Security Compliance
How to gather diagnostics for SolarWinds products
Detailed instructions on how to collect diagnostic logs from products not hosted on the SolarWinds platform.
First published date
Last published date
Overview
- Access Rights Manager (ARM)
- Dameware
- Database Performance Analyzer (DPA)
- Kiwi CatTools
- Kiwi Syslog
- Network Topology Mapper (NTM)
- Patch Manager
- Security Event Manager (SEM)
- Serv-U
- SolarWinds Platform
- SQL Sentry
- Task Factory
- Web Help Desk (WHD)
Product section
Cause
Resolution
Collect diagnostics for your product and send them to SolarWinds Technical Support.
- ARM
- Dameware
- DPA
- Kiwi CatTools
- Kiwi Syslog Server
- NTM
- Patch Manager
- SEM
- Serv-U
- SolarWinds Platform
- SQL Sentry
- Task Factory
- WHD
ARM
Please use the ARM Diagnostics application provided with ARM, it can be located on the Start Menu > SolarWinds.
The application will save a .zip file in the location provided (default is the desktop of the logged in user) which can then be uploaded to the Serv-U link provided by support. Log files, relevant Windows Event logs, and system information is included. Options allow comments and additional files to be added.
In the case where the ARM Diagnostics application will not start (an issue in some 2023 and 2024 versions of ARM), please follow the steps below to compile the log files manually.
On the ARM server (or collector server, if the issue is regarding collector services):
- Open Windows File Explorer to navigate to C:\ProgramData\protected-networks.com\8MAN (default location).
- Right-click on the log folder and select Send To > Compressed (zipped) folder. This will create a .zip file that contains all of the log files.
- Upload the created .zip log file to the Serv-U location provided by support.
Starting with Dameware 12.1.1, you can collect diagnostics for your Dameware issues using the updated Dameware Diagnostics tool. This tool enables you to review diagnostics or share them with SolarWinds support.
If you select Keep data selection, the same filters are populated the next time you use the Diagnostics Tool. You can also use the drop-down menu beneath the Included data section to skip log folders older than a given number of days or choose not to skip any log files.
- To get to Dameware Diagnostics:
- For Central Server Diagnostics:
- Open File Explorer and go to: C:/Program Files (x86)/SolarWinds/Dameware Central Server/SolarWindsDiagnostics.exe
- Double-click SolarWindsDiagnostics.exe.
- For Remote Support Diagnostics:
- Open File Explorer and go to: C:/Program Files (x86)/SolarWinds/Dameware Remote Support/SolarWindsDiagnostics.exe
- Double-click SolarWindsDiagnostics.exe.
- For Central Server Diagnostics:
- When SolarWindsDiagnostics.exe opens, save to the default location or choose your own location. The date is automatically embedded in the zip file name.
- Click Advanced Data Collection Options and expand Dameware Server Diagnostics (or Dameware Remote Support Diagnostics, as applicable) to select or de-select the filters you want to use.
- Click Start and save diagnostics. Diagnostics are generated in a file.
- To view the zip file, click Open file location and open the zip file you created.
- When you are finished reviewing the diagnostics file, click Finish. The Diagnostics Tool closes.
Option 1:
If you can access the SolarWinds DPA web interface, go to the Options page and then click on the Support tab (or go to the Support section for older Ignite versions). Click on the button (or link for older versions) that says All Log Files (Zipped). This will zip up all relevant log files from Ignite and prompt you to save the archive on your desktop.
Option 2:
If you can’t bring up the DPA web page, navigate to the following directory and zip or tar.gz up the logs directory from there.
- On Windows, the default directory is installdir\iwc\tomcat\logs
-
A good way to find your path for your installation is to open services.msc on the server. Look for the Service called "Ignite PI Server", right-click this, and select properties. The path to the executable will show you to the tomcat folder.
-
- On UNIX/Linux, the default directory is installdir/iwc/tomcat/logs/
- To zip the logs when you find the path, run the command from the tomcat directory.
tar -czvf logs.tar.gz logs
- One way to look for DPA's path is with a find command
find / -name "tomcat"
- Another way to find the path for your install is to search for the process if DPA is running with the command the path may show where DPA is running from the java path. Often this is install home/iwc/jre_linux.
ps -ef | grep dpa
- One way to look for DPA's path is with a find command
Kiwi CatTools
-
RDP to the server where you install Kiwi CatTools Application.
-
Open the Kiwi CatTools.
-
On the activities pane, select Stop Timer.
Note: If the activities is/are not running ignore step 3 and proceed to step 4.
-
On the Kiwi CatTools Console>File>Debug select Create diagnostics for Technical Support.
-
A prompt message will appear that will give you options to select what diagnostics files you want to create. Select the files that you want to create and choose
-
Next option will provide you the option to select the device that you want to capture logs to be included and variation files that you want to include. Once you have selected the capture logs and the variation files please select "Create".
-
After selecting the "Create Tab" a message prompt like the image below will appear. This indicates that a file TechSupport.zip is successfully created.
