[SDP 3][58409ba5-9d4c-4031-a0b3-0357fa1efdff] Windows Small Business Server 2008 All-purpose data collection and analysis

Article translations Article translations
Close Close
Article ID: 2414539 - View products that this article applies to.
Expand all | Collapse all

SUMMARY

The Windows Small Business Server 2008 All-Purpose Data Collection and Analysis manifest collects information that is used in troubleshooting Windows Small Business Server 2008 issues. This includes general Windows issues in different technologies that include Setup, Performance, Networking, and Directory Services.

MORE INFORMATION

This article describes the information that may be collected from a computer that is running the Windows Small Business Server 2008 All-Purpose Data Collection and Analysis manifest.

Information that is collected

Event logs - General
Collapse this tableExpand this table
DescriptionFile name
Event log – Application – text, csv, and evtx formats<ComputerName>_evt_Application.*
Event log – System – text, csv, and evtx formats<ComputerName>_evt_System.*
Event logs – Other<ComputerName>_evt_*.*


File version information
Collapse this tableExpand this table
DescriptionFile name
File version information from %windir%\cluster\*.*<ComputerName>_sym_Cluster.*
File version information from %windir%\system32\*.dll<ComputerName>_sym_System32_dll.*
File version information from %windir%\system32\*.exe<ComputerName>_sym_System32_exe.*
File version information from %windir%\system32\*.sys<ComputerName>_sym_System32_sys.*
File version information from %windir%\system32\drivers folder<ComputerName>_sym_Drivers.*
File version information from %windir%\system32\drivers\*.*<ComputerName>_sym_SysWOW64_sys.*
File version information from {Program Files (x86}}\*.sys<ComputerName>_sym_ProgramFilesx86_sys.*
File version information from {Program Files}\*.sys<ComputerName>_sym_ProgramFiles_sys.*
File version information from {Program Files}\Microsoft iSNS Server\*.* and %windir%\system32\iscsi*.*<ComputerName>_sym_MS_Iscsi.*
File version information from all drivers that are currently running on the computer<ComputerName>_sym_RunningDrivers.*
File version information from all processes that are currently running on the computer<ComputerName>_sym_Process.*
File version information from print spooler folder %windir%\system32\Spool\*.*<ComputerName>_sym_PrintSpooler.*
File version information from Windows\Cluster<ComputerName>_sym_Cluster.*


Device and drivers
Collapse this tableExpand this table
DescriptionFile name
Devices and connection information that is generated by devcon utility<ComputerName>_Devcon.log
Minifilter drivers enumeration by using Fltmc.exe utility<ComputerName>_Fltmc.txt
MS-DOS device names by using dosdev utility<ComputerName>_DosDev.txt
Output from Driver Verifier Manager (verifier.exe) utility<ComputerName>_Verifier.txt
Upper and lower filters information by using fltrfind.exe utility<ComputerName>_FltrFind.txt
Information about driver signature by using driverquery.exe<ComputerName>_SignedDrivers.txt


Storage and disk information
Collapse this tableExpand this table
DescriptionFile name
Fibre Channel Information Tool information that is collected by FCInfo utility<ComputerName>_fcinfo.txt
Information from computer disk sectors that is generated by SecInspect.exe utility<ComputerName>_Secinspect.txt
iSCSI related information that is generated by iscsicli.exe utility<ComputerName>_iSCSIInfo.txt
Parsing of storage-related event logs (Events 6 7 9 11 15 50 51 57 and 389) on System log by using evparse.exe utility<ComputerName>_StorageEventLogs.htm
Fibre Channel Information tool (fcinfo) output to obtain SAN resources and configuration information<ComputerName>_FCInfo.txt
Dispart's SAN policy information<ComputerName>_DiskpartSANPolicy.txt


Memory dumps and related
Collapse this tableExpand this table
DescriptionFile name
Information about computer memory dumps, user memory dumps, and memory dump configuration<ComputerName>_DumpReport.*
Compressed version of mini computer memory dumps that is located at %windir%\minidumps<ComputerName>_dmp_*.cab
Windows Error Reporting mini dumps that were generated in the past 30 days<ComputerName>_dmp_*.cab


