EDR: How to Collect Sensor Diagnostics Logs for Troubleshooting
search cancel

EDR: How to Collect Sensor Diagnostics Logs for Troubleshooting

book

Article ID: 285991

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

Collect EDR sensor diagnostics for general troubleshooting. This guide should be used for:
  • General connectivity problems with the server
    • Sensors that are on appearing as offline
    • Sensors that never appeared in the console
  • Missed or Delayed data collection
  • Installation issues while the service is running

Environment

  • EDR Sensor: All Versions (formerly CB Response)
  • Microsoft Windows
  • Linux
  • macOS

Resolution

Follow steps below for a given OS platform to collect sensor diagnostics

Windows

Collection TypeLink
General DiagnosticsEDR: How to Collect Windows Sensor Diagnostic Logs (6.2.2+)
General Diagnostics for Legacy OS's on 6.1.13EDR: How to Collect Windows Sensor Diagnostic Logs (6.1.13)
Verbose Debug Level for Reproducible issuesEDR: Enable Verbose Debug Logging Locally on Windows sensor
EDR: Enable Verbose Debug Logging Remotely on Windows Sensor
Performance (CPU/Memory/Slowness)EDR: How to Collect Diagnostic Logs for Sensor Performance-Related Issues (Windows)
Sensor Not ConnectingEDR: How to Collect Diagnostic Logs for Sensor Connection Issues (Windows)
 
  • If a CB Protection Agent is installed, the CB Tamper Protect Updater must be disabled to gain read access to the Diagnostics folder on the Windows platform

MacOS

  • 6.1.3 and lower: https://community.carbonblack.com/t5/Knowledge-Base/Cb-Response-How-to-generate-Apple-MacOS-sensor-diag-report-6-1-3/ta-p/62912
  • 6.2 and higher: https://community.carbonblack.com/t5/Knowledge-Base/Cb-Response-Generate-Apple-MacOS-Sensor-diag-report-in-6-2-x-and/ta-p/62181

Linux

  • https://community.carbonblack.com/t5/Knowledge-Base/Cb-Response-How-to-gather-Linux-sensor-diagnostics/ta-p/48672