search
cancel
Search
How to collect a Procmon for Boot/Login Sensor Performance
book
Article ID: 287955
calendar_today
Updated On:
Feedback
Subscribe
Products
Carbon Black EDR (formerly Cb Response)
Show More
Show Less
Issue/Introduction
How to collect a Procmon capture for performance issues related Boot or Login with the CB EDR sensor
Environment
Carbon Black EDR Sensor: All Versions
Microsoft Windows: All Supported Versions
Resolution
Download the latest Process Monitor (Procmon) from sysinternals
https://docs.microsoft.com/en-us/sysinternals/downloads/procmon
Unzip and place Procmon in an easy to find location
Open Procmon and Press Ctrl+E to stop the capture
Go to Options > Enable Boot Logging > Generate Thread Profiling every second
Go to Filter and uncheck the filtering "Process Name is System"
Reboot the machine
After the machine has come up, open Procmon immediately. Save what was captured
Save the file as .PML
Zip the PML file before sending, they compress well.
Upload the capture to the case
Additional Information
Sensor Diagnostics
will need to be captured along with the Procmon capture
See
this
document for other performance issues
Do not put any additional filters in place
When reviewing the data, make sure to add the "Duration" Column and filter by "Duration more than 1" second to help narrow down where the issue may be
Feedback
thumb_up
Yes
thumb_down
No