IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How to collect logs for performance-related issues (MacOS)

EDR: How to collect logs for performance-related issues (MacOS)

Environment

  • EDR Sensor: 6.x and Higher
  • macOS: All Supported Versions

Objective

To collect relevant logs on an Apple macOS endpoint in order to troubleshoot most performance-related issues. Typical issues may include:
  • General system performance issues
  • High CPU/Memory of EDR sensor process
  • High CPU/Memory of third-party applications

Resolution

  1. Log onto the Apple macOS endpoint exhibiting performance issues.
  2. Generate a process sample for the sensor:
# sudo sample CbOsxSensorService 10 1 -f ~/Desktop/process_sample_`hostname`_`date +%Y-%m-%d_%H-%M-%S`.log
  1. Generate an Apple macOS sensor diag report.
  2. Upload all log files to CB Vault
  3. Update your Carbon Black Technical Support case with further relevant information:
- Is the performance issue a reproducible scenario and if so, what steps, if any, are taken to reproduce it? 
(For example, were any backups, updates, or large file transfers being performed?)

- How many endpoints are affected? What are their general system profiles and function? 

- What other security applications/real-time scanners are installed?

- How long do the performance issues last? 

- What actions, if any, return the system performance to normal?

- Is the endpoint connected to to any network shares? 

- Does this endpoint generate a large number of logs, binaries, or PDF reports?

Additional Notes

  • The process sample generated in step 2 will be created on your Desktop.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎02-15-2019
Views:
1816
Contributors