Collect Historical Server Logs
book
Article ID: 291669
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Steps to collect historical (non debug) App Control Server logs.
Environment
- App Control Server: All Supported Versions
- Microsoft Windows Server: All Supported Versions
- Microsoft Internet Information Services (IIS): All Supported Versions
Resolution
Step 1: Gather Relevant Background Information
- What is the OS version and build of the application server where the App Control Server is installed?
- What is the total system memory of the application server?
- What is the total free disk space on the drive App Control Server is installed on?
- What version of the App Control Server is currently installed?
- Is the SQL database located on the same server as the App Control Server?
- What version of SQL Server is hosting the App Control database? Is it patched to the latest Cumulative Update?
- What error message or events are you receiving regarding this issue?
- When did the error messages/events/issue start?
- Were there any new changes on the server(s) or the network recently?
Step 2: Gather Event Viewer and IIS Logs
Collecting IIS Logs
Collecting Event Viewer logs
Step 3: Gather App Control Server Logs
Method 1: Remotely From the Console
- Log in to the App Control Console.
- Browse to: https://ServerAddress/support.php
- Go to the Diagnostics tab > Click on "Snapshot Server Logs".
- From the right-hand menu > Related Views > Click on “Available log files".
- Save copies of the files with today's Request Date and the File Name:
- PHPErrors-TIMESTAMP.log
- ReporterLog-TIMESTAMP.log
- ServerLog-TIMESTAMP.bt9
Method 2: Locally from the App Control Server
- Log in to the App Control Server as the Carbon Black Service Account.
- Collect a copy of the following files from the Parity Server directory:
- C:\Program Files (x86)\Bit9\Parity Console\WebUI\Logs\php_errors.log
- C:\Program Files (x86)\Bit9\Parity Server\Reporter\ParityReporter.log
- C:\Program Files (x86)\Bit9\Parity Server\ServerLog.bt9
- Collect a copy the most recent automatic log captures:
- C:\Program Files (x86)\Bit9\Parity Server\Support\API-TIMESTAMP.log
- C:\Program Files (x86)\Bit9\Parity Server\Support\PHPErrors-TIMESTAMP.log
- C:\Program Files (x86)\Bit9\Parity Server\Support\ReporterLog-TIMESTAMP.log
- C:\Program Files (x86)\Bit9\Parity Server\Support\ServerLog-Auto-TIMESTAMP.bt9
- C:\Program Files (x86)\Bit9\Parity Server\Support\SQLTrace-TIMESTAMP.log
Feedback
thumb_up
Yes
thumb_down
No