Skip to content

Add modular Windows diagnostic manifests - #326

Open
Scott Roberts (Azure) (ScottAzure) wants to merge 4 commits into
masterfrom
scout/windows-diagnostic-modular
Open

Scott Roberts (Azure) (ScottAzure) wants to merge 4 commits into
masterfrom
scout/windows-diagnostic-modular

Conversation

@ScottAzure

@ScottAzure Scott Roberts (Azure) (ScottAzure) commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Split the existing Windows diagnostic manifest into domain-focused modular manifests.
  • Keep manifest files as the source of truth; docs/manifest_content.md and docs/manifest_by_file.md are regenerated by tools/parse_manifest.py.
  • Add diagnostic-wga-gap-closure as a targeted add-on for min-diagnostic instead of broadening mini to the full diagnostic manifest.

Design notes

The split is domain-based, not a literal copy of the current diagnostic echo sections. Some existing sections are mixed or misleading: for example, one Plug and Play section contains FSLogix collection, and the MSRDCollect section includes RDInfra, identity, AppX/system, RDP, device-management, PowerShell, and probe entries.

No hand-authored docs/manifests/windows/* reference docs are included. The repository's established pattern is to update manifests and regenerate the two manifest index docs. Each modular manifest includes parser-safe echo metadata for purpose, coverage, and when to use it, so the rationale is visible in file diffs without creating a parallel docs source.

Manifest catalog: why each module exists and what it covers

Manifest Why it exists What it covers
diagnostic-registry-core Many WGA and support investigations need offline SYSTEM/SOFTWARE hive reads without collecting the whole diagnostic set. SOFTWARE and SYSTEM registry hives plus LOG1/LOG2 hive journals.
diagnostic-events-core Core Windows triage almost always starts with the primary OS event logs. System, Application, Windows Azure, Security, and Setup event logs.
diagnostic-events-rdp Cannot-RDP scenarios need Terminal Services/RDS logs that are easy to miss in smaller collections. RemoteDesktopServices, RdpCoreTS, LocalSessionManager, RemoteConnectionManager, SessionBroker, SessionServices, RDPClient, RemoteAssistance, and RemoteHelp event logs.
diagnostic-events-network-security Network, firewall, SMB, OpenSSH, and TLS/auth failures often require event channels outside System.evtx. CAPI2, CodeIntegrity, NDIS, NetworkProfile, NetworkProvider, NlaSvc, NTLM, Schannel, SMB client/server, TCPIP, firewall, OpenSSH, WinINet proxy, and WinRM event logs.
diagnostic-events-directory-services Domain join, DNS, and DC promotion investigations need directory-service event channels. Active Directory Web Services, DFS Replication, DNS Server, Directory Service, DNS Server audit, and DNS Client logs.
diagnostic-events-identity AVD, Entra/AAD sign-in, policy, Kerberos, and smart-card issues share identity/policy event dependencies. AAD, GroupPolicy, Hello for Business, Kerberos KDC Proxy, SmartCard, User Device Registration, and Workplace Join logs.
diagnostic-events-system-services AppX, WMI, PowerShell, task, device-management, and shell failures were mixed into broad diagnostic sections; this isolates them. AppLocker, AppModel, AppReadiness, AppX deployment/packaging, Diagnostics-Performance, PowerShell, Shell-Core, TaskScheduler, WER, Winlogon, WMI Activity, and device-management logs.
diagnostic-events-storage Storage/attach/profile issues need storage-specific operational logs without pulling all event channels. NTFS and VHDMP operational logs.
diagnostic-events-azure Azure platform and Service Fabric event logs are useful for guest-agent/platform integration issues. Service Fabric, WindowsAzure Diagnostics/Status, and Azure Recovery Services event logs.
diagnostic-provisioning Provisioning, sysprep, unattend, and in-place-upgrade failures depend on Panther/Sysprep files, not just event logs. CustomData, State.ini, WaSetup.xml/log, VmAgentInstaller.xml, unattend files, Panther setupact/setuperr, sysprep action files, sysprep logs, Sysprep_succeeded.tag, and scanresults.xml.
diagnostic-pnp-appinstall Driver/device install and app install failures need setupapi and netcfg evidence. netcfg ETL files, setupapi files, and setupapi.app.log.
diagnostic-domainjoin Domain join and DC promotion have a separate Windows debug-log surface. netlogon.log, NetSetup.LOG, mrt.log, DCPROMO.LOG, dcpromoui.log, and PASSWD.LOG.
diagnostic-dotnet Some app/agent failures need .NET machine configuration but not the full Windows diagnostic set. 32-bit and 64-bit .NET Framework machine.config files.
diagnostic-guest-agent-core Windows Guest Agent triage needs the core agent logs and aggregate status as a small reusable bundle. Telemetry.log, TransparentInstaller.log, WaAppAgent.log, WindowsAzure config XML, AggregateStatus JSON, AppAgentRuntime.log, and MonitoringAgent.log.
diagnostic-extensions-core Extension failures share generic handler/state/log artifacts independent of extension publisher. CommandExecution, Install, Update, Heartbeat logs, config.txt, HandlerEnvironment, HandlerManifest, RuntimeSettings, HeartBeat.Json, and PackageInformation files.
diagnostic-extensions-azure Azure first-party extensions have many known support-specific log paths that should be selectable without Service Fabric or third-party logs. IaaSDiagnostics, KeyVault, IaaSAntimalware, Security.Monitoring, BGInfo, JsonADDomainExtension, VMAccessAgent, MMA, DSC, Azure Backup, Guest Configuration, GPU driver, and related package files.
diagnostic-extensions-aadlogin AADLoginForWindows failures have dedicated WGA and support scenarios, including command-execution log dependencies. AADLoginForWindows extension .log/.txt files and CommandExecution logs.
diagnostic-extensions-servicefabric Service Fabric extension triage is large enough to keep out of the generic extension bundle. Service Fabric MC, MC test, SfmcSetup, ServiceFabricNode, and related infrastructure/cluster manifest and raw event logs.
diagnostic-extensions-thirdparty Third-party security extensions are useful in guest issues but should be explicitly selected. Symantec, TrendMicro DeepSecurity, and ESET extension artifacts.
diagnostic-windows-update Windows Update and servicing failures depend on CBS/DISM/WindowsUpdate plus servicing state. servicing sessions.xml, CBS logs, DISM logs, windowsupdate*.log, and WindowsUpdateClient Operational event log.
diagnostic-proxyagent Guest ProxyAgent and eBPF issues are distinct from core guest-agent log collection. WindowsAzure ProxyAgent logs and Windows eBPF committed logs.
diagnostic-avd-rdinfra AVD/RDInfra logs were previously mixed into MSRDCollect; this makes them explicit. RDInfra install logs, MsRDCMMRHost logs, RDMSDeploymentUI, rdweb.log, RemotePackages listing, and RDInfra directory listing.
diagnostic-msrdcollect MSRDCollect-specific tssesdir XML is a small focused artifact family. Windows\System32\tssesdir XML files.
diagnostic-fslogix FSLogix profile/container issues need both ProgramData and Program Files FSLogix artifacts plus event logs. FSLogix Profile logs, ETL logs, App Rules/CompiledRules probes, and FSLogix Apps/CloudCache event logs.
diagnostic-arc Azure Arc and Guest Configuration troubleshooting needs a separate lightweight bundle. AzureConnectedMachineAgent himds/azcmagent logs and GuestConfig policy/extension manager logs.
diagnostic-blobfuse BlobFuse evidence should be selectable independently from broader workload/HPC collection. BlobFuse logs under ProgramData and var/log paths present in the existing diagnostic manifest.
diagnostic-hpc HPC/NVIDIA/HPC Pack failures have specialized logs and event channels. NVIDIA installer files, HPCSetupLogs, HPC Pack ProgramData logs, and HPC event logs.
diagnostic-hpc-pack-2019 Directory probes are useful for HPC Pack 2019 layout validation without copying logs. HPC Pack 2019 LogFiles, Diagnostics, HpcFrontend, HpcNaming, Management, Monitoring, and SOA directories.
diagnostic-hpc-pack-2016 Directory probes are useful for HPC Pack 2016 layout validation without copying logs. HPC Pack 2016 LogFiles, Diagnostics, HpcFrontend, HpcNaming, Management, Monitoring, and SOA directories.
diagnostic-diskinfo Disk and partition context is broadly useful but does not require any file copy. diskinfo, output.
diagnostic-misc A few existing diagnostic operations do not fit a larger coherent domain but are preserved for lossless parity. Windows Temp ScriptLog and Windows IME directory probes.
diagnostic-wga-gap-closure Gives min-diagnostic a deliberate add-on when Windows Guest Analyzer coverage is the driver, without collecting full diagnostic. RDP operational/session broker logs, WaSetup/Panther setup logs, extension CommandExecution logs, AADLoginForWindows command logs, scanresults.xml, msiexec.log, and the CrowdStrike C-00000291 driver marker.

