Solved

Process Monitor, how to read logs

Posted on 2011-09-22
15
516 Views
Last Modified: 2012-05-12
I have Process Monitor installed and running, but not sure how to read the logs....
0
Comment
Question by:wfcrr
  • 8
  • 6
15 Comments
 
LVL 66

Expert Comment

by:johnb6767
ID: 36580949
It might help to know what you are trying to troubleshoot......
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 36580976
Process Monitor - Hands-On Labs and Examples
http://blogs.technet.com/b/appv/archive/2008/01/24/process-monitor-hands-on-labs-and-examples.aspx

I have referenced this in the past, might help..... But to know EXACTLY what you are trying to resolve will still be of help to us....
0
 

Author Comment

by:wfcrr
ID: 36581185
Windows 7 Pro IE8, two issues. We have a business app runs in IE8. We have IE8 set to open all new windows in a tab, rather than open a new browser. Not sure if I said that right, but at this time, for example, I have 8 pages up, all in the same browser window, but in 8 separate tabs.  The thing that happening is when I click a link to open an email, an Outlook window opens, but the tab goes blank. If I hit the back arrow, the page comes back.  It should do this. It didn't do it when it was XP. Anyway, you posted at length about this in another question on my old account. EE is moving all my old posts over to this new account and I wanted to continue the discussion here, in a new question, as I don't know when they are going to move that question over
0
 

Author Comment

by:wfcrr
ID: 36581198
You had told me to download Process Monitor and run "Result is Access Denied".  I did that this mornign, but don't know how to use what I see in the logs.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 36581319
Gotcha.....

Click the blue icon (to the left of the "A" on the toolbar at the top.

First Column - Select "Result" from the drop down.
Second Column - Select "Is"  from the drop down.
Third Column - MANUALLY type "Access Denied" (no quotes)

Then click the link and see if anything populates.....

Can you post a link to the other thread as well? Need a refresher.....  :-)

0
 

Expert Comment

by:rodynetwork
ID: 36581433
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/Windows_7/Q_27312311.html

I did run Process Monitor with the filter Result is Access Denied and it ran while I went to IE8 and click through the offending processes.  I just don't know how to interpret what I am seeing in the logs...
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 36582082
Did it provide output ONLY when showing just the Access Denied filter?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 66

Expert Comment

by:johnb6767
ID: 36582084
If it was blank, then it was not a permissions issue.
0
 

Author Comment

by:wfcrr
ID: 36582114
The log has a bunch of stuff in it. I just don't know what to do with any of it.
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 36584573
In the right hand side, under the "Result Column" are you seeing NOTHING but "Access Denied"?

You can right click on ANY item in ANY column, and select "Include/Exclude"

Excluding removes the processes/results (in this case, you might need to remove the "Success" entries to remove 85% of the useless data. If you "Include" a process, it ONLY shows results from that process.

Once you are done, remove the Filters you have set from the icon, so next time you dont chase your tail with needless filters set.....

Post a screenshot if you could, and I will help guide you....
0
 

Author Comment

by:wfcrr
ID: 36586591
See if this image is readable.
log.jpg
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 36590790
On the following keys, you should be able to reset the security (to inherit them from thier parent folders), by right clicking these>Permissions>Advanced, and hit the top check box "Include inheritable ......", and then hit "Apply".
This will reset the permissions based on what the parent keys are pushing down.

Then hit the bottom checkbox, and hit "Apply", this will force the child objects to inherit what you just inherited from the parent keys.

If they dont inherit/push properly, they should be set as the following.....

SYSTEM\Full Control
Administrators\Full Control
Users\Read

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinSock2

Same process for these below, to reset them. Here is what they should be set to...

SYSTEM\Full Control
YOUR USER ID\Full Control
Administrators\Full Control

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings

Once you get these reset, retest and if it still fails, lets use Procmon again to continue until you see NO MORE "Access Denieds"....
0
 

Author Comment

by:wfcrr
ID: 36592692
Got a few questions, bear in mind I am a rank novice.  I assume you are telling me "regedit" stuff, so I went to cmd, regedit and navigated to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing and messed around with properties, attempting to give the USER and Administrator permissions of Full Control. Is that what you are saying to do?  Also, I found check boxes for include inheritable and hit Apply, but IE8 still has the tab go blank when I hit an email link.  I am going to try closing and reopen IE8, as I haven't closed the browser since I made those changes.
0
 

Author Comment

by:wfcrr
ID: 36592792
Ok. I'm confused.  I have ProcMon up and running. I have the Filter window up and have removed all other filters and have only the Result is Access Denied filter added. There is red X next to Result is.  I hit apply and I see the event log window has bazillions of things being captured.  I am on the users machine...not sure what is different but I see what too much in the event log for it to be useful.  What am I missing in the PrcMon setup?
0
 
LVL 66

Accepted Solution

by:
johnb6767 earned 500 total points
ID: 36594272
The defaults are fine, it should look like the image below. The only thing listed should be ACCESS DENIED entries....

 Process Denied Image
As for the permissions, what I was referring to is the boxes at the bottom, once you hit the Advanced Button. Using these, will automatically reset the permissions based on the parent folders, without having to reset them manually.....
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
This Micro Tutorial will teach you how to the overview of Microsoft Security Essentials. This is a free anti-virus software that guards your PC against viruses, spyware, worms, and other malicious software. This will be demonstrated using Windows…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now