Hotfixes and updates
Collapse this tableExpand this table
DescriptionFile name
Installed updates and hotfixes<ComputerName>_Hotfixes.*


Virtualization
Collapse this tableExpand this table
DescriptionFile name
Basic information about computer virtual environment<ComputerName>_Virtualization.*


Networking-related information
Collapse this tableExpand this table
DescriptionFile name
Basic IP networking configuration information, such as Tcp/ip registry key, ipconfig, netstat, nbtstat, and netsh output<ComputerName>_TcpIp-Info.txt
Basic SMB configuration information that is based on output of net.exe utility<ComputerName>_SMB-Info.txt
Information about TCP Offload from the registry and netsh<ComputerName>_TCPIP-Info-Offload.txt
Networking Setup/ information about the attempts to join domains<ComputerName>_netsetup.log
Network Diagnostic took (netdiag.exe) output<ComputerName>_netdiag.txt
Permissions dump for registry key HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg<ComputerName>_winreg.txt
DNS cache information from ipconfig.exe /displaydns command<ComputerName>_DnsClient-DnsCache.txt
Hosts file from \Windows\System32\Drivers\etc folder<ComputerName>_DnsClient-HostsFile.txt
Services file from \Windows\System32\Drivers\etc folder<ComputerName>_TCPIP-ServicesFile.txt
LMHosts file from \Windows\System32\Drivers\etc folder<ComputerName>_WinsClient-LmhostsFile.txt
Firewall information from "netsh firewall" context output<ComputerName>_Firewall-Netsh-Fw.txt
IPsec information from "netsh ipsec" context output<ComputerName>_IPsec-Netsh.txt
IPsec policy information from "netsh ipsec static exportpolicy" output<ComputerName>_IPsec-Export.ipsec
General networking configuration from "netsh dump" output<ComputerName>_Netsh-Dump.txt
Load Balancing configuration by using wlbs.exe display command<ComputerName>_NLB-WlbsDisplay.txt
Remote Access Service Information by using "netsh ras" context output<ComputerName>_RAS-Netsh.txt
General IPv4 information by using "netsh int ipv4" context output<ComputerName>_TCPIP-Netsh-IPv4.txt
General IPv6 information by using "netsh int ipv6" context output<ComputerName>_TCPIP-Netsh-IPv6.txt
Winsock catalog information by using "netsh winsock show catalog" output<ComputerName>_WinSock-Netsh.txt
Wired 802.1X (LAN) information by using "netsh lan" context output<ComputerName>_8021x-Netsh-LAN.txt
Wireless Local Area Network (WLAN) 802.11 connectivity and security settings by using "netsh wlan" context output<ComputerName>_8021x-Netsh-WLAN.txt
Background Intelligent Transfer Service (BITS) information by using "BitsAdmin /list" command output<ComputerName>_BITS-BitsAdmin-List.txt
Dynamic Host Configuration Protocol (DHCP) Server information by using "netsh dhcp server" context output<ComputerName>_DhcpServer-Netsh.txt
Windows Internet Name Service (WINS) server information by using "netsh wins server" context output<ComputerName>_WinsServer-Netsh.txt
Windows Internet Name Service (WINS) client – Netbios cache by using "nbtstat.exe –c" command output<ComputerName>_WinsClient-NetbiosCache.txt
Remote procedure call (RPC) general information by using "netsh rpc" context output<ComputerName>_RPC-Netsh.txt
Displays the current Windows HTTP Services (WinHTTP) proxy information by using "netsh winhttp show proxy" output<ComputerName>_WinHttp-Netsh.txt

Printers and print drivers
Collapse this tableExpand this table
DescriptionFile name
Printers and print driver information. This includes drivers, print monitors, and print processors.<ComputerName>_PrintInfo.*

Directory Services-related information
Collapse this tableExpand this table
DescriptionFile name
Netlogon service log file (\Windows\Debug\Logs\netlogon.log)<ComputerName>_Netlogon.log
Winlogon log file (\Windows\security\logs\winlogon.log)<ComputerName>_Winlogon.log
Security templates that are currently cached on the system (From \Windows\Security\Templates\Policies)<ComputerName>_AppliedSecTempl.txt
Collects user rights settings by using showpriv.exe tool<ComputerName>_Userrights.txt
Networking setup- / domain join-related information<ComputerName>_Netsetup.log

