Understand Troubleshooting Methodology



Similar documents
Hands-On Microsoft Windows Server 2008

Windows 7, Enterprise Desktop Support Technician

Windows 7, Enterprise Desktop Support Technician Course 50331: 5 days; Instructor-led

Windows Operating Systems. Basic Security

"Charting the Course to Your Success!" MOC D Windows 7 Enterprise Desktop Support Technician Course Summary

Integrating LANGuardian with Active Directory

Module 3: Resolve Software Failure This module explains how to fix problems with applications that have problems after being installed.

Server Manager Performance Monitor. Server Manager Diagnostics Page. . Information. . Audit Success. . Audit Failure

Course Description. Course Audience. Course Outline. Course Page - Page 1 of 12

Table Of Contents. - Microsoft Windows - WINDOWS XP - IMPLEMENTING & SUPPORTING MICROSOFT WINDOWS XP PROFESSIONAL...10

Also on the Performance tab, you will find a button labeled Resource Monitor. You can invoke Resource Monitor for additional analysis of the system.

Events Forensic Tools for Microsoft Windows

20410: Installing and Configuring Windows Server 2012

Understanding Windows Server 2003 Networking p. 1 The OSI Model p. 2 Protocol Stacks p. 4 Communication between Stacks p. 13 Microsoft's Network

המרכז ללימודי חוץ המכללה האקדמית ספיר. ד.נ חוף אשקלון טל' פקס בשיתוף עם מכללת הנגב ע"ש ספיר

Installing Active Directory

Managing and Maintaining Windows Server 2008 Servers

Installing and Configuring Windows Server 2012 MOC 20410

50331D Windows 7, Enterprise Desktop Support Technician (Windows 10 Curriculum)

Signal Customized Helpdesk Course

Installing and Configuring Active Directory Agent

Contents. Supported Platforms. Event Viewer. User Identification Using the Domain Controller Security Log. SonicOS

Find the Who, What, Where and When of Your Active Directory

Workshop 5051A: Monitoring and Troubleshooting Microsoft Exchange Server 2007

Monitoring Windows Event Logs

REMOTE INFRASTRUCTURE MANAGEMENT COURSE CURRICULUM

Implementing and Supporting Microsoft Windows XP Professional

MS Installing and Configuring Windows Server 2012

Managing and Maintaining a Windows Server 2003 Network Environment

DC Agent Troubleshooting

MCSA Security + Certification Program

Configuring Sponsor Authentication

Advanced Event Viewer Manual

Course Outline: Course Installing and Configuring Windows Server 2012

Lesson Plans Microsoft s Managing and Maintaining a Microsoft Windows Server 2003 Environment

Server Installation, Administration and Integration Guide

Implementing, Managing, and Maintaining a Microsoft Windows Server 2003 Network Infrastructure

Planning for Windows Server 2008 Servers

Docufide Client Installation Guide for Windows

Dell Active Administrator 8.0

Configuring Security for SMTP Traffic

MS MCITP: Windows 7 Enterprise Desktop Support Technician Boot Camp

OfficeScan 10 Enterprise Client Firewall Updated: March 9, 2010

Installing and Configuring Windows Server 2012

MCSA Objectives. Exam : TS:Exchange Server 2007, Configuring

Before deploying SiteAudit it is recommended to review the information below. This will ensure efficient installation and operation of SiteAudit.

Windows Server 2012 Server Manager

NETWRIX ACCOUNT LOCKOUT EXAMINER

Implementing, Managing and Maintaining a Microsoft Windows Server 2003 Network Infrastructure: Network Services Course No.


Installation Notes for Outpost Network Security (ONS) version 3.2

Log Server Error Reference for Web Protection Solutions

RSA Authentication Manager 8.1 Virtual Appliance Getting Started

Objectif. Participant. Prérequis. Remarque. Programme. Windows 7, Enterprise Desktop Support Technician (seven)

June 20, Copyright 2012 by World Class CAD, LLC. All Rights Reserved.

MCSE Core exams (Networking) One Client OS Exam. Core Exams (6 Exams Required)

Configuration Information

Shavlik NetChk Protect 7.1

MCITP MCITP: Enterprise Administrator on Windows Server 2008 (5 Modules)

WhatsUp Event Alarm v10.x Listener Console User Guide

How To Upgrade A Websense Log Server On A Windows 7.6 On A Powerbook (Windows) On A Thumbdrive Or Ipad (Windows 7.5) On An Ubuntu (Windows 8) Or Windows

Web Security Log Server Error Reference

Intel Entry Storage System SS4200-E Active Directory Implementation and Troubleshooting

IDENTIKEY Appliance Administrator Guide

Kerio VPN Client. User Guide. Kerio Technologies

Outline SSS Microsoft Windows Server 2008 Hyper-V Virtualization

Exam : Installing and Configuring Windows Server 2012

MONITORING MICROSOFT WINDOWS SERVER 2003

Introduction: Using Windows Server 2008 How-To p. 1 How to Educate Yourself About Windows Server 2008 p. 2 How to Benefit from This Book p.

