• Install & Activate
  • Troubleshooting
BEST Antivirus KBS : Largest Anti-Malware Knowlegde Base and Support
  • Install & Activate
  • Troubleshooting

Data collection for advanced troubleshooting on Windows (Microsoft)

/Troubleshoot Problems / Troubleshooting Microsoft / Troubleshooting Microsoft Business / Microsoft for Windows / Troubleshoot Problems / Troubleshooting Microsoft / Troubleshooting Microsoft Home / Microsoft for Windows / Troubleshoot Problems / Troubleshooting Microsoft / Troubleshoot Problems / Troubleshooting Microsoft / Troubleshooting Microsoft Business / Troubleshoot Problems / Troubleshooting Microsoft / Troubleshooting Microsoft Home / Data collection for advanced troubleshooting on Windows (Microsoft)
  • December 25, 2021
  • BEST Antivirus Staff 2
  • Troubleshooting Microsoft / Microsoft for Windows / Microsoft for Windows / Troubleshooting Microsoft Business / Troubleshooting Microsoft Home

Contents

  1. Source : Official Microsoft Brand Editor by : BEST Antivirus KBS Team
0
(0)

When collaborating with Microsoft support professionals, you may be asked to use the client analyzer to collect data for troubleshooting of more complex scenarios. The analyzer script supports other parameters for that purpose and can collect a specific log set based on the observed symptoms that need to be investigated.

Run ‘MDEClientAnalyzer.cmd /?‘ to see the list of available parameters and their description:

Image of client analyzer parameters in command line.

 Note

When any advanced troubleshooting parameter is used, the analyzer also calls into MpCmdRun.exe to collect Microsoft Defender Antivirus related support logs.

-h – Calls into Windows Performance Recorder to collect a verbose general performance trace in addition to the standard log set.

-l – Calls into built-in Windows Performance Monitor to collect a lightweight perfmon trace. This may be useful when diagnosing slow performance degradation issues that occur over time but hard to reproduce on demand.

-c – Calls into process monitor for advanced monitoring of real-time file system, registry, and process/thread activity. This is especially useful when troubleshooting various application compatibility scenarios.

-i – Calls into built-in netsh.exe command to start a network and windows firewall trace that is useful when troubleshooting various network-related issues.

-b – Same as ‘-c’ but the process monitor trace will be initiated during next boot and stopped only when the -b is used again.

-a – Calls into Windows Performance Recorder to collect a verbose performance trace specific to analysis of high CPU issues related to the antivirus process (MsMpEng.exe).

-v – Uses antivirus MpCmdRun.exe command line argument with most verbose -trace flags.

-t – Starts verbose trace of all client-side components relevant to Endpoint DLP. This is useful for scenarios where DLP actions are not happening as expected for files.

-q – Calls into DLPDiagnose.ps1 script from the analyzer ‘Tools’ directory that validates the basic configuration and requirements for Endpoint DLP.

-d – Collects a memory dump of MsSenseS.exe (the sensor process on Windows Server 2016 or older OS) and related processes.

  • * This flag can be used in conjunction with above mentioned flags.
  • ** Capturing a memory dump of PPL protected processes such as MsSense.exe or MsMpEng.exe is not supported by the analyzer at this time.

-z – Configures registry keys on the machine to prepare it for full machine memory dump collection via CrashOnCtrlScroll. This would be useful for analysis of computer freeze issues.

* Hold down the rightmost CTRL key, then press the SCROLL LOCK key twice.

-k – Uses NotMyFault tool to force the system to crash and generate a machine memory dump. This would be useful for analysis of various OS stability issues.

The analyzer and all the above scenario flags can be initiated remotely by running ‘RemoteMDEClientAnalyzer.cmd’, which is also bundled into the analyzer toolset:

Image of commandline with analyzer information.

 Note

  • When using RemoteMDEClientAnalyzer.cmd it calls into psexec to download the tool from the configured file share and then run it locally via PsExec.exe. The CMD script uses ‘-r’ flag to specify that it is running remotely within SYSTEM context and so no prompt to the user will be presented.
  • That same flag can be used with MDEClientAnalyzer.cmd to avoid a prompt to user that requests to specify the number of minutes for data collection. For example:

    MDEClientAnalyzer.cmd -r -i -m 5

    • -r – Indicates that tool is being run from remote (or non-interactive context)
    • -i – Scenario flag for collection of network trace along with other related logs
    • -m # – The number of minutes to run (5 minutes in the above example)


Source : Official Microsoft Brand
Editor by : BEST Antivirus KBS Team

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

(Visited 6 times, 1 visits today)
Tagged: Fix MicrosoftFix Microsoft for BusinessFix Microsoft for homeFix Microsoft for Windows

Related Articles

  • All about Microsoft

  • Microsoft Defender for Business (preview) troubleshooting

  • Support and troubleshooting Microsoft Defender for Cloud Apps

  • Troubleshooting – What is *.cas.ms, *.mcas.ms, or *.mcas-gov.us? (Microsoft)

  • Troubleshooting access and session controls (Microsoft)

  • Troubleshooting the SIEM agent (Microsoft)

ask or enter a search term

Top Rated Posts

5 (1)

Identity Protection – Enrolment/Registering (TotalAV)

5 (7)

[KB2885] Download and install ESET offline or install older versions of ESET Windows home products

5 (1)

Base Filtering Engine not found (Kaspersky)

5 (1)

Installing on iPhone & iPad

5 (1)

[KB7857] Set up an HTTPS/SSL connection for ESET PROTECT (8.x) Linux

About

We are BEST Antivirus , Trusted Comparison and Cheap Antivirus Software 2020. KBS is Knowledge Base and Support : This page was created to guide customers through the installation and to resolve all the common errors of anti-virus software.

Partners

› Avast
› AVG
› BitDefender
› ESET
› Trend Micro
› All Partners

Resources

› Store
› Advertise
› Brand Reviews
› Review Platforms
› Contact Page
› Knowledge Base

  • Install & Activate
  • Troubleshooting
© Copyright by BEST Antivirus by SSG Limited