Registry keys
Collapse this tableExpand this table
DescriptionFile name
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Hotfix

HKCU\SOFTWARE\Policies\Microsoft

HKLM\Software\Policies\Microsoft

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

HKLM\SYSTEM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

HKLM\Software\Microsoft\Active Setup

HKCU\Software\Microsoft\Active Setup

HKLM\Software\Microsoft\Windows NT\CurrentVersion

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions

HKLM\SYSTEM\CurrentControlSet\Control\ProductOptions

HKCU\Software\Microsoft\Windows NT\Currentversion\AppCompatFlags

HKCU\Software\Microsoft\Java VM

HKLM\Software\Microsoft\Windows\CurrentVersion\NetCache

HKLM\Software\Microsoft\EAPOL\Parameters\General\Global

HKLM\Software\Microsoft\NetworkAccessProtection

HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkList
<ComputerName>_reg_Software.txt
HKLM\System\MountedDevices

HKLM\Hardware\DESCRIPTION\System\CentralProcessor

HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider

HKLM\System\CurrentControlSet\Control\Session Manager\Power

HKLM\SYSTEM\CurrentControlSet\Control\Lsa

HKLM\System\CurrentControlSet\Control\Session Manager

HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation

HKLM\SYSTEM\CurrentControlSet\Control\Video

HKLM\System\CurrentControlSet\Services\napagent

HKLM\System\CurrentControlSet\Services\Afd

HKLM\System\CurrentControlSet\Services\BITS

HKLM\System\CurrentControlSet\Services\Dhcp

HKLM\System\CurrentControlSet\Services\DHCPServer

HKLM\System\CurrentControlSet\Services\Dnscache

HKLM\System\CurrentControlSet\Services\DNS

HKLM\System\CurrentControlSet\Services\IPsec

HKLM\System\CurrentControlSet\Services\PolicyAgent

HKLM\System\CurrentControlSet\Services\lanmanserver

HKLM\System\CurrentControlSet\Services\LanmanWorkstation

HKLM\System\CurrentControlSet\Services\MpsSvc

HKLM\System\CurrentControlSet\Services\MRxDav

HKLM\System\CurrentControlSet\Services\WebClient

HKLM\System\CurrentControlSet\Services\MrxSmb

HKLM\System\CurrentControlSet\Services\MrxSmb10

HKLM\System\CurrentControlSet\Services\MrxSmb20

HKLM\System\CurrentControlSet\Services\rdbss

HKLM\System\CurrentControlSet\Services\MUP

HKLM\System\CurrentControlSet\Services\NetBT

HKLM\System\CurrentControlSet\Services\Netlogon

HKLM\System\CurrentControlSet\Services\RasMan

HKLM\System\CurrentControlSet\Services\SharedAccess

HKLM\System\CurrentControlSet\Services\wscsvc

HKLM\System\CurrentControlSet\Services\SMB

HKLM\System\CurrentControlSet\Services\Tcpip

HKLM\System\CurrentControlSet\Services\Tcpip6

HKLM\System\CurrentControlSet\Services\VSS

HKLM\System\CurrentControlSet\Services\Winsock

HKLM\System\CurrentControlSet\Services\Winsock2
<ComputerName>_reg_System.txt
HKLM\System\MountedDevices<ComputerName>_reg_MountedDevices.hiv
HKCU\Network<ComputerName>_reg_NetworkConnections.TXT
HKLM\System\CurrentControlSet\Control\CrashControl

HKLM\System\CurrentControlSet\Control\Session Manager

HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management

HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

HKLM\Software\Microsoft\Windows\Windows Error Reporting

HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting
<ComputerName>_reg_Recovery.txt
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Runonce

HKCU\Software\Microsoft\Windows\CurrentVersion\RunonceEx

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKLM\ Software\Microsoft\Windows\CurrentVersion\Run

