EDR: Generate Apple macOS Sensor Diagnostic Logs
search cancel

EDR: Generate Apple macOS Sensor Diagnostic Logs

book

Article ID: 285743

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

Generate a cbdiag report for an Apple MacOS endpoint running EDR Sensor version 6.2.0 and later.

Environment

  • EDR Sensor: 6.2.0 and Higher
  • macOS: All Supported Versions

Resolution

  • 6.x OSX Sensor:
  1. Open the Terminal app
  2. Run:
sudo /Applications/CarbonBlack/sensordiag -type CDE
  1. Optionally, gather logs from a specified date and later:
sudo /Applications/CarbonBlack/sensordiag -type CDE -startdate 2018-06-29
  • 7.0.1+ OSX Sensor:
  1. Open the Terminal app
  2. Run:
sudo /Applications/VMware\ Carbon\ Black\ EDR.app/Contents/Helpers/sensordiag -type CDE
  1. Optionally, gather logs from a specified date and later:
sudo /Applications/VMware\ Carbon\ Black\ EDR.app/Contents/Helpers/sensordiag -type CDE -startdate 2018-06-29

Additional Information

  • Optional -startdate parameter format is YYYY-MM-DD.
  • The resulting file will be generated in the current working directory.
  • Sensor reports under 25 MB can be attached directly to a Carbon Black Technical Support case. 
  • Files larger than 25 MB should be uploaded to CB Vault.