When troubleshooting an issue on devices, we will often ask you for the OPSWAT Agent logs from your machine. There are 2 ways to retrieve the Agent logs:
OPTION 1: Collect the logs on a device directly.
OPTION 2: Remotely retrieve the logs. This requires that you have administrator permission on your organization's OPSWAT Central Management account and the device is connecting to the OPSWAT Central Management servers.
OPTION 1: Collect the Agent's logs on a device directly
This option is only available for Windows and macOS' persistent Agent.
On Windows devices:
If you are using Windows installed client, the process is very simple. Just download this tool, run it, and the log files will automatically be placed in a zip file on your desktop. This zip file may be very large.
On macOS devices:
If you are using the macOS installed client, the process is very simple. Just download this tool, run it, and the log files will automatically be placed in a zip file on your desktop. This zip file may be very large.
You can find your logs in the following locations:
Agent logs: %ProgramData%\OPSWAT\Gears\logs\
Crash dumps: %ProgramData%\OPSWAT\Gears\logs\reports\
SDK logs: %ProgramData%\OPSWAT\Gears\sdk\
OPG (verification file) logs: %HOMEPATH%\AppData\Local\OPSWAT\Gears\Logs
Agent log: the file gears-ondemand.log should be located in the same folder of the the executable file.
Crash dumps: %HOMEPATH%\AppData\Local\CrashDump
Note: If the on-demand agent is triggered by Pulse Secure Host Checker, you can find log files at %appdata%\ Pulse Secure \Host Checker\policy_XXX (for example: C:\Users\bob\AppData\Roaming\Pulse Secure\Host Checker\policy_1)
Installed client: ~/Library/Logs/Gears/logs and /Library/Logs/Gears/logs
On-demand client: On the desktop* as 'gears-ondemand.log'
Crash dump:~/Library/Logs/DiagnosticReports and /Library/Logs/DiagnosticReports
When running the Mac on-demand client as root, the logs will appear in /var/root/Desktop/gears-ondemand.log and additional malware logs will appear in ~/Library/Logs/Gears/logs/Metascan-Client-V2.log
Logs are only stored in memory, but can be sent via email from within the app by selecting the corresponding option on the feedback screen.
OPTION 2: Remotely retrieve the Agent 's logs from the OPSWAT Central Management console
Note: This option requires
You have administrator permission on your organization's OPSWAT Central Management account.
The device is connected to the OPSWAT Central Management servers.
As an administrator of the OPSWAT Central Management account, you can follow the below steps:
Log into OPSWAT Central Management console.
Go to Inventory > Devices.
Search for a device you would like to get logs of.
Select devices and choose the Fetch log action.
When a device is connecting to OPSWAT Central Management cloud, the device will collect log files and submit to OPSWAT Central Management cloud.
To download log file you fetched from OPSWAT Central Management console, go to Device details of the corresponding device and click on Events > Actions.
Sending the Logs to Support:
If you have been asked to share the files with support and they are too large to email or attach to the support ticket, please use the Large File submission feature on the OPSWAT support portal: https://portal.opswat.com/en/support/requests/large_file