Blog Viewer

EDR: How to collect logs for performance-related issues (MacOS)

By CB_Support posted Feb 15, 2019 07:07 PM

  

Environment

  • EDR Sensor: 6.x and Higher
  • macOS: All Supported Versions

Objective

To collect relevant logs on an Apple macOS endpoint in order to troubleshoot most performance-related issues. Typical issues may include:
  • General system performance issues
  • High CPU/Memory of EDR sensor process
  • High CPU/Memory of third-party applications

Resolution

  1. Log onto the Apple macOS endpoint exhibiting performance issues.
  2. Generate a process sample for the sensor:
# sudo sample CbOsxSensorService 10 1 -f ~/Desktop/process_sample_`hostname`_`date +%Y-%m-%d_%H-%M-%S`.log
  1. Generate an Apple macOS sensor diag report.
  2. Upload all log files to CB Vault
  3. Update your Carbon Black Technical Support case with further relevant information:
- Is the performance issue a reproducible scenario and if so, what steps, if any, are taken to reproduce it? 
(For example, were any backups, updates, or large file transfers being performed?)

- How many endpoints are affected? What are their general system profiles and function? 

- What other security applications/real-time scanners are installed?

- How long do the performance issues last? 

- What actions, if any, return the system performance to normal?

- Is the endpoint connected to to any network shares? 

- Does this endpoint generate a large number of logs, binaries, or PDF reports?

Additional Notes

  • The process sample generated in step 2 will be created on your Desktop.

Related Content



#EDR
0 comments
0 views

Permalink