-
The file is located in the folder C:\Program Files (x86)\CatTools3\Reports
Note: Once you have created the Diagnostics file you need to select "Run Now" on the Activities pane so that Kiwi CatTools can backup the configuration of your devices.
Kiwi Syslog Server
Standard Diagnostic
- Open Kiwi Syslog Service Manager.
- Go to File > Create Tech-Support File (Zip).
- The .zip file is generated automatically. The location of the file is indicated on the message window that is displayed once the file is successfully created.
- You should also gather the following information and include it in the packet passed to SolarWinds support:
- Physical\Virtual Machine.
- CPU/Memory usage, OS version, and others. Run
msinfo32command to get the system information. - Check EventLogs for issues and, if possible, export Eventlogs on that System.
- Screenshot(s) of the issue and/or any error messages.
Kiwi Web Access Logs
C:\Program Files\UltiDev\Cassini Web Server for ASP.NET 2.0\UltiDevCassinWebServer2a.trace.logC:\Program Files (x86)\SolarWinds\Kiwi Syslog Web Access\html\KiwiSyslogWebAccess.log
Note: Starting from version 9.8, Kiwi Web Access is now being hosted in IIS.
Kiwi Syslog Server NG
- Open Services.
- Stop the Kiwi Syslog Server NG service.
- Navigate to C:\ProgramData\SolarWinds\KiwiSyslogService\logs and remove all logs.
- Restart the Kiwi Syslog Server NG service, and reproduce the issue diagnostics are needed for.
- Navigate to C:\ProgramData\SolarWinds\KiwiSyslogService\logs and archive the newly generated log files as a zip.
NTM
- Open the Map. Enter the password if asked.
- Click HELP on the menu.
- Under Support Tools, click Create Tech Diagnostic File.
Patch Manager
Enable Server Side Logging
-
In the navigation pane, click Patch Manager System Configuration.
-
In the center pane, click Log Adjuster.
-
In the Log Adjuster window, modify the Logging Level to Verbose, and click Apply.
When the test is over, change the logging level back to the previous value in order to save disk space on your server.
-
Launch the problematic task and wait for it to run to completion/error.
-
After the task is completed, launch the Patch Manager Diagnostic Tool from one of the following locations:
- Start menu
- C:\Program Files\SolarWinds\Patch Manager\Server\ServerDiagnostics.exe
Patch Manager creates a zipped folder named SolarWindsDiagnostics.zip.
Enable Client / Agent Side Logging
WMI providers + Agent
- Enable WMI providers logging. This also works for the agent.
- Run regedit, go to HKEY_LOCAL_MACHINE\SOFTWARE\EminentWare\Logging, add DWORD (key=value):
- Enable=1
- Level=1
- Options=1
- Logging=15 (maximum logging level)
- Run regedit, go to HKEY_LOCAL_MACHINE\SOFTWARE\EminentWare\Logging, add DWORD (key=value):
- Enable agent logging through the PaM console.
- Go to Patch Manager System Configuration\Policy Editor.
- Either create a new policy and then assign it to the desired scope or edit the default policy.
- Edit 6 entries:
- Agent Logging
- Logging Enabled=1
- Logging Level=15
- Logging Options=1
- Worker Process
- Logging Enabled=1
- Logging Level=15
- Logging Options=1
- Agent Logging
- Agent logs are located in C:\ProgramData\Solarwinds\Logs\PM on PM Agent nodes and WMI Provider (non-agent) logs are located under C:\Windows\system32\WBEM\Logs\
SEM
Collecting SEM Appliance Debugging Information
If you are running SEM versions 2019.4 and later, follow these steps:
- Visit https://your-sem-server/webui/settings to access the HTML5 console.
- On the Settings page, click the System Resources tab, and then click Download Debug logs.
- Wait for a few minutes to be prompted with the debug logs (.tgz file) to download to your system.
If your SEM virtual appliance is versions 6.7 and lower, follow these steps:
- Connect to your SEM virtual appliance using either the vSphere/Hyper-v "console" view or an SSH client like PuTTY on port 32022 (port 22 is also available if version 6.3.1 or newer)
- If you are using an SSH client, log in to your SEM virtual appliance using your CMC credentials established during activation or changed anytime later.
- At the cmc> prompt, type manager and hit return.
- At the cmc>manager prompt, enter debug.
- Press Enter and specify whether you want to send the debugging files as an email or save them to a network location. Note: When you choose to send the debugging files in an email, send the files to yourself first. Debug files larger than 10 MB might be blocked by mail servers.
- Follow the prompts to generate the files.
- Verify the script generated three files: a .tgz file, a .log file, and a .txt file. Support only needs the .tgz file, but sending all 3 files .tgz, .log, .txt) is fine. Note: None of these files contain any Alert data or other data from your SEM database.
- Type exit to return to the cmc> prompt. Repeat the same command until you exit the SSH session if you want to close it.
Gathering Debug logs from SEM agent:
- On Windows: Locate the file C:\windows\syswow64\ContegoSPOP\collectLogs.bat, right-click, and then select Run as administrator.
Grab the file created for SolarWinds support: "C:\windows\syswow64\ContegoSPOP\lemAgentLogs.cab."
