IT-professionals moeten mogelijk logbestanden van een of meer computers ophalen om een probleem te diagnosticeren. Dit kan het beste worden gedaan met behulp van tools voor extern beheer, maar kan ook worden gedaan door middel van scripting. Het gedeelte Bijlagen van dit artikel bevat voorbeelden van logboekverzamelaars die kunnen worden uitgevoerd of gewijzigd om aan de meeste behoeften te voldoen.
Scriptdetails:
C:\Users\<Current User>\AppData\Roaming\
9af4c403c997dcebdba49b6251565a5c
3a8bb6d3a75ebe14ffc631fe68dcfa308eaf3691
4917c7f2e0d8d6111159cfe18b8dc9ca6cf04ff4467166d65435e3b8e07a5e2b
.cmd
Het bestand wordt weergegeven als een Kladblok-pictogram en wordt geopend als Kladblok wanneer u dubbelklikt
.cmd
en andere scriptbestanden..bat
bestand in plaats daarvan?
.cmd
als .bat
bestanden die verschillen in context en beveiliging bevatten..cmd
..bat
..txt
bestand bevatten?
Logboek verzameld | ZIP-logboekpad | Gebruikte opdracht | Beheerder vereist | Type opdracht | Microsoft / Dell referentie-URL | 2.3 Wijziging |
---|---|---|---|---|---|---|
Applicatiegebeurtenislogboeken | \Logs\OperatingSystem\Event Logs\application_eventlog.evtx |
wevtutil epl Application /q:"*[System[(Level<=5)]]" application_eventlog.evtx |
Nee | Opdrachtregel | https://learn.microsoft.com/windows/win32/wes/windows-event-log |
0 |
AppX-pakketlijst | \Logs\Application\installed_appx.txt |
Get-AppxPackage | Select PackageFullName | Sort PackageFullName |
Ja | Powershell | https://learn.microsoft.com/powershell/module/appx/get-appxpackage?view=windowsserver2022-ps |
0 |
Lijst met beschikbare slaapstanden | \Logs\Power\available_sleepstates.txt |
powercfg /a |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Batterijrapport | \Logs\Power\Battery_Report.html |
powercfg /batteryreport /output Battery_Report.html /duration 14 |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
BCD-informatie | \Logs\OperatingSystem\bcd.txt |
bcdedit |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-server/administration/windows-commands/bcdedit |
0 |
Lijst met Bitlocker-beschermers | \Logs\Security\bitlocker_PCRs.txt |
manage-bde %SYSTEMDRIVE% -protectors -get -type TPM |
Ja | Powershell | https://learn.microsoft.com/windows-server/administration/windows-commands/manage-bde |
0 |
BitLocker-status | \Logs\Security\bitlocker_status.txt |
manage-bde -status |
Ja | Powershell | https://learn.microsoft.com/windows-server/administration/windows-commands/manage-bde |
0 |
Lijst met breedbandadapters | \Logs\Network\broadband_adapter.txt |
netsh mbn show interfaces |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/networking/technologies/netsh/netsh-contexts |
0 |
Geconfigureerde Wake Timer-lijst | \Logs\Power\waketimers.txt |
powercfg /waketimers |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Dell Command Update logboek | \Logs\Dell\Dell_Command_Update\Activity.log |
XCOPY /s /y /q /F %SYSTEMDRIVE%\ProgramData\Dell\UpdateService\Log |
Ja | Opdrachtregel | Dell Command | Update | 0 |
Dell Data Migrate-logboeken (bestemming) | \Logs\Dell\Dell_Data_Migrate_Destination\(Various files) |
XCOPY /s /I /y /q /F %SYSTEMDRIVE%\ProgramData\Dell\SupportAssist\CDM\Logs . |
Ja | Opdrachtregel | https://www.dell.com/support/manuals/data-assistant/migrate_1.0_ug/ | 0 |
Dell Data Migrate-logboeken (bron) | \Logs\Dell\Dell_Data_Migrate_Source\(Various Files) |
XCOPY /s /y /q /F %SYSTEMDRIVE%\ProgramData\DDA\logs\ . |
Ja | Opdrachtregel | https://www.dell.com/support/manuals/data-assistant/migrate_1.0_ug/introduction?guid=guid-28c0bb91-e84d-4118-99ee-e5500769b170& | 0 |
Dell Digital Delivery logs | \Logs\Dell\Dell_Digital_Delivery\ |
