[SDP 3][0fdad3a3-4766-4948-9665-be71e7829833] File Sharing Diagnostic

Windows 8Windows Server 2012 DatacenterWindows Server 2012 Datacenter

Summary


The File Sharing Diagnostic collects data for troubleshooting file-sharing issues in a Windows Server environment. 

More Information


The File Sharing Diagnostic collects data either statically or interactively for File Sharing Client and File Sharing Server.

The Static Data Collection option collects static data configuration information.

The Interactive Data Collection option lets the user collect data while the issue is being reproduced, and then it also collects static configuration data. Interactive data collection for File Sharing Client enables network capture by Network Monitor 3.4, ETL logging for remote file systems, problem steps recorder (psr.exe), Performance Monitor, and (optionally) iDNA for Windows Explorer. Interactive data collection for File Sharing Server collects the same main set of data with Performance Monitor counters specific to File Sharing Server, but it does not include the iDNA option. 

Information collected

BITS Client
DescriptionFile name
Current jobs information from BitsAdmin command: cmd.exe /c bitsadmin /list /allusers /verbose
{ComputerName}_BitsClient_bitsadmin-list-allusers-verbose.TXT
HKLM\SOFTWARE\Policies\Microsoft\Windows\BITS
HKLM\System\CurrentControlSet\Services\BITS
{ComputerName}_BitsClient_reg_.TXT
Microsoft-Windows-Bits-Client/Operational
{ComputerName}__evt_*.*

BranchCache
DescriptionFile name
BranchCache information from netsh output
{ComputerName}_BranchCache_netsh_output.TXT
HKLM\SOFTWARE\Policies\Microsoft\PeerDist
HKLM\SYSTEM\CurrentControlSet\services\PeerDistKM
HKLM\SYSTEM\CurrentControlSet\services\PeerDistSvc
{ComputerName}_BranchCache_reg_output.TXT
Microsoft-Windows-BranchCache/Operational
Microsoft-Windows-BranchCacheSMB/Operational
{ComputerName}__evt_*.*

Certificates information
DescriptionFile name
Certutil command to show certificates in the machine store: certutil -silent -store my
{ComputerName}_Certificates-machinestore.TXT
Certutil command to show certificates in the user store: certutil -silent -user -store my
{ComputerName}_Certificates-userstore.TXT
HKLM\SYSTEM\CurrentControlSet\services\CertPropSvc
HKLM\SYSTEM\CurrentControlSet\services\crypt32
HKLM\SYSTEM\CurrentControlSet\services\CryptSvc
HKLM\SYSTEM\CurrentControlSet\services\SCardSvr
HKLM\SYSTEM\CurrentControlSet\services\SCPolicySvc
{ComputerName}_Certificates_reg_.TXT
Microsoft-Windows-CAPI2/Operational
{ComputerName}__evt_*.*

CscClient
DescriptionFile name
HKCU\SOFTWARE\Policies\Microsoft\Windows\NetCache
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\NetCache
HKLM\SOFTWARE\Policies\Microsoft\NetCache
HKLM\SYSTEM\CurrentControlSet\services\CSC
HKLM\SYSTEM\CurrentControlSet\services\CscService
{ComputerName}_CscClient_reg_output.TXT
Microsoft-Windows-OfflineFiles/Analytic
Microsoft-Windows-OfflineFiles/Debug
Microsoft-Windows-OfflineFiles/Operational
Microsoft-Windows-OfflineFiles/SyncLog
{ComputerName}__evt_*.*

DFS Client
DescriptionFile name
DFS Client Information from dfsutil output
{ComputerName}_DfsClient_info.TXT
HKLM\Software\Policies\Microsoft\System\DFSClient
HKLM\SYSTEM\CurrentControlSet\services\DfsC
HKLM\SYSTEM\CurrentControlSet\services\MUP
{ComputerName}_DfsClient_reg_output.TXT