Windows: C:\Windows\SysWOW64\ContegoSPOP\ - On Linux/Unix AgentsLinux: /usr/local/contego/ContegoSPOP/spoplog.txt
Mac: /Applications/TriGeoAgent/spoplog.txt
Serv-U
Navigate to the install location, in Windows at C:\ProgramData\RhinoSoft\Serv-U by default. If Serv-U is running on Linux, the default location is /usr/local/Serv-U.
Select and zip the following logs:
- Serv-U.Archive.
- Serv-U Domain logs (see the Setting Up Serv-U's Log ).
- Serv-U-StartupLog.txt
- Debugsocket* logs if available.0
SolarWinds Platform
Prior to 2022.3, the SolarWinds Platform was known as the Orion Platform. The steps to gather differ slightly depending on version and whether the Web Console is available.
Collect diagnostics on Orion Platform 2018.4 and later if Web Console is accessible
- Log in to the Orion Web Console, click Settings > My Deployment, and click the Diagnostics tab.
- Select the server to collect diagnostics, click Collect Diagnostics, and complete the wizard. See Collect diagnostics from the Orion Web Console for more details. The diagnostics that are collected are stored on the Orion server in the C:\ProgramData\SolarWinds\Diagnostics folder.
- If the page doesn't load, generate the diagnostics per steps in Orion Platform 2018.2 and earlier.
- If the page doesn't load, generate the diagnostics per steps in Orion Platform 2018.2 and earlier.
Collect diagnostics on Orion Platform 2018.2 and earlier, or if Web Console is not accessible on Orion Platform 2018.4 and later.
- Log on to the SolarWinds Server you wish to generate diagnostics from.
- In the Windows Start Menu, navigate to SolarWinds Platform Diagnostics in the SolarWinds Platform > SolarWinds Diagnostics program folder, for example, using the Search Windows option in your toolbar. The tool may also be opened by navigating to the install directory, by default at C:\Program Files (x86)\SolarWinds\Orion\ or C:\Program Files\SolarWinds\Orion\ and running SolarWindsDiagnostics.exe.
- Click the start button and save the zip to the Desktop.
It will take a few minutes to generate the diagnostics zip file.
SQL Sentry
Enable Error Logging (Logging > Monitoring Service > Errors)
Ensure error logging is enabled for the monitoring services. Allow a few minutes to pass to generate errors in the log.
Retrieve the Error Log
Once the log has been generated, navigate to the SQL Sentry installation directory on the server hosting a monitoring service and locate the file called rolling-log.txt. Note that you may have several of these files, and you may need to retrieve these files from other machines if your environment has multiple sites with errors. More file locations here.
Task Factory
-
Open your Visual Studio package containing the Task Factory component.

-
Select the Task Factory component, then select the F4 key to open the properties window.

-
Go to the Misc properties section, then enter a fully qualified file path and name in the LogFileLocation property.
Note: The file path and name should take the following example format: C:\Users\username\Desktop\LogFile.txt.
-
Save your package and LogFileLocation property settings. Execute the package to generate the file in the specified location.



WHD
Replicate the issue with the logs in Debug mode
To ensure that information about the issue is captured, put the logs in debug mode and replicate the issue.
- Make sure all logs are in Debug mode:
- In the Web Help Desk main menu bar, click Setup.
- Under General, click Logs.
- Change all log settings to Debug.
- Replicate the issue.
- Run the HealthCheck report as described in one of the following sections.
Run HealthCheck on Windows
- Navigate to your
<WebHelpDesk>\HealthCheckUtilitydirectory. - Right-click
start_healthcheck.batand select Run as Administrator. - When the utility is finished, locate the following ZIP file in the
HealthCheckUtilitydirectory:healthCheckReportYYYYMMDDHHMMSS.zip
whereYYYYMMDDHHMMSSis the date and time you ran the utility.
Run HealthCheck on OS X and Linux
- Make sure all logs are in Debug mode:
- Open a terminal window.
- Execute the following:
cd <WebHelpDesk>/HealthCheckUtility sudo ./start_healtchck.sh
- When the utility is finished, locate the following ZIP file in the
HealthCheckUtilitydirectory:healthCheckReportYYYYMMDDHHMMSS.zip
whereYYYYMMDDHHMMSSis the date and time you ran the utility.
Send to SolarWinds Technical Support
To upload your diagnostics, create a support case in the Customer Portal.
-
Log in to the SolarWinds Customer Portal.
-
Open a Support Case. You can do this one of two ways:
-
On the Customer Portal menu bar, navigate to Technical Support > Open a Support Case.
-
Scroll to the bottom of the Home page and click Open a new Support Case.
-
-
After you submit a case, click Upload Diagnostics.
Note: You have the option to upload your diagnostics as you create your support case, or you can upload your diagnostics up to 30 days later.
The Serv-U File Sharing page appears with options to upload one or more files.
-
To upload one or more files, click Browse to find and select your files, and then click Upload. After uploading your files, the case is updated providing Support representatives access to the diagnostic files.