate for DLP 16 Linux release
SUPOPS-607DLP, ViewerWindowsUpdate Symantec articles in section 6.3.10 JAVA Memory Settings to a newer kb
SUPOPS-603DLP, ViewerWindowsOld Oracle server information
SUPOPS-604DLP, ViewerWindowsRemove Processor Speed findings for Enforce and Detection servers
SUPOPS-606SEPWindowsUpdate url responses for report checking if SEP Symantec servers are working.
SUPOPS-605SEPWindowsRemove 'Symantec Endpoint Protection (Small Business Edition)' entries from Search Kbs and Product landing sites
SUPOPS-585SEPMWindowsSEPM report for configured ports is incorrect for custom port
SUPOPS-619SMSMSEWindowsExchange build numbers of 15.x are  not mapped to correct Exchange versions
SUPOPS-608SymDiagWindowsCommand line option debuglog filepath does not create log file in filepath
SUPOPS-631SymDiagWindowsCollect all reg values from Windows NT\CurrentVersion 
SUPOPS-628SymDiagWindowsPickup the latest etl2pcapng
SUPOPS-609SymDiagWindowsNull exception in SelectProductVM.CheckMatchingProducts
SUPOPS-630SymDiagWindowsCollect HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders

Build 2.1.314.11248 (11/11/2022)

KeyComponent/sOSSummary
SUPOPS-601DLPWindowsUpdate System requirements for supported OSes
SUPOPS-602DLPWindowsUpdate versions for 16
SUPOPS-597SEP, SEPMWindowsUpdate for 14.3 RU6 release
SUPOPS-598SEP, SEPMWindowsUpdate System Requirements for newer versions of Windows
SUPOPS-299SEP, WSSWindowsCollect "verbose" data for NTR by default
SUPOPS-584SEP, WSSWindowsNTR trace logs not included if it is disabled
SUPOPS-595SEP, WSSWindowsWhen Ntr runs collection of ipconfig and nslookup, the command does not exist
SUPOPS-590SEP, WSSWindowsReport RHC_ProtectionStatus is not run when NTR is enabled
SUPOPS-589SEP, WSSWindowsBNS Connection is not collected when NTR is enabled
SUPOPS-600SEP, WSSWindowsIf NTR is installed and disabled, exception when checking pac file integrity is logged
SUPOPS-591SEP, WSSWindowsWssLatency is not collected when NTR is enabled
SUPOPS-599SEP, WSSWindowsIf NTR is installed and disabled, exception getting NTR latency is logged
SUPOPS-593SEP, WSSWindowsChange Latency results from a text file to a DbVar and display in view ...\Other Data\Latency
SUPOPS-588SEPM Config ReviewWindowsAdd Windows Vista to Config Review's Legacy Windows report
SUPOPS-499SymDiagLinuxCollect Linux commands into a table for setting up SUDO permissions

Build 2.1.312.11245 (10/04/2022)

KeyComponent/sOSSummary
SUPOPS-583SEPWindowsScan hangs if xml value is not found when running GetPolicyClientControlMode
SUPOPS-514SEPWindowsWPP logging fails to initialize due to existing file
SUPOPS-507SEPWindowsDisplay Final GEH exceptions from ccSettings as a list
SUPOPS-568SEPWindowsAdd SETDAD_MINIDM_WPP_GUID to WPP list
SUPOPS-570SEPWindowsCollect SEPInstallTraceSession.etl for SEP Windows
SUPOPS-579SEPWindowsCloud Client warns that feature is in mixed mode
SUPOPS-578SEPWindowsException in WtrInformation when accessing database in background thread
SUPOPS-582SEP,SEPMWindowsUpdate version for Sep 14.3 RU5 (Refresh 2) release
SUPOPS-365SEPMWindowsSEPM Top 5 intrusion query errors with an arithmetic overflow error converting expression to data type int
SUPOPS-553SMSMSEWindowsCollect permissions for folders and registry
SUPOPS-552SMSMSEWindowsUpdate for SMSE 7.09 and 7.10
SUPOPS-565SMSMSEWindowsAdd SMSMSE Quar Admins to Console Permission report checks
SUPOPS-566SMSMSEWindows.Net v4.8 is reported as an error for SMSMSE requirements report
SUPOPS-540SPEWindowsAdd CSAPI logging to SPE Windows
SUPOPS-535SPEWindowsAdd WPP logging to SPE Windows
SUPOPS-554SymDiagWindowsException in Symantec.Diag.Ui.Net3.AppUi3..cctor
SUPOPS-557SymDiagWindowsIf SymDiag is running in silent mode and it is not able to verify the certificates, a UI error is displayed
SUPOPS-555SymDiagWindowsUpdate copyrights
SUPOPS-574SymDiagWindowsException when parsing SID names