XCOPY /s /y /q /F %SYSTEMDRIVE%\ProgramData\dell\D3\Resources\Logs\ |
Ja | Opdrachtregel | https://www.dell.com/support/contents/article/product-support/self-support-knowledgebase/software-and-downloads/download-center/dell-digital-delivery | 0 |
Dell Factory Load Information | \Logs\Dell\FactoryLoad\dell.sdr |
XCOPY /y /q /F %SYSTEMDRIVE%\dell.sdr |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/administration/windows-commands/xcopy |
0 |
Dell Optimizer logboeken | \Logs\Dell\Dell_Optimizer\* |
*XCOPY command copies multiple AppData files specific to Dell Optimizer* |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/administration/windows-commands/xcopy |
1 |
Dell Update pakketlogboeken | \Logs\Dell\Dell_Update_Package\* |
XCOPY /s /y /q /F %SYSTEMDRIVE%\ProgramData\Dell\UpdatePackage\Log . |
Nee | Opdrachtregel | Dell Command | Update | 0 |
Gedetailleerd chauffeursrapport | \Logs\Driver\driver_details.txt |
Get-WmiObject Win32_PnPSignedDriver | select * |
Nee | Powershell | https://learn.microsoft.com/previous-versions/windows/desktop/legacy/aa394354(v=vs.85) |
0 |
DirectX diagnoselogboek | \Logs\Graphics\DXdiag.txt |
dxdiag.exe /t DXdiag.txt |
Nee | Opdrachtregel | https://support.microsoft.com/windows/open-and-run-dxdiag-exe-dad7792c-2ad5-f6cd-5a37-bf92228dfd85 |
0 |
Lijst met stuurprogramma's | \Logs\Driver\driver_list.txt |
Get-WmiObject Win32_PnPSignedDriver| select devicename, driverversion, driverdate | Sort-Object devicename |
Nee | Powershell | https://learn.microsoft.com/previous-versions/windows/desktop/legacy/aa394354(v=vs.85) |
0 |
Lijst met driverwinkels | \Logs\Driver\driver_store.txt |
dism /online /get-drivers /all /format:table |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-hardware/manufacture/desktop/what-is-dism?view=windows-11 |
0 |
Drivers in foutstatus | \Logs\Driver\error_state_drivers.txt |
Pnputil /enum-devices /problem /ids |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-hardware/drivers/devtest/pnputil |
1 |
Energierapport | \Logs\Power\energy.html |
powercfg /energy /output energy.html |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Groepsbeleidsobjecten | \Logs\OperatingSystem\GPO_List.html |
start /min gpresult /H GPO_List.html |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/administration/windows-commands/gpresult |
0 |
Lijst met geïnstalleerde applicaties | \Logs\Application\installed_apps.txt |
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* | Select-Object DisplayName, DisplayVersion, Publisher, InstallDate | Sort-Object InstallDate |
Nee | Powershell | https://learn.microsoft.com/powershell/module/microsoft.powershell.management/get-itemproperty?view=powershell-7.3 |
0 |
IP-configuratie | \Logs\Network\ipconfig_all.txt |
ipconfig /all |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/administration/windows-commands/ipconfig |
0 |
Last Wake Trigger | \Logs\Power\lastwake.txt |
powercfg /lastwake |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Geheugendump (volledige kernel) | \Logs\MemoryDumps\memory.dmp |
XCOPY /y /q /F %SYSTEMROOT%\memory.dmp |
Nee | Opdrachtregel | https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/xcopy |
0 |
Geheugendump (Minidump) | \Logs\MemoryDumps\*.dmp |
XCOPY /s /I /y /q /F %SYSTEMROOT%\minidump\*.dmp |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-server/administration/windows-commands/xcopy |
0 |
Geheugendump (status/details) | \Logs\Operating System\DumpStatus.txt |
IF EXIST %SYSTEMROOT%\memory.dmp |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-server/administration/windows-commands/if |
0 |
Status geheugenbeheer | \Logs\System\MemoryManagement.html |
