Collect Historical Server Logs
search cancel

Collect Historical Server Logs

book

Article ID: 291669

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Steps to collect historical (non debug) App Control Server logs.

Environment

  • App Control Server: All Supported Versions
  • Microsoft Windows Server: All Supported Versions
  • Microsoft Internet Information Services (IIS): All Supported Versions

Resolution

Step 1: Gather Relevant Background Information

  • What is the OS version and build of the application server where the App Control Server is installed?
  • What is the total system memory of the application server?
  • What is the total free disk space on the drive App Control Server is installed on?
  • What version of the App Control Server is currently installed?
  • Is the SQL database located on the same server as the App Control Server?
  • What version of SQL Server is hosting the App Control database? Is it patched to the latest Cumulative Update?
  • What error message or events are you receiving regarding this issue?
  • When did the error messages/events/issue start?
  • Were there any new changes on the server(s) or the network recently?

Step 2: Gather Event Viewer and IIS Logs

Collecting IIS Logs

Collecting Event Viewer logs

Step 3: Gather App Control Server Logs

Method 1: Remotely From the Console

  1. Log in to the App Control Console.
  2. Browse to: https://ServerAddress/support.php
  3. Go to the Diagnostics tab > Click on "Snapshot Server Logs".
  4. From the right-hand menu > Related Views > Click on “Available log files".
  5. Save copies of the files with today's Request Date and the File Name:
    • PHPErrors-TIMESTAMP.log
    • ReporterLog-TIMESTAMP.log
    • ServerLog-TIMESTAMP.bt9

Method 2: Locally from the App Control Server

  • Log in to the App Control Server as the Carbon Black Service Account.
  1. Collect a copy of the following files from the Parity Server directory:
    • C:\Program Files (x86)\Bit9\Parity Console\WebUI\Logs\php_errors.log
    • C:\Program Files (x86)\Bit9\Parity Server\Reporter\ParityReporter.log
    • C:\Program Files (x86)\Bit9\Parity Server\ServerLog.bt9
  2. Collect a copy the most recent automatic log captures:
    • C:\Program Files (x86)\Bit9\Parity Server\Support\API-TIMESTAMP.log
    • C:\Program Files (x86)\Bit9\Parity Server\Support\PHPErrors-TIMESTAMP.log
    • C:\Program Files (x86)\Bit9\Parity Server\Support\ReporterLog-TIMESTAMP.log
    • C:\Program Files (x86)\Bit9\Parity Server\Support\ServerLog-Auto-TIMESTAMP.bt9
    • C:\Program Files (x86)\Bit9\Parity Server\Support\SQLTrace-TIMESTAMP.log