Module 10: Maintaining Active Directory

Installation Guide for Pulse on Windows Server 2008R2

Troubleshooting and Supporting Windows 7 in the Enterprise

Core Protection Suite

Chapter 8 Monitoring and Logging

Move a VM 3.0 with AD Integration to a new server. Creation date: 17/06/2008 Last Review: 26/06/2008 Revision number: 1

Monitoring Replication

PC Power Down. MSI Deployment Guide

Table of Contents WELCOME TO ADAUDIT PLUS Release Notes... 4 Contact ZOHO Corp... 5 ADAUDIT PLUS TERMINOLOGIES... 7 GETTING STARTED...

WatchGuard Mobile User VPN Guide

RSA Authentication Manager 7.1 Basic Exercises

Configuring WMI Performance Monitors

Converting InfoPlus.21 Data to a Microsoft SQL Server 2000 Database

Service Overview & Installation Guide

Lesson Plans Configuring Exchange Server 2007

Symantec Mail Security for Microsoft Exchange Management Pack Integration Guide

Session 17 Windows 7 Professional DNS & Active Directory(Part 2)

Deploying Remote Desktop Connection Broker with High Availability Step-by-Step Guide

Using WMI Scripts with BitDefender Client Security

NOTE: Labs in this course are based on the General Availability release of Windows Server 2012 R2 and Windows 8.1.

Setting up an MS SQL Server for IGSS

ACTIVE DIRECTORY DEPLOYMENT

MCSE Objectives. Exam : TS:Exchange Server 2007, Configuring

Managing IBM Lotus Notes Domino 7 Servers and Users. Course Description. Audience. Course Prerequisites. Machine Requirements.

Operating System Installation Guide

How To Complete A Lab On Windows 7 From A Dvd

MCSA/MCITP: Enterprise Windows Server 2008 Course 9952; 14 Days, Instructor-led

Getting Started With Delegated Administration

Installation Guide for Pulse on Windows Server 2012

Hands-On Microsoft Windows Server Chapter 12 Managing System Reliability and Availability

Carisbrooke. End User Guide

Transcription:

Understand Troubleshooting Methodology

Lesson Overview In this lesson, you will learn about: Troubleshooting procedures Event Viewer Logging Resource Monitor

Anticipatory Set If the workstation service failed to start, where would this event be recorded?

Troubleshooting Procedures Determine whether the problem is systemic or specific o Systemic An approach used when there is more than one resource experiencing problems Virus outbreak can affect several systems on a single network. Solution: Isolate the network and clean affected machines. o Specific An approach used when a problem has been isolated to a single system and related to a process, program or hardware. All other systems remain unaffected. A system has a disk failure. This does not affect any other systems on the network. Solution: Replace the failed disk.

Troubleshooting Procedures (continued) Event Viewer is the first tool to be used to determine the time and type of problem that a machine may be having.

Event Viewer Event Viewer has three default logs: 1. Application Contains events logged by applications or programs 2. Security Records events such as valid and invalid logon attempts, as well as events related to resource use such as creating, opening, or deleting files or other objects. An administrator can specify what events are recorded in the security log. 3. System Contains events logged by Windows system components that are predetermined by Windows Other log files found in event viewer, if the computer is a Domain Controller: o o o Directory Service Contains events logged by the Windows directory service File Replication Service Contains events logged by the Windows File Replication service DNS Server Contains events logged by the Windows DNS service such as events that resolve DNS names to Internet protocol (IP) addresses

Event Viewer (continued) Event Viewer event types: o Error a significant problem, such as loss of data or loss of functionality. o Warning might not be significant, but may indicate a possible future problem. o Information describes the successful operation of an application, driver, or service. o Success Audit an audited security access attempt that succeeds. o Failure Audit an audited security access attempt that fails. The Event Log service starts automatically when you start Windows. All users can view application and system logs. Only administrators can gain access to security logs.

Event Viewer (continued) Event Filtering can filter events based on a set of rules to determine which events in the log would be visible. Custom Views saved filters that you intend on using again.

Logging Windows primary log locations 1. Event Viewer logs %systemroot%\system32\winevt\logs\<log file>.evtx 2. Microsoft firewall logs %systemroot%\system32\logfiles\firewall\firewall.log Most applications create their own log files upon installation.

Resource Monitor A system tool that allows you to view information about the use of hardware (CPU, memory, disk, and network) and software (file handles and modules) resources in real time. You can filter the results according to specific processes or services that you want to monitor.

Resource Monitor (continued) Allows you to view all processes and either selectively end a single process or the entire process tree. You can also temporarily suspend a process. Allows you to view a process wait chain, and to end processes that are preventing a program from working properly. A process that is not responding will appear as a red entry in the CPU table of the Overview tab, and in the Process table of the CPU tab.

Lesson Review What are the three default event logs found in Windows Event Viewer? What is the default location for the event logs? What is the difference between systemic and specific troubleshooting?