This article discusses the methods for collecting logs for the CrowdStrike Falcon Sensor.
Not applicable
It is highly recommended to collect logs before troubleshooting CrowdStrike Falcon Sensor or contacting Dell support.
Click Windows, Mac, or Linux for relevant logging information.
A user can troubleshoot CrowdStrike Falcon Sensor on Windows by manually collecting logs for:
Click the appropriate logging type for more information.
%LOCALAPPDATA%\Temp
and then click OK.%SYSTEMROOT%\Temp
and then click OK.CrowdStrike Window Sensor_[TIMESTAMP]_[BIT].log
CrowdStrike Window Sensor_[TIMESTAMP].log
[TIMESTAMP]
= Date & time of Installation[BIT]
= Represents either Agent32 or Agent64It is recommended to Enable verbosity and then reproduce the issue before the Capture of product logs. Once the issue is resolved, it is recommended to Disable verbosity. Click the appropriate process for more information.
regedit
and then press CTRL+SHIFT+ENTER to run the Registry Editor as an administrator.[HKEY_LOCAL_MACHINE\SYSTEM\CrowdStrike\{9b03c1d9-3138-44ed-9fae-d9f4c034b88d}\{16e0423f-7058-48c9-a204-725362b67639}\Default]
.AFLAGS
.03
, and then click OK.eventvwr
and then click OK.CSAgent
.CrowdStrike_[WORKSTATIONNAME].evtx
and then click Save.[WORKSTATIONNAME]
in case the issue is happening on multiple endpoints.
regedit
and then press CTRL+SHIFT+ENTER to run the Registry Editor as an administrator.[HKEY_LOCAL_MACHINE\SYSTEM\CrowdStrike\{9b03c1d9-3138-44ed-9fae-d9f4c034b88d}\{16e0423f-7058-48c9-a204-725362b67639}\Default]
.0
, and then click OK.A user can troubleshoot CrowdStrike Falcon Sensor on Mac by collecting:
Click the appropriate log type for more information.
CrowdStrike Falcon Sensor uses the native install.log to document install information.
/var/log
and then click Go.Install.log
to a readily available location for further investigation.It is recommended to Enable verbosity and then reproduce the issue before the Capture of product logs. Once the issue is resolved, it is recommended to Disable verbosity. Click the appropriate process for more information.
sudo sysctl cs.feature=3
and then press Enter.sudo
, and then press Enter.cs.feature=3
.sudo /Library/CS/falconctl diagnose
and then press Enter.sudo
, and then press Enter.falconctl_diagnose.tgz
will be generated in /private/tmp
.sudo sysctl cs.feature=0
and then press Enter.sudo
, and then press Enter.cs.feature=0
.su root
and then press Enter.sudo
, and then press Enter.sudo mkdir /tmp/CrowdStrike
and then press Enter./tmp/CrowdStrike
directory can be modified in your environment.
sudo grep falcon /var/log/messages > /tmp/CrowdStrike/log_messages.txt
and then press Enter.sudo grep falcon /var/log/syslog > /tmp/CrowdStrike/log_syslog.txt
and then press Enter.sudo grep falcon /var/log/rsyslog > /tmp/CrowdStrike/log_rsyslog.txt
and then press Enter.sudo grep falcon /var/log/daemon > /tmp/CrowdStrike/log_daemon.txt
and then press Enter./tmp/CrowdStrike
(Step 5) using SSH.To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.