Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Decoding SCP Support Tool Logs (Window OS)

Decoding SCP Support Tool Logs

*Applicable to Windows OS

Overview: The SCP support tool is your best bet when troubleshooting SCP-related issues. It can be difficult to troubleshoot issues when you are unable to read the logs collected. This document aims to provide instructions on how to decode and review these logs.

There are two (2) logs we are going to focus on: the ETL traces and Syscore.etl.

 

SCP ETL traces 

The ETL traces are log files that contain detailed information about events and activities related to the SCP application.

The ETL traces are generated by SCP and contain information about various activities, such as web requests, security events, and other SCP-related activities.

These traces are in the following path: C:\ProgramData\Skyhigh\SCP\Logs

*SCPContinuousEtlTraces.etl contains the most current information

*SCPContinuousEtlTraces.etl1/2/3 contains archived information

 

Decoding SCPContinuousEtlTraces.etl

The SCP ETL traces are decoded using the same SCP Support tool used to collect them. I highly recommend downloading and saving the tool on your local machine. Download: SCP Support tool

  1. Connect to VPN

  2. Run the SCP Support tool as an admin

  3. Select Analysis Mode (might take a few for this option to become available) 

  1. Browse for the support tool logs

  2. Select the Logs folder 

The SCP support tool should determine the version automatically

  1. Press Decode

The decoding process may take a few minutes – the tool might even become ‘Unresponsive.’ Be patient.

 

IF the tool prompts the following error: “no symbols or decoder,” follow the steps below:

 

  1. Open File Explorer

  2. Map Network Drive

  3. \\10.213.175.51\mcp\BuildSymbols

    1. Username: mcafee\mcp

    2. Password: mcp

  1. Copy and paste the tracefmt.exe to \Logs folder within SCP support logs

  2. Find the folder matching your version > 64 bit

  3. Copy and paste tmffiles folder to \Logs folder within SCP support logs

  1. Press Decode on tool

 

Once the logs have been decoded, you should see a few more files within the Logs directory. 

 

You will need to remove the behind the SCP version #

  • Was this article helpful?