Gather logs for Windows Sensor version 6.1.13 and lower
book
Article ID: 288104
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
How to collect logs and other diagnostics for the EDR Windows Sensor 6.1.13 and lower.
Environment
- EDR Windows Sensor: 6.1.13 and lower
- Windows OS: All supported versions
Resolution
- Download the attached zip file and extract the cbDiag.exe file.
- Open Windows Command Prompt (cmd.exe)
- Run cbdiag.exe with admin permissions
- Press Enter or 0 to select "Take a new diag" option
Sample Output:
Additional Information
CbDiag.exe /?
- The resulting file is generated in the same directory as the cbdiag.exe utility.
- Resulting file name format: <date-time>.diag.gz
- Administrator permissions require access to system file paths and registry keys.
- Disable Tamper Protect Updater if App Control is installed.
- If applicable, locally approve the utility hash within your App Control Web UI
MD5 of CbDiag.exe: 469c78f4a4664b11be1a7641afec2214
Data collected:
- Basic System Information
- Carbon Black product logs
- System event logs
- System Crash dumps
- Product registry keys
- System registry keys related to crash dumps
- Product binary information
- Running system drivers and processes
- Installed system services, hardware, software
Feedback
thumb_up
Yes
thumb_down
No