HKLM\Software\Microsoft\Windows\CurrentVersion\Runonce

HKLM\Software\Microsoft\Windows\CurrentVersion\RunonceEx

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad"

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Load

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
<ComputerName>_reg_Startup.txt
HKLM\SYSTEM\CurrentControlSet\Control\Print<ComputerName>_reg_Print.*
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server Web Access

HKLM\System\CurrentControlSet\Services\TermService

HKLM\System\CurrentControlSet\Services\TermDD
<ComputerName>_reg_TermServer.txt
HKLM\Software\Microsoft\Internet Explorer

HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings

HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings

HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings

HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings

HKLM\Software\Microsoft\Internet Domains

HKLM\Software\Microsoft\Internet Connection Wizard

HKCU\Software\Microsoft\Internet Connection Wizard

HKLM\Software\Microsoft\Internet Account Manager

HKCU\Software\Microsoft\Internet Account Manager

HKLM\Software\Microsoft\IEAK

HKCU\Software\Microsoft\IEAK

HKLM\Software\Microsoft\IEAK6

HKLM\Software\Microsoft\IE Setup
<ComputerName>_reg_IE.txt
HKLM\System\CurrentControlSet\Services\iScsiPrt

HKLM\Software\Microsoft\iSCSI Target

HKLM\Software\Microsoft\Windows NT\CurrentVersion\iSCSI
<ComputerName>_reg_iSCSI.*
HKLM\Software\Microsoft\iSCSI Target<ComputerName>_reg_iSCSI_Target.hiv
HKLM\Software\Microsoft\Windows NT\CurrentVersion\iSCSI<ComputerName>_reg_CurrentVersion_iSCSI.HIV
HKLM\System\CurrentControlSet\Control\MPDev

HKLM\System\CurrentControlSet\Control\iSCSIPrt

HKLM\System\CurrentControlSet\Services\MSiSCSI

HKLM\System\CurrentControlSet\Services\MSDsm

HKLM\System\CurrentControlSet\Services\MPIO

HKLM\System\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}

HKLM\System\CurrentControlSet\Services\Tcpip
<ComputerName>_reg_Storage.txt
HKLM\Software\Microsoft\Exchange

HKLM\System\CurrentControlSet\Services\MSExchangeActiveSyncNotify

HKLM\System\CurrentControlSet\Services\MSExchangeADDXA

HKLM\System\CurrentControlSet\Services\MSExchangeAL

HKLM\System\CurrentControlSet\Services\MSExchangeDSAccess

HKLM\System\CurrentControlSet\Services\MSExchangeES

HKLM\System\CurrentControlSet\Services\MSExchangeFBPublish

HKLM\System\CurrentControlSet\Services\MSExchangeIS

HKLM\System\CurrentControlSet\Services\MSExchangeMGMT

HKLM\System\CurrentControlSet\Services\MSExchangeMTA

HKLM\System\CurrentControlSet\Services\MSExchangeMU

HKLM\System\CurrentControlSet\Services\MSExchangeOMA

HKLM\System\CurrentControlSet\Services\MSExchangeSA

HKLM\System\CurrentControlSet\Services\MSExchangeSenderID

HKLM\System\CurrentControlSet\Services\MSExchangeSRS

HKLM\System\CurrentControlSet\Services\MSExchangeTransport

HKLM\System\CurrentControlSet\Services\MSExchangeUCF

HKLM\System\CurrentControlSet\Services\MSExchangeWEB

HKLM\Software\Microsoft\MosTrace\CurrentVersion\DebugAsyncTrace

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\STORE.EXE
<ComputerName>_reg_Exchange.txt
HKLM\Cluster<ComputerName>_reg_Cluster.hiv
HKLM\System\CurrentControlSet\Services\Clussvc<ComputerName>_reg_Clussvc.txt
HKLM\System\CurrentControlSet\Services\Clusdisk<ComputerName>_reg_Clusdisk.txt


Domain controllers
Collapse this tableExpand this table
DescriptionFile name
Domain Controller Diagnostics Tool (dcdiag.exe) output<ComputerName> _DCDiag.txt
Replication topology overview by using "repadmin.exe /showrepl" output<ComputerName>_repadmin.txt


