About Windows Agent Must Gather V3.0
Guardium Windows Agent Must Gather V3.0 (a.k.a. Windows S-TAP Must Gather) is the latest must gather script, which is released in Guardium V11.5.
It's included in all Guardium Windows agents (GIM, S-TAP, GAM, CAS, FAM monitor, FAM crawler, FDEC for NAS/SP, FAM for NAS/SP) in V11.5, and will be back-ported to all supported versions.
Index
2. What is "S-TAP mode" and "STANDALONE mode"?
When you run diag.bat (or diag.ps1) under %WINSTAP_DIR%\Bin, the script will run as S-TAP mode. This will use S-TAP features. For example, use ExternalZip.exe to create a zip file, and upload the zip file to the collector using Upload Feature.
You can also run Must Gather from Guardium GUI, or from Windows Start menu. These are available only when Windows S-TAP is installed.
On the other hand, diag.bat and diag.ps1 are also included in other Guardium Windows agents such as GIM, GAM, CAS, FAM Monitor, FAM Crawler, FAM for NAS, etc... Also, you can put diag.bat and diag.ps1 in any location (e.g. C:\tmp) on Windows and run it. In these cases, diag.bat (diag.ps1) will not use any Windows S-TAP feature, and will run as STANDALONE mode. This is a new feature in Must Gather V2.1.
There are some differences between S-TAP mode and STANDALONE mode. See below for details. Must Gather script temporarily gathers all files to ZIP Source directory and create a zip file under ZIP Target directory, then clean up the temporarily gathered files in ZIP Source directory.
|
S-TAP mode |
STANDALONE mode |
location of diag.bat |
%WINSTAP_DIR%\Bin\diag.bat (e.g. C:\Program Files\IBM\Windows S-TAP\Bin\diag.bat) |
%DIAG_DIR%\diag.bat (e.g. C:\tmp\diag.bat)
NOTE: anywhere except %WINSTAP_DIR%\Bin
|
location of diag.log |
%WINSTAP_DIR%\Bin\diag\diag.log |
%DIAG_DIR%\diag\diag.log |
ZIP Source directory |
%WINSTAP_DIR%\Logs |
%DIAG_DIR%\diag |
ZIP Target directory |
%WINSTAP_DIR%\bin\zipTmp |
%DIAG_DIR%\zip |
ZIP filename |
WSTAP_%HOST%_%YYYY-MM-DDTHH-MM-SSTZD%.zip |
GRD_WIN_DIAG_%YYYY-MM-DDTHH-MM-SSTZD%.zip |
ZIP tool |
ExternalZip.exe |
Powershell compress-archive command |
command options |
supported |
supported |
S-TAP features (Run from GUI / Upload) |
supported |
NOT supported |