Microsoft Defender for Endpoint
Endpoint protection

Data Collection Analyzer

In brief

The data collection analyzer table now uses updated links for MpCmdRun.exe and Endpoint DLP, and the -v entry includes additional troubleshooting examples such as Cloud Protection reporting and Platform Update failures.

What Defender admins need to know

Administrators using the analyzer have more current troubleshooting references and scenarios; no configuration change is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

|-b|Same as -c but the process monitor trace will be initiated during next boot and stopped only when the -b is used again.|Process Monitor (ProcMon) to initiate a boot trace when investigating a driver or service or application startup delay related issue. This scenario can also be used to investigate a slow boot or slow sign-in.|One of the following processes:

  • MSSense.exe
  • MsSenseS.exe
  • SenseIR.exe
  • SenseNdr.exe
  • SenseTVM.exe
  • SenseAadAuthenticator.exe
  • SenseGPParser.exe
  • SenseImdsCollector.exe
  • SenseSampleUploader.exe
  • MsMpEng.exe
  • NisSrv.exe
| |-e|Calls into Windows Performance Recorder to collect Defender AV Client tracing (AM-Engine and AM-Service) for analysis of Antivirus cloud connectivity issues.|When troubleshooting Cloud Protection (MAPS) reporting failures.|MsMpEng.exe| |-a|Calls into Windows Performance Recorder to collect a verbose performance trace specific to analysis of high CPU issues related to the antivirus process (MsMpEng.exe).|When troubleshooting high cpu utilization with Microsoft Defender Antivirus (Antimalware Service Executable or MsMpEng.exe) if you already used the Microsoft Defender Antivirus Performance Analyzer to narrow down the /path/process or /path or file extension contributing to the high cpu utilization. This scenario enables further investigate what the application or service is doing to contribute to the high cpu utilization.|MsMpEng.exe| |-v|Uses antivirus MpCmdRun.exe command line utilityMpCmdRun.exe command line utility with most verbose -Trace flags.|Anytime an advanced troubleshooting is needed. Such as when troubleshooting Cloud Protection (MAPS) reporting failures, Platform Update failures, Engine update failures, Security Intelligence Update failures, False negatives, etc. Can also be used with -b, -c, -h, or -l.|MsMpEng.exe| |-t|Starts verbose trace of all client-side components relevant to Endpoint DLP, which is useful for scenarios where DLP actionsDLP actions aren't happening as expected for files.|When running into issues where the Microsoft Endpoint Data Loss Prevention (DLP) actions expected aren't occurring.|MpDlpService.exe| |-q|Calls into DLPDiagnose.ps1 script from the analyzer Tools directory that validates the basic configuration and requirements for Endpoint DLP.|Checks the basic configuration and requirements for Microsoft Endpoint DLP|MpDlpService.exe| |-d|Collects a memory dump of MsSenseS.exe (the sensor process on Windows Server 2016 or older OS) and related processes. - * This flag can be used with above mentioned flags. - ** Capturing a memory dump of PPL protected processes such as MsSense.exe or MsMpEng.exe isn't supported by the analyzer at this time.|On Windows 7 SP1, Windows 8.1, Windows Server 2008 R2, Windows Server 2012 R2, or Windows Server 2016 running w/ the MMA agent and having performance (high cpu or high memory usage) or application compatibility issues.|MsSenseS.exe| |-z|Configures registry keys on the machine to prepare it for full machine memory dump collection via CrashOnCtrlScroll. This would be useful for analysis of computer freeze issues. * Hold down the rightmost CTRL key, then press the SCROLL LOCK key twice.|Machine hanging or being unresponsive or slow. High memory usage (Memory leak): a) User mode: Private bytes b) Kernel mode: paged pool or nonpaged pool memory, handle leaks.|MSSense.exe or MsMpEng.exe|