Forensic Tools - Working with Logs

Generate a HAR file
Background HAR (HTTP Archive) files can be helpful in analyzing the requests and responses, with their associated contents and times, made while interactin...
Thu, May 25, 2023 at 2:50 PM
FTKC 7.6+ : Site Server Log Accessibility
Site Server Log Accessibility From version 7.6 and above of FTK, Site Server logs can now be configured to automatically be stored in a specific location. ...
Thu, May 25, 2023 at 2:49 PM
Collecting Crash Dumps
Overview While troubleshooting, you may be asked to collect crash dumps and provide them to Support.  The following steps will allow up to 10 Crash Dumps t...
Wed, May 24, 2023 at 3:45 PM
Capture Processing Engine Debug/Error Logs
Introduction: Sometimes, diagnosing an issue with processing can be difficult and may necessitate reviewing debug data.  The following will allow you to cap...
Wed, May 24, 2023 at 1:09 PM
Capture debug/error logs for FTK Imager
Introduction: Sometimes, diagnosing an issue with Imager can be difficult and may necessitate reviewing debug data.  The following will allow you to capture...
Wed, May 31, 2023 at 2:10 PM
How do I use DTCPing?
Question How can I use Microsoft's DTCPing tool to verify that the Distributed Transaction Coordinator is communicating correctly?   Answer DTCPing ...
Thu, May 25, 2023 at 2:59 PM
Disable EP log compression
Question How do I disable compression of the Evidence Processor debug logs in the "Jobs" folder?   Note: Disabling debug log compression can...
Tue, Aug 29, 2023 at 7:13 AM
Forensic Tools Product Log Locations
Question Where are the various Forensic Tools product logs located by default?   Answer FTK Central: %PUBLIC%\Documents\AccessData\AccessDataLogs\adg...
Wed, Jul 26, 2023 at 8:51 AM