Other
Collapse this tableExpand this table
DescriptionFile name
Resultant Set of Policy (RSoP) generated by gpresult.exe utility<ComputerName>_GPResult.*
Schedule Tasks information (csv and txt) generated by schtasks.exe utility<ComputerName>_schtasks.*
System Information - MSInfo32 tool output – txt and nfo formats<ComputerName>_msinfo32.*
Volume Shadow Copy Service (VSS) information<ComputerName>_VSSAdmin.txt
Windows basic activation information by using %windir%\system32\slmgr.vbs<ComputerName>_KMSActivation.txt
Operating system startup options file (Boot.ini)<ComputerName>_BOOT.INI
Hyperthread-capable processor information<ComputerName>_HyperThread.txt
Information about process and threads by using pstat.exe tool<ComputerName>_PStat.txt
SP Catalog Logging file (Windows\System32\catroot2 \DBErr.txt)<ComputerName>_DBErr.txt
Windows Update Reporting Events log file (from WINDOWS\SoftwareDistribution)<ComputerName>_ReportingEvents.log
Windows Update log file (from windows folder)<ComputerName>_WindowsUpdate.log
List Performance information from top processes, such as memory usage, handle count, and number of threads, and also kernel memory allocation information<ComputerName>_ProcessPerfInfo.*


Windows Vista or Windows Server 2008
Hyper-V role
Collapse this tableExpand this table
DescriptionFile name
Event log - Hyper-V-related event logs (Microsoft-Windows-Hyper-V*) – Text, csv, and evtx formats<ComputerName>_evt_HyperV*.*
Hyper-V Configuration and Virtual Machine Information<ComputerName>_HyperV-Info.htm
Hyper-V Virtual Machine Definition files from %ProgramData%\Microsoft\Windows\Hyper-V\Virtual Machines\*.xml<ComputerName>_{VirtualMachineGUID}.xml


FailoverCluster feature
Collapse this tableExpand this table
DescriptionFile name
All files from the \windows\cluster\reports folder<ComputerName>_ClusterReports*.*
Server manager log file that is located at %windir%\logs\ServerManager.log<ComputerName>_ServerManager.log
Registry key HKLM\System\CurrentControlSet\Services\ClusDisk<ComputerName>_Clusdisk.txt
Registry key HKLM\System\CurrentControlSet\Services\ClusSvc<ComputerName>_ClussvcRegistry.txt
Output from "Cluster . RES" command prompt utility, listing resources and properties<ComputerName>_Cluster_Res_Properties_All.txt
Cluster log files generated by running "cluster.exe log"<ComputerName>_Cluster.Log
Cluster MPS Tool (clusmps.exe) output<ComputerName> _Cluster_MPS_Information.txt


Server manager/ roles information
Collapse this tableExpand this table
DescriptionFile name
Information about server roles installed on a server generated by servermanagercmd.exe<ComputerName>_ServerManagerCmdQuery.*
Server manager log file that is located at %windir%\logs\ServerManager.log<ComputerName>_ServerManager.log


Boot information
Collapse this tableExpand this table
DescriptionFile name
Output from bcdedit.exe utility<ComputerName>_BCDEdit.txt

<ComputerName>_BCD-Backup.bak


Deployment logs
Collapse this tableExpand this table
DescriptionFile name
Setupact.log from folders:

%windir%

%windir%\Panther

%windir%\Panther\UnattendedGC
<ComputerName>_Setupact-*.log
Setupapi logs that are located on %windir%\inf folder<ComputerName>_SetupApi.app.log

<ComputerName>_SetupApi.evt.log

<ComputerName>_SetupApi.offline.log
Setuperr.log that is located on Windows folder<ComputerName>_Setuperr.log
Upgrade log – SetupReport.txt from windows\panther folder<ComputerName>_SetupReport.txt


