This article discusses the methods for collecting VMware Carbon Black Cloud Endpoint sensor logs.
Affected Products:
VMware Carbon Black Cloud Endpoint
Affected Versions:
v3.3.0 and later (Windows)
v3.1.0 and later (Mac)
v2.5.0 and later (Linux)
Affected Operating Systems:
Windows
Mac
Linux
Not applicable.
Click the appropriate operating system for the log collection process.
Click the appropriate client version for specific installation steps. Reference How to Identify the VMware Carbon Black Cloud Endpoint Sensor Version for more information.
cmd
and then press CTRL+SHIFT+ENTER. This runs Command Prompt as an administrator.CD [DIRECTORY]
and then press Enter.[DIRECTORY]
= Directory of the VMware Carbon Black Cloud Endpoint sensor.[DIRECTORY]
is C:\Program Files\Confer
.repcli capture [DESTINATION DIRECTORY]
and then press Enter.[DESTINATION DIRECTORY]
= Target destination for log bundle.
[DESTINATION DIRECTORY]
used in Step 5.psc_sensor.zip
and then click Rename.psc_sensor.zip
to [MACHINENAME]_psc_sensor.zip
.[MACHINENAME]
= Fully qualified domain name of endpoint.
cmd
and then press CTRL+SHIFT+ENTER. This runs Command Prompt as an administrator.CD [DIRECTORY]
and then press Enter.[DIRECTORY]
= Directory of the VMware Carbon Black Cloud Endpoint sensor.[DIRECTORY]
is C:\Program Files\Confer
.repcli capture
and then press Enter.C:\Windows\TEMP\confer-temp
.confer_dump.zip
and then click Rename.confer_dump.zip
to [MACHINENAME]_confer_dump.zip
.[MACHINENAME]
= Fully qualified domain name of endpoint.
Click the appropriate client version for specific installation steps. Reference How to Identify the VMware Carbon Black Cloud Endpoint Sensor Version for more information.
type sudo /Applications/VMware\ Carbon\ Black\ Cloud/repcli.bundle/Contents/MacOS/repcli capture [UNINSTALL_CODE] [DESTINATION DIRECTORY]
and then press Enter.[UNINSTALL_CODE]
= Removal code for VMware Carbon Black Cloud Endpoint. For more information, reference How to Manage the VMware Carbon Black Cloud Endpoint Uninstall Code.[DESTINATION DIRECTORY]
= Target destination for log bundle.[DESTINATION DIRECTORY]
, right-click confer.zip
, and then select Rename.confer.zip
to [MACHINENAME]_confer_dump.zip
.[MACHINENAME]
= Fully qualified domain name of endpoint.
sudo /Applications/Confer.app/uninstall -l [UNINSTALL_CODE] -d [DESTINATION DIRECTORY]
and then press Enter.[UNINSTALL_CODE]
= Removal code for VMware Carbon Black Cloud Endpoint. For more information, reference How to Manage the VMware Carbon Black Cloud Endpoint Uninstall Code.[DESTINATION DIRECTORY]
= Target destination for log bundle.[DESTINATION DIRECTORY]
, right-click confer.zip
, and then select Rename.confer.zip
to [MACHINENAME]_confer_dump.zip
.[MACHINENAME]
= Fully qualified domain name of endpoint.
Click the appropriate client version for specific installation steps. Reference How to Identify the VMware Carbon Black Cloud Endpoint Sensor Version for more information.
su root
and then press Enter.root
and then press Enter.sudo /opt/carbonblack/psc/bin/collectdiags.sh
and then press Enter./tmp
. The filename is in the format diags_[HOSTNAME]_[EPOCH_TIME]_[RANDOM].tgz
su root
and then press Enter.root
and then press Enter.sudo tar cvf $(hostname –long)_$(date +"%Y-%b-%d_%H-%M-$S")_logs.tgz /var/opt/carbonblack/psc/log
and then press Enter./var/opt/carbonblack/psc/log
.To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.