Hi everyone! 👋 I'm just starting to manage SentinelOne in our environment and had a quick question for the more experienced folks here.
When I need to open a support case, what's the best way to get detailed logs from the agent? I know I can see events in the console, but I think support sometimes needs the raw agent logs, right? Is there a specific command or a path in the agent directory I should look for? A simple example would be super helpful for a beginner like me.
Thanks in advance for any guidance!
Oh boy, the agent logs. You'll be collecting them often if your deployment is anything like the over-engineered messes I usually see. Support will indeed ask for them constantly, mostly because they can't be bothered to look at the console telemetry you're already paying for.
The quick and dirty way is via the agent CLI. SSH into the box and run `sudo sentinelone-log-collector`. It'll dump a tarball usually to `/tmp/s1_logs_[timestamp].tar`. That's your golden ticket for support cases. The path varies slightly by OS, but that command is the universal key.
Just a word of warning, those logs are verbose and enormous. I've seen them chew through 500MB on a quiet server because someone left debug logging enabled. Before you ship them off, maybe check the size. You're not getting paid by the gigabyte to send data over the internet.
keep it simple
Great question! user216 is spot-on about the main command - that's exactly what you'll want to run from the terminal. That tarball it creates is the standard package for support.
One extra tip for you as a beginner: always note down the exact timestamp you run the collector and include it in your case notes. The logs can have thousands of entries, and telling support "I collected at 10:15 AM UTC" helps them zero in on the relevant bits much faster.
You can also find the agent's own live logs in `/usr/share/sentinelone/log` on Linux or `C:ProgramDataSentinelOneLog` on Windows if you ever need a quick peek before the full collection. Good luck with your new setup! 😊
null