Servicing logs
Collapse this tableExpand this table
DescriptionFile name
Component-Based Servicing Logs located on %windir%\Logs\CBS<ComputerName>_CBS*.log
DPX Setup Act log located on %windir%\logs\DPX<ComputerName>_setupact.log"
Pending Operations Queue Exec log located on %windir%\winsxs<ComputerName>_poqexec.log
Windows Side-by-Side Pending Bad log located on %windir%\ winsxs<ComputerName>_pending.xml.bad
Windows Side-by-Side Pending log located on %windir%\ winsxs<ComputerName>_pending.xml


ServerCore installation option media
Collapse this tableExpand this table
DescriptionFile name
Installed roles and component (output from oclist.exe command)<ComputerName>_OCList*.log
Windows Update, Remote Desktop and other information configured by scregedit.wsf script<ComputerName>_Scregedit.txt


Domain controllers
Collapse this tableExpand this table
DescriptionFile name
Domain Controller promotion debug log from \Windows\debug folder<ComputerName>_DCPromo.log


Networking-related information
Collapse this tableExpand this table
DescriptionFile name
Networking Setup/ information about the attempts to join domains<ComputerName>_netsetup.log
Current configuration settings for Network Access Protection (NAP) by using "netsh nap client export" command<ComputerName>_NapClient-Export.xml
Network Access Protection (NAP) client information by using "netsh nap client" context output<ComputerName>_NapClient-Netsh.txt
Windows Firewall with Advanced Security general information by using "netsh advfirewall show" context output<ComputerName>_Firewall-Netsh-AdvFw.txt
Windows Firewall with Advanced Security computer security connection rules by using "netsh advfirewall consec" context output<ComputerName>_Firewall-Netsh-AdvFw-ConSec-Rules.txt
Windows Firewall with Advanced Security firewall rules by using "netsh advfirewall firewall" context output<ComputerName>_Firewall-Netsh-AdvFw-Fw-Rules.txt
Information about current Firewall policy by using "netsh advfirewall export" command<ComputerName>_Firewall-Netsh-AdvFw-Export.wfw
HTTP service information by using "netsh http" context output<ComputerName>_Http-Netsh.txt
Network Input Output (NETIO) binding filters by using "netsh netio show bindingfilters" command<ComputerName>_TCPIP-Netsh-NetIO.txt


Windows SBS logs
Collapse this tableExpand this table
DescriptionFile name
Windows SBS logs from c:\program files\Windows Small Business Server\Logs
Exchange Server setup logs
DcPromo logs
<ComputerName>_*.log


Windows SBS BPA
Collapse this tableExpand this table
DescriptionFile name
Windows SBS 2008 BPA data is captured by using the latest BPA configuration file.<ComputerName>_BPA.xml


Windows SBS Setup
Collapse this tableExpand this table
DescriptionFile name
If Windows SBS setup errors are found, errors are analyzed and isolated.<ComputerName>_analyzedSetupoutput.txt


More information

In addition to the files collected and listed earlier, this SDP manifest can detect one or more of the following situations:
  • Computer is running on a virtual environment
  • Presence of a computer memory dump in the past 30 days
  • Presence of a user mode memory dump in the past 30 days
  • Problems related to computer memory dump configuration that could stop a memory dump from being generated
  • Presence of services that could interfere with memory dump generation
  • Unexpected Shutdown event logs on System log from past 30 days (Events 50 from EventLog) 
  • Computer memory dump-related event logs on System log from past 30 days (Events 1001 from Save Dump)
  • Srv-related event logs 2020 and 2021 from the past 30 days
  • Processes that have high number of handles (more than 40,000) 
  • Computer has low number of System Page Entries (less than 5,000) 
  • Computer is in low available memory condition (computer committed limit more than 85 percent) 
  • Any kernel pool memory tag that uses more than 60 percent of all allocated memory 
  • Unsupported version of a service pack 
  • Unsupported operating system versions 
  • Windows SBS 2008 Setup failure analysis 
  • Autoruns output

References

926079 Frequently asked questions about the Microsoft Support Diagnostic Tool (MSDT)

Properties

Article ID: 2414539 - Last Review: July 10, 2012 - Revision: 3.0
APPLIES TO
  • Windows Small Business Server 2008 Premium
  • Windows Small Business Server 2008 Standard
Keywords: 
KB2414539

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com