Get-mmagent | Out-File MemoryManagement.html |
Ja | Powershell | https://learn.microsoft.com/powershell/module/mmagent/get-mmagent?view=windowsserver2022-ps |
1 |
Microsoft-systeeminformatie (MSinfo32) | \Logs\OperatingSystem\msinfo32.nfo |
start msinfo32 /nfo msinfo32.nfo |
Nee | Opdrachtregel | https://support.microsoft.com/topic/description-of-microsoft-system-information-msinfo32-exe-tool-10d335d8-5834-90b4-8452-42c58e61f9fc |
0 |
Monitorinformatie | \Logs\Graphics\monitor.txt |
Get-CimInstance -Namespace root\wmi -ClassName WmiMonitorID | ForEach-Object {if ($_.UserFriendlyNameLength -gt 0) {($_.ManufacturerName -ne 0 | foreach {[char]$_}) + [char] 10 + 'InstanceName: ' + ($_.InstanceName) + [char] 10 + ($_.UserFriendlyName -ne 0 | foreach {[char]$_}) + [char] 10 + 'Serial: ' + ($_.SerialNumberID -ne 0 | foreach {[char]$_}) + [char] 10 + 'ProdCodeID: ' + ($_.ProductCodeID -ne 0 | foreach {[char]$_}) + [char] 10 + 'WeekOfManufacture:' + $_.WeekOfManufacture + [char] 10 + 'YearOfManufacture:' + $_.YearOfManufacture + [char] 10 + 'DisplayActive:' + $_.Active + [char] 10 -join ''} else{($_.ManufacturerName -ne 0 | foreach {[char]$_}) + [char] 10 + 'InstanceName: ' + ($_.InstanceName) + [char] 10 + ('No Model (Likely Internal LCD)') + [char] 10 + 'Serial: ' + ($_.SerialNumberID -ne 0 | foreach {[char]$_}) + [char] 10 + 'ProdCodeID: ' + ($_.ProductCodeID -ne 0 | foreach {[char]$_}) + [char] 10 + 'WeekOfManufacture:' + $_.WeekOfManufacture + [char] 10 + 'YearOfManufacture:' + $_.YearOfManufacture + [char] 10 + 'DisplayActive:' + $_.Active + [char] 10 -join ''}} |
Nee | Nee | https://learn.microsoft.com/windows/win32/wmicoreprov/wmimonitorid |
0 |
Logboek geavanceerde eigenschappen netwerkadapter | \Logs\Network\net_adapter_adv_properties.txt |
Get-NetAdapterAdvancedProperty |
Nee | Powershell | https://learn.microsoft.com/powershell/module/netadapter/get-netadapteradvancedproperty?view=windowsserver2022-ps |
0 |
Versie en installatiedatum van besturingssysteem | \Logs\LogCollectorStatus.txt |
(Get-WMIObject -class Win32_ComputerSystem | Select-Object Model| Format-List | Out-string).Trim(); (Get-WMIObject -class Win32_OperatingSystem | Select-Object Caption, Version| Format-List| Out-string).Trim(); (Write-Output 'OS Install Date:').Trim(); ((Get-Item 'C:\Windows\system.ini').CreationTime | Out-String).Trim() |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-operatingsystem |
0 |
PnP-apparatenlijst | \Logs\Operating System\pnp_devices.txt |
Get-CimInstance Win32_PnPEntity |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-pnpentity |
0 |
Stroomaanvragen | \Logs\Power\power_requests.txt |
powercfg /requests |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Details energieschema | \Logs\Power\powerschemes.txt |
powercfg /query |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Lijst met energieschema's | \Logs\Power\power_schemes.html |
powercfg /list |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Lijst met processen | \Logs\OperatingSystem\ processes.txt |
Get-WmiObject -Class Win32_Service | Select-Object -Property Name, ProcessID |
Nee | Powershell | https://learn.microsoft.com/powershell/module/scheduledtasks/get-scheduledtask?view=windowsserver2022-ps |
0 |
Provisioning-pakketten | \Logs\Application\installed_provisioning_packages.txt |
Get-ProvisioningPackage |
Nee | Powershell | https://learn.microsoft.com/powershell/module/provisioning/get-provisioningpackage?view=windowsserver2022-ps |
0 |
Lijst met geplande taken | \Logs\OperatingSystem\taskscheduler.txt |
Get-ScheduledTask | Where State -ne "Disabled" | Get-ScheduledTaskInfo |
