Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

App Control: Collecting Logs Remotely for Troubleshooting Server (High Debug)

App Control: Collecting Logs Remotely for Troubleshooting Server (High Debug)

Environment

  • App Control Server: All Supported Versions

Objective

To remotely collect high debug logs for troubleshooting the App Control Server.

Resolution

  1. Gather the following information:
    • What is the OS version and build of the application server where the App Control Server is installed?
    • What is the total system memory of the application server?
    • What is the total free disk space on the drive App Control Server is installed on?
    • What version of the App Control Server is currently installed?
    • Is the SQL database located on the same server as the App Control Server?
    • What version of SQL Server is hosting the App Control database? Is it patched to the latest Cumulative Update?
    • What is the maximum memory set for SQL Server?
    • What error message or events are you receiving regarding this issue?
    • When did the error messages/events/issue start?
    • Were there any new changes on the server(s) or the network recently?
  2. Collect High Debug App Control Server logs:
    1. Log in to the App Control Console and navigate to https://ServerAddress/support.php > Diagnostics
    2. Click the Snapshot Server Logs button to write existing logs and start a fresh log file.
    3. Set Server Logging as follows:
      • Logging Duration: 30 Minutes
      • All Debug Levels: High
      • Enable SQL Trace
    4. Click Start logging & reproduce the issue.
    5. Return to https://ServerAddress/support.php > Diagnostics
    6. Click "Stop Logging Now"
    7. Click on “Available log files" from the right menu > Related Views > Save files:
      API-TIMESTAMP.log
      AppControlAD-TIMESTAMP.log
      ReporterLog-TIMESTAMP.log
      ServerLog-TIMESTAMP.bt9
      SQLTrace-date-time.csv
  3. Collect the Windows Application and Windows System logs.
  4. Collect the most recent IIS Logs.
  5. Upload the collected logs to the Vault and provide an update on the relevant Support Case.

Additional Notes

  • App Control Server 8.8.6 and earlier: Restart the App Control Reporter service due to a known issue causing it to stop sending events after debugging finishes.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎01-24-2019
Views:
6275
Contributors