The way I typically work with it is to "capture" before and after I perform an action, and then right-click on specific values in their columns (that I know are irrelevant) to "exclude" them. Slowly takes away some of the haystack....
Steve Iwanowski, NextStep Technology Advisors, aka DSD Lancaster PA ¯\_(ツ)_/¯
Original Message:
Sent: 12-12-2024 08:43
From: Jane Scanlan
Subject: Process Monitor - has anyone installed this at a client?
I had to download a zip file of executables to get this process monitor, and yeah, @Kevin Moyes it is hunting for a needle in a big haystack. But, at least I have something to look through on my hunt for this customer's random issues. I'm going to start another post with another subject.
------------------------------
Jane Scanlan
Partner
Next Level Manufacturing Consulting Group
------------------------------
Original Message:
Sent: 12-12-2024 01:25
From: Michele Herzog
Subject: Process Monitor - has anyone installed this at a client?
Great info to post in a survey coming to gather tips and tricks!
------------------------------
[Michele] [Herzog] [CPA,CITP, CGMA]
[Overland Park] [KS]
[816-520-1365]
Original Message:
Sent: 12-11-2024 14:15
From: Alnoor Cassim
Subject: Process Monitor - has anyone installed this at a client?
Steve - Right on! Better to download the whole SysInternals suite of utilities. This might be a good topic to add to the MotM 2025 Tips & Tricks session too.
------------------------------
Alnoor Cassim
Accounting Systems, Inc. (ASI)
Original Message:
Sent: 12-11-2024 13:54
From: Steve Iwanowski
Subject: Process Monitor - has anyone installed this at a client?
When I was wearing an "IT" hat, I used Process Monitor all the time, and even recently recommended it to find out which reg keys Sage was using for Product Updates.
I wanted to note that you do not need to install it, and can grab it (and may other cool utilities, such as autoruns, process explorer, autologin, ZoomIt, etc) directly from the https://live.sysinternals.com site (or even typing \\live.sysinternals.com in Windows Explorer).
------------------------------
Steve Iwanowski, NextStep Technology Advisors, aka DSD Lancaster PA ¯\_(ツ)_/¯
Original Message:
Sent: 12-11-2024 12:21
From: Alnoor Cassim
Subject: Process Monitor - has anyone installed this at a client?
Jane - It was used by a consultant here on 90M fairly recently to in fact detect and prove to a client's IT that AV was scanning Sage files. I believe this Sage Community post is a KB entry too and she sent them the KB article and IT followed the steps, not she herself.
For myself, I've used ProcMon a lot but to everyone's point is most effective when you're looking for something very specific, otherwise it's a big morass of wading thru traced process data. A good example of where to use it is when you're suspecting permissions errors. The ProcMon result column will show ACCESS DENIED on usually a pvxwin32.exe process and now there is irrefutable proof. I usually save the trace file to CSV, open it in Excel, re-sort the columns so the ACCESS DENIED entries appear at the top. Hope that helps.
------------------------------
Alnoor Cassim
Accounting Systems, Inc. (ASI)