Cross-reference verification

Check Result
Existing Windows diagnostic operations 348 unique ops
Union of modular Windows manifests, excluding diagnostic-wga-gap-closure 348 unique ops
Missing from modular split 0
Extra in modular split 0
Generated manifest docs Rebuilt with tools/parse_manifest.py and compared against a fresh parser run
WGA baseline for min-diagnostic 561 full / 9 partial / 10 none, plus 11 custom-unknown and 3 malformed/non-parseable rule JSON files
WGA with min-diagnostic + diagnostic-wga-gap-closure 579 full / 1 none, plus the same 11 custom-unknown and 3 malformed/non-parseable rule JSON files

WGA / driver-alignment notes

diagnostic-wga-gap-closure adds the artifact families needed by the Windows Guest Analyzer gaps found in min-diagnostic, including RDP operational/session broker logs, WaSetup/Panther setup logs, extension CommandExecution logs, AADLoginForWindows command logs, scanresults.xml, msiexec.log, and the CrowdStrike C-00000291 driver marker.

This keeps min-diagnostic small while giving support workflows a deliberate add-on when Windows Guest Analyzer coverage is the driver.

Validation

  • Verified the Windows modules, excluding diagnostic-wga-gap-closure, are a lossless partition of the current Windows diagnostic manifest: 348 unique ops, 0 missing, 0 extra.
  • Regenerated docs/manifest_content.md and docs/manifest_by_file.md with tools/parse_manifest.py.
  • Compared regenerated docs against a fresh parser run.
  • Compared WGA dependency coverage: min-diagnostic improves from 561 full / 9 partial / 10 none to 579 full / 1 none with diagnostic-wga-gap-closure.

Split the existing Windows diagnostic manifest into domain-focused modules, add Windows module selection docs, and add a targeted WGA mini-diagnostic gap-closure manifest.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Add domain-focused Windows diagnostic fragments matching the existing diagnostic manifest operation set plus a targeted WGA mini-diagnostic gap-closure add-on.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep manifest files as the source of truth and rely on parse_manifest.py for generated documentation. Move rationale and module descriptions to the pull request body instead of adding a parallel docs source.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Add parser-safe echo metadata to each Windows modular manifest so reviewers can see why each module exists, what it covers, and when to use it directly in the manifest diff.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant