IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How to collect a Procmon for Boot/Login Sensor Performance

EDR: How to collect a Procmon for Boot/Login Sensor Performance

Environment

  • Carbon Black EDR (Formerly CB Response) Sensor: All Versions
  • Microsoft Windows: All Supported Versions

Objective

How to collect a Procmon capture for performance issues related Boot or Login with the CB EDR sensor

Resolution

  1. Download the latest Process Monitor (Procmon) from sysinternals
  2. Unzip and place Procmon in an easy to find location
  3. Open Procmon and Press Ctrl+E to stop the capture
  4. Go to Options > Enable Boot Logging > Generate Thread Profiling every second
  5. Go to Filter and uncheck the filtering "Process Name is System"
  6. Reboot the machine
  7. After the machine has come up, open Procmon immediately. You will be asked to save what was captured
  8. Save the file as .PML
  9. Zip the PML file before sending, they compress well. 
  10. Upload the capture to CBVault

Additional Notes

  • Sensor Diagnostics will need to be captured along with the Procmon capture (See Related Content)
  • For other performance issues (See Related Content)
  • Do not put any additional filters in place

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
2858
Contributors