Process Monitor is a free tool from Windows Sysinternals, which is part of the Microsoft TechNet website. The tool monitors and displays in real-time all file system activity on a Microsoft Windows operating system. Process Monitor is useful for troubleshooting issues when we need to identify the files or registry keys an application is accessing.
The article below gives detailed steps on how to capture a Process Monitor log including how to capture system event while the computer is starting up.
If you have been asked by Sophos Technical Support to gather a Process Monitor log, follow the instructions below. Unless specified, gather a normal Process Monitor log.
The following sections are covered:
We may need to troubleshoot an issue that is related to your boot process. If this is required, a Sophos Technical Support agent will explicitly specify that we require boot logging. To enable boot logging, follow the following steps.
If you've spotted an error or would like to provide feedback on this article, please use the section below to rate and comment on the article. This is invaluable to us to ensure that we continually strive to give our customers the best information possible.
Every comment submitted here is read (by a human) but we do not reply to specific technical questions. For technical support post a question to the community. Or click here for new feature/product improvements. Alternatively for paid/licensed products open a support ticket.