Firewall
DescriptionFile name
[W8/WS2012] Get-NetFirewallProfile
[W8/WS2012] Get-NetFirewallRule
[W8/WS2012] Get-NetIPsecMainModeSA
[W8/WS2012] Get-NetIPsecQuickModeSA
[W8/WS2012] Show-NetFirewallRule
[W8/WS2012] Show-NetIPsecRule -PolicyStore ActiveStore
{ComputerName}_Firewall_info_pscmdlets.TXT
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall
HKLM\SYSTEM\CurrentControlSet\Services\BFE
HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT
HKLM\SYSTEM\CurrentControlSet\Services\MpsSvc
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
{ComputerName}_Firewall_reg_.TXT
Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity
Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurityVerbose
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Microsoft-Windows-Windows Firewall With Advanced Security/FirewallVerbose
{ComputerName}__evt_*.*
netsh advfirewall consec show rule all any dynamic verbose
netsh advfirewall consec show rule all any static verbose
{ComputerName}_Firewall_netsh_advfirewall-consec-rules.TXT
netsh advfirewall export
{ComputerName}_Firewall_netsh_advfirewall-export.wfw
netsh advfirewall firewall show rule name=all
{ComputerName}_Firewall_netsh_advfw-firewall-rules.TXT
netsh advfirewall monitor show consec verbose
{ComputerName}_Firewall_netsh_advfirewall-consec-rules-active.TXT
netsh advfirewall monitor show firewall verbose
{ComputerName}_Firewall_netsh.TXT
netsh advfirewall show allprofiles
netsh advfirewall show allprofiles state
netsh advfirewall show currentprofile
netsh advfirewall show domainprofile
netsh advfirewall show global
netsh advfirewall show privateprofile
netsh advfirewall show publicprofile
netsh advfirewall show store
{ComputerName}_Firewall_netsh_advfirewall.TXT
netsh wfp show boottimepolicy file=
{ComputerName}_Firewall_netsh_wfp-show-boottimepolicy.XML
netsh wfp show filters file=
{ComputerName}_Firewall_netsh_wfp-show-filters.XML
netsh wfp show netevents file=
{ComputerName}_Firewall_netsh_wfp-show-netevents.XML
netsh wfp show options optionsfor=keywords
{ComputerName}_Firewall_netsh_wfp-show-options-optionsforkeywords
netsh wfp show options optionsfor=netevents
{ComputerName}_Firewall_netsh_wfp-show-options-optionsfornetevents
netsh wfp show security netevents
{ComputerName}_Firewall_netsh_wfp-show-security-netevents.TXT
netsh wfp show state file=
{ComputerName}_Firewall_netsh_wfp-show-state
netsh wfp show sysports file=
{ComputerName}_Firewall_netsh_wfp-show-sysports.XML

FolderRedirection
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\Windows\System\Fdeploy
{ComputerName}_FolderRedirection_reg_output.TXT
Microsoft-Windows-Folder Redirection/Operational
{ComputerName}__evt_*.*

General information
DescriptionFile name
Basic system information, including machine name, service pack, computer model, processor name, and processor speed
resultreport.xml

List of user SIDs, group memberships, and permissions through Whoami /all output
{ComputerName}_Whoami.txt
Resultant Set of Policy (RSoP) generated by gpresult.exe utility
{ComputerName}_GPResult.*
System information - MSInfo32 tool output
{ComputerName}_msinfo32.nfo
{ComputerName}_msinfo32.txt

Group Policy client
DescriptionFile name
Microsoft-Windows-GroupPolicy/Operational
{ComputerName}__evt_*.*

Internet Explorer
DescriptionFile name
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings
{ComputerName}_InternetExplorer_reg_output.TXT

IPsec
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec
HKLM\SYSTEM\CurrentControlSet\Services\IKEEXT
HKLM\SYSTEM\CurrentControlSet\Services\IPsec
HKLM\SYSTEM\CurrentControlSet\Services\PolicyAgent
{ComputerName}_IPsec_reg_.TXT
IPsec information from command: netsh dynamic show all
{ComputerName}_IPsec_netsh_dynamic.TXT
IPsec information from command: netsh ipsec static exportpolicy
{ComputerName}_IPsec_netsh_LocalPolicyExport.ipsec
IPsec information from command: netsh static show all
{ComputerName}_IPsec_netsh_static.TXT
W8/WS2012 powershell output for the IPsec
{ComputerName}_IPsec_info_pscmdlets.TXT

Kerberos tickets and TGT
DescriptionFile name
Kerberos Information from klist.exe output
{ComputerName}_Kerberos_klist.txt

Network adapters
DescriptionFile name
W8/WS2012 powershell output for Network Adapter information
{ComputerName}_NetworkAdapters_info_pscmdlets.TXT

Network capture
DescriptionFile name
Netsh Trace: CAB
{ComputerName}_nettrace.cab
Netsh Trace: Network Capture (ETL)
{ComputerName}_nettrace.etl
Network capture information from nmcap.exe output
{ComputerName}_netcap.cap

Network connections
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\Netman
{ComputerName}_NetworkConnections_reg_.TXT
W8/WS2012 powershell output for Network Connections
{ComputerName}_NetworkConnections_info_pscmdlets.TXT

Network LBFO
DescriptionFile name
W8/WS2012 powershell output for Network LBFO
{ComputerName}_NetworkLBFO.TXT

Network list
DescriptionFile name
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList
HKLM\SYSTEM\CurrentControlSet\services\netprofm
{ComputerName}_NetworkList_reg_.TXT
Microsoft-Windows-NetworkProfile/Operational
{ComputerName}__evt_*.*

Network location awareness
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\NlaSvc
{ComputerName}_NetworkLocationAwareness_reg_.TXT
Microsoft-Windows-NlaSvc/Operational
{ComputerName}__evt_*.*