Nee | Powershell | https://learn.microsoft.com/powershell/module/scheduledtasks/get-scheduledtask?view=windowsserver2022-ps |
0 |
Servicetag | Part of File Name |
Get-CimInstance -ClassName Win32_BIOS -Property SerialNumber | Select-Object -ExpandProperty SerialNumber |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-bios |
0 |
Servicetag- en plint-ID | \Logs\System\System_Board.txt |
Get-CimInstance -ClassName Win32_BaseBoard | Format-List |
Nee | Powershell | https://www.dell.com/support/manuals/data-assistant/migrate_1.0_ug/introduction?guid=guid-28c0bb91-e84d-4118-99ee-e5500769b170 | 1 |
Lijst met services | \Logs\OperatingSystem\services.txt |
Get-Service | Sort Status |
Nee | Powershell | https://learn.microsoft.com/powershell/module/microsoft.powershell.management/get-service?view=powershell-7.3 |
0 |
Rapport van slaaponderzoek | \Logs\Power\sleepstudy.html |
powercfg /sleepstudy /output sleepstudy.html |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Lijst met opstartprocessen | \Logs\Application\startup_processes.txt |
Get-CimInstance Win32_StartupCommand | Select-Object Name, command, Location, User | Format-List |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-startupcommand |
0 |
Lijst met storageapparaten | \Logs\Storage\Disk_Drives.txt |
Get-CimInstance -ClassName Win32_DiskDrive | select * | Format-List |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-diskdrive |
0 |
Storagevolumes | \Logs\Storage\Disk_Volumes.txt |
Get-CimInstance -ClassName Win32_DiskPartition | Format-List |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/Win32-DiskPartition |
0 |
Systeemmodel | Part of File Name |
Get-WMIObject -class Win32_ComputerSystem | Select-Object -ExpandProperty Model |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-computersystem |
0 |
TPM-informatie | \Logs\Security\tpm.txt |
get-tpm |
Ja | Powershell | https://learn.microsoft.com/powershell/module/trustedplatformmodule/get-tpm?view=windowsserver2022-ps |
0 |
Lijst met USB-apparaten | \Logs\USB\usb_devices.txt |
gwmi Win32_USBControllerDevice |%%{[wmi]($_.Dependent)} | Sort Manufacturer,Name,Description,DeviceID | Ft -GroupBy Manufacturer Name,Description,Service,DeviceID |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-usbcontrollerdevice |
0 |
Details videoadapter | \Logs\Graphics\video.txt |
Get-WmiObject win32_videocontroller | select * |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-videocontroller |
0 |
Details van videoresolutie | \Logs\Graphics\video.txt |
Get-WmiObject win32_videocontroller | select caption, CurrentHorizontalResolution, CurrentVerticalResolution, CurrentRefreshRate, DriverVersion |
Nee | Powershell | https://learn.microsoft.com/windows/win32/cimwin32prov/win32-videocontroller |
0 |
Lijst met apparaten uit de slaapstand | \Logs\Power\device_wake_armed.html |
powercfg -devicequery wake_armed |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-hardware/design/device-experiences/powercfg-command-line-options |
0 |
Windows-systeemgebeurtenislogboeken | \Logs\OperatingSystem\Event Logs\system_eventlog.evtx |
wevtutil epl System /q:"*[System[(Level<=5)]]" system_eventlog.evtx |
Nee | Opdrachtregel | https://learn.microsoft.com/windows/win32/wes/windows-event-log |
0 |
Windows Systeminfo-logboek | \Logs\LogCollectorStatus.txt |
Systeminfo |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/administration/windows-commands/systeminfo |
0 |
Lijst met Windows-updates | \Logs\OperatingSystem\WindowsUpdateLog.txt |
Get-WindowsUpdateLog |
Nee | Powershell | https://learn.microsoft.com/powershell/module/windowsupdate/get-windowsupdatelog?view=windowsserver2022-ps |
0 |