Build 2.1.310.11238 (08/11/2022) 

KeyComponent/sOSSummary
SUPOPS-538SEPWindowsException if Cloud Server connection, but no cloud policies
SUPOPS-533SEPWindowsSEP 14.3 RU5 Cloud API to get policies fails
SUPOPS-551SEPWindowsSymDiag does not collect debug and wpp logs when using the -s -enable command line options
SUPOPS-530SEP, SEPMWindowsAdd 14.3 RU5 refresh as new version for SEP
SUPOPS-503SEPMWindowsError converting data type nvarchar to numeric when collecting information about a sep client
SUPOPS-527SPEWindowsUpdate SPE OS requirements for System Requirements report
SUPOPS-542SPEWindowsCollect Stargate logs for v8.2
SUPOPS-543SPEWindowsFor service report, remove symcmicrodefsmgr if 8.2 or greater
SUPOPS-544SPEWindowsRemove 7.8 from install requirement strings
SUPOPS-545SPEWindowsRemove excess spaces from PE's file version
SUPOPS-546SPEWindowsCollect Common Agent Framework files
SUPOPS-528SPEWindowsUpdate SPE supported versions for latest version report
SUPOPS-532SymDiagWindowsCollect Internet Settings from the registry
SUPOPS-550WSSWindowsThe WSS SSL Root Certificate report incorrectly reports that the certificate is not installed if more than 1 certificate is installed

Build 2.1.308.11236 (06/21/2022) 

KeyComponent/sOSSummary
SUPOPS-530SEP, SEPMWindowsAdd 14.3 RU5 as new version for SEP.  NOTE: 2.1.308 is required for full support of SEP 14.3 RU5.  Earlier versions may not collect all SEP data, have report errors and not enable SEP debugging.

Build 2.1.308.11235 (06/07/2022) 

KeyComponent/sOSSummary
SUPOPS-153DLPWindowsDLP Agent enable / disable FINEST logging
SUPOPS-484DLPWindowsAdd etw guids for vrtam.sys and vnwcd.sys
SUPOPS-520DLP, ViewerWindowsUpdate Enforce Oracle Server version information in config review
SUPOPS-510SEDWindowsLatest versions of Endpoint Encryption and Encryption Desktop
SUPOPS-525SEEWindowsWin Server 2019 is reported as not supported for see
SUPOPS-524SEEWindowsEndpoint Encryption Management Server reports CLRtypes not installed when they are.
SUPOPS-470SEPWindowsCollect additional hardening files for RU4
SUPOPS-513SEPWindowsUnexpected installation report error
SUPOPS-526SEPWindowsSymDiag exits while running ScCloudPolicyVersions script command
SUPOPS-495SEPWindowsChange how SEP Information Features are displayed.  Now shown as Features and as Protections
SUPOPS-489SEPWindowsParse SEP 14.3 RU4 Application Hardening log (AsrMan.log)
SUPOPS-488SEPMWindowsProactive and Config Review report an error when checking on the latest version
SUPOPS-494SymDiagWindowsMSI Applications missing apps that are only in Uninstall key
SUPOPS-485SymDiagWindowsWhen Sql Server is not installed, try to collect install log files
SUPOPS-511SymDiagWindowsUpdate 3rd party software
SUPOPS-506WSSWindowsWSS Pac file is not downloaded

Build 2.1.306.11230 (02/07/2022) 

Issue keyComponentOSSummary
SUPOPS-478DLPWindowsUpdate DLP Version
SUPOPS-173DLPWindowsCollect Debug Output Strings for DLP
SUPOPS-447DLPWindowsUnable to identify Enforce version when installed to a custom directory
SUPOPS-459SEDWindowsSED 10.5 MP3 released
SUPOPS-479SEEWindowsUpdate SEE version
SUPOPS-458SEPWindowsCould not find a part of the path after saving the SBDZ
SUPOPS-464SEPWindowsSymDiag can crash if try to delete an invalid Common Client value
SUPOPS-476SEP, SEPMWindowsUpdate EP 14.3 RU4 version
SUPOPS-480SMSMSEWindowsUpdate SMSMSE Version
SUPOPS-477SymDiagWindowsUpdate Sql Server Versions

Build 2.1.304.11227 (01/27/2022) 

Issue keyComponentOSSummary
SUPOPS-468ViewerWindowsEO WebBrowser license error when using public decrypt server
SUPOPS-475SymDiag, ViewerWindowsNot able to connect with reputation server