Environment
- Carbon Black EDR (Formerly CB Response) Sensor: All Versions
- Microsoft Windows: All Supported Versions
Objective
How to collect a Procmon capture for performance issues related Boot or Login with the CB EDR sensor
Resolution
- Download the latest Process Monitor (Procmon) from sysinternals
- Unzip and place Procmon in an easy to find location
- Open Procmon and Press Ctrl+E to stop the capture
- Go to Options > Enable Boot Logging > Generate Thread Profiling every second
- Go to Filter and uncheck the filtering "Process Name is System"
- Reboot the machine
- After the machine has come up, open Procmon immediately. You will be asked to save what was captured
- Save the file as .PML
- Zip the PML file before sending, they compress well.
- Upload the capture to CBVault
Additional Notes
- Sensor Diagnostics will need to be captured along with the Procmon capture (See Related Content)
- For other performance issues (See Related Content)
- Do not put any additional filters in place
Related Content