Windows-updatelogboek | \Logs\OperatingSystem\hotfixes.txt |
Get-hotfix |
Nee | Powershell | https://learn.microsoft.com/powershell/module/microsoft.powershell.management/get-hotfix?view=powershell-7.3 |
0 |
Lijst met bekabelde netwerken | \Logs\Network\current_wired_network_interfaces.txt |
netsh lan show interfaces |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/networking/technologies/netsh/netsh-contexts |
0 |
Bekabelde netwerkprofielen | \Logs\Network\wired_profiles.txt |
netsh lan show profiles |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/networking/technologies/netsh/netsh-contexts |
0 |
Instellingen bekabeld netwerk | \Logs\Network\wired_settings.txt |
netsh lan show settings |
Nee | Opdrachtregel | https://learn.microsoft.com/windows-server/networking/technologies/netsh/netsh-contexts |
0 |
Draadloze rapporten | \Logs\Network\wlan-report-latest.html |
netsh wlan show wlanreport duration=30 && copy /y %ProgramData%\microsoft\windows\wlanreport\wlan-report-latest.html . && copy /y %ProgramData%\Microsoft\Windows\wlanreport\wlan-report-latest.cab . |
Ja | Opdrachtregel | https://learn.microsoft.com/windows-server/networking/technologies/netsh/netsh-contexts |
0 |
Windows upgraden/vernieuwen | \Logs\OperatingSystem\windows_upgrade_history |
get-itemproperty -path 'HKLM:\SYSTEM\Setup\Source OS*' | SELECT PSChildName, Productname, ReleaseId, DisplayVersion, CurrentBuild |
Powershell | https://learn.microsoft.com/powershell/module/microsoft.powershell.management/get-itemproperty?view=powershell-7.4 |
1 | |
Display Stream-compressie | Logs\Graphics\Display_Stream_Compression_status.txt |
REG QUERY HKLM\SYSTEM\CurrentControlSet\Control\Class /s /v DPMstDscDisable > Display_Stream_Compression_status.txt |
Nee | Powershell | https://learn.microsoft.com/windows-server/administration/windows-commands/reg-query |
1 |
PCIe-apparaat Generatie- en koppelingssnelheid | \Logs\System\PCIe_Device_Info.txt |
(Get-WMIObject Win32_Bus -Filter 'DeviceID like "PCI%%"').GetRelated('Win32_PnPEntity') | foreach { [pscustomobject][ordered]@{Name = $_.Name; ExpressSpecVersion=$_.GetDeviceProperties('DEVPKEY_PciDevice_ExpressSpecVersion').deviceProperties.data;MaxLinkSpeed=$_.GetDeviceProperties('DEVPKEY_PciDevice_MaxLinkSpeed').deviceProperties.data; MaxLinkWidth=$_.GetDeviceProperties('DEVPKEY_PciDevice_MaxLinkWidth').deviceProperties.data; CurrentLinkSpeed=$_.GetDeviceProperties('DEVPKEY_PciDevice_CurrentLinkSpeed').deviceProperties.data; CurrentLinkWidth=$_.GetDeviceProperties('DEVPKEY_PciDevice_CurrentLinkWidth' ).deviceProperties.data} | Where MaxLinkSpeed } | Format-Table -AutoSize; |
Nee | Powershell | https://learn.microsoft.com/powershell/module/microsoft.powershell.management/get-wmiobject?view=powershell-5.1 |
1 |
BIOS-instellingen | \Logs\System\BIOS_Settings.txt |
Get-CimInstance -Namespace root\dcim\sysman\biosattributes -ClassName EnumerationAttribute | Select-Object AttributeName, CurrentValue, Defaultvalue, PossibleValue |
Ja | Powershell | https://learn.microsoft.com/powershell/module/cimcmdlets/get-ciminstance?view=powershell-7.4 |
1 |
Dell Command negeerlijst | \Logs\Dell\Dell_Command_Update\Update_Ignore_List.txt |
REG QUERY HKLM\SOFTWARE\DELL\UpdateService\Service\IgnoreList /s /v InstalledUpdateJson |
Nee | Powershell | https://learn.microsoft.com/windows-server/administration/windows-commands/reg-query |
1 |
Dell Optimizer-instellingen | \Logs\Dell\Dell_Optimizer\user_settings.txt |
do-cli /get |
Nee | Opdrachtregel | https://www.dell.com/support/manuals/dell-optimizer/dell-optimizer-4.0_ug/command-line-interface-for-dell-optimizer?guid=guid-a82481c9-8abf-4a15-9f2b-6011e36c6b19& |
1 |