Network Store Interface
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\nsi
HKLM\SYSTEM\CurrentControlSet\services\nsiproxy
{ComputerName}_NetworkStoreInterface_reg_.TXT

Proxy configuration
DescriptionFile name
Copies PAC files from Internet Explorer locations
Network Isolation Policy registry information
Proxy Configuration: Firewall Client Proxy Configuration (ISA/TMG)
Proxy Configuration: IE System
Proxy Configuration: IE User
Proxy Configuration: WinHTTP

SMB Client
DescriptionFile name
HKCU\Network
HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider
HKLM\SYSTEM\CurrentControlSet\Control\SMB
HKLM\SYSTEM\CurrentControlSet\services\LanManWorkstation
HKLM\SYSTEM\CurrentControlSet\services\lmhosts
HKLM\SYSTEM\CurrentControlSet\services\MrxSmb
HKLM\SYSTEM\CurrentControlSet\services\MrxSmb10
HKLM\SYSTEM\CurrentControlSet\services\MrxSmb20
HKLM\SYSTEM\CurrentControlSet\services\MUP
HKLM\SYSTEM\CurrentControlSet\services\NetBIOS
HKLM\SYSTEM\CurrentControlSet\services\NetBT
HKLM\SYSTEM\CurrentControlSet\services\Rdbss
{ComputerName}_SmbClient_reg_output.TXT
SMB Client Information from Net.exe
{ComputerName}_SmbClient_info.TXT

SMB Server
DescriptionFile name
HKLM\SYSTEM\CurrentControlSet\services\LanManServer
HKLM\SYSTEM\CurrentControlSet\services\SRV
HKLM\SYSTEM\CurrentControlSet\services\SRV2
HKLM\SYSTEM\CurrentControlSet\services\SRVNET
{ComputerName}_SmbServer_reg_output.TXT
SMB Server Information from tools such as net.exe
{ComputerName}_SmbServer_info.txt

TCPIP
DescriptionFile name
HKLM\SOFTWARE\Policies\Microsoft\Windows\TCPIP
HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc
HKLM\SYSTEM\CurrentControlSet\services\TCPIP
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6
HKLM\SYSTEM\CurrentControlSet\Services\tcpipreg
{ComputerName}_TCPIP_reg_output.TXT
Microsoft-Windows-Iphlpsvc/Operational
{ComputerName}__evt_*.*
TCP OFFLOAD information from netstat output
{ComputerName}_TCPIP_OFFLOAD.TXT
TCPIP Information from commands such as hostname, ipconfig, route, and netstat
{ComputerName}_TCPIP_info.TXT
TCPIP information from netsh output
{ComputerName}_TCPIP_netsh_info.TXT
TCPIP Services File located at: windir\system32\drivers\etc\services
{ComputerName}_TCPIP_ServicesFile.TXT
W8/WS2012 powershell output for TCPIP
{ComputerName}_TCPIP_info_pscmdlets_net.TXT

WebClient
DescriptionFile name
HKCU\Network
HKCU\Software\Microsoft\Office\14.0\Common\Internet
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider
HKLM\System\CurrentControlSet\Services\MRxDAV
HKLM\SYSTEM\CurrentControlSet\services\WebClient
{ComputerName}_WebClient_reg_output.TXT
WebClient proxy settings from command: netsh winhttp show proxy
{ComputerName}_WebClient_netsh_winhttp-proxy-settings.txt
WebClient proxy settings from proxycfg.exe output
{ComputerName}_WebClient_proxycfg.txt

WinHTTP
DescriptionFile name
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKLM\System\CurrentControlSet\Services\WinHttpAutoProxySvc
{ComputerName}_WinHTTP_reg_output.TXT
WinHTTP proxy settings from command: netsh winhttp show proxy
{ComputerName}_WinHTTP_netsh_proxy-settings.txt
WinHTTP proxy settings from proxycfg.exe output
{ComputerName}_WinHTTP_proxycfg.txt

WinSock
DescriptionFile name
Microsoft-Windows-Winsock-AFD/Operational
Microsoft-Windows-Winsock-WS2HELP/Operational
{ComputerName}__evt_*.*
HKLM\SYSTEM\CurrentControlSet\services\AFD
HKLM\SYSTEM\CurrentControlSet\services\WinSock
HKLM\SYSTEM\CurrentControlSet\services\WinSock2
Registry Information for WinSock and AFD:
{ComputerName}_WinSock_reg_.TXT
Winsock information from netsh winsock output
{ComputerName}_WinSock_netsh.TXT


In addition to collecting the information that is described earlier, this diagnostic package can detect one or more of the following symptoms:

  • Event log messages
  • When a %Component% event trace log file was collected

References

For more information about the Microsoft Automated Troubleshooting Services and the Support Diagnostics Platform, see the following Microsoft Knowledge Base article:  

2598970 Information about Microsoft Automated Troubleshooting Services and Support Diagnostic Platform