Capturing information for Novell Client problems

  • 7009022
  • 20-Jul-2011
  • 02-Aug-2017


Novell Client for Windows Vista
Novell Client 2 for Windows Vista/2008
Novell Client 2 SP1 for Windows Vista
Novell Client 2 SP1 for Windows Server 2008
Novell Client 2 SP1 for Windows 7
Novell Client 2 SP1 for Windows Server 2008 R2


Some Novell Client-related problems require diagnostic data for analysis. For example:
Cannot save a file
Unable to open a file
Error when trying to modify a file
File locking problem
Problems with oplocking, file caching
Slow performance


For the duplication you can produce, capture a simultaneous LAN trace, Process Monitor log, and Problem Steps Recorder log. Note that the Problem Steps Recorder is available only on Windows 7 and Windows Server 2008 R2 and later.

Follow these steps:

1. Download and install Process Monitor (free), available from
2. Download and install Wireshark (free), available from (Or, some other protocol analyzer).
3. Launch Process Monitor. Press the magnifying glass icon to stop capturing. PM logs are typically very large, so don't capture any longer than is necessary.
4. Launch Wireshark.
5. Launch Problem Step Recorder. Windows Logo Key + R, type PSR.EXE.
6. Begin capturing in Wireshark. Click Capture -> Interfaces -> Start capturing on the appropriate interface.
7. Begin capturing in PSR. Click the "Start Record" button. (See MS document "Problem Steps Recorder Overview")
8. Begin capturing in Process Monitor. Click the magnifying glass icon.
9. Duplicate the problem as succinctly as possible.
10. Stop capturing in Process Monitor. Click the magnifying glass icon.
11. Stop capturing in PSR. Click the "Stop Record" button. Save the PSR log.
12. Stop capturing in Wireshark. Type Ctrl + E.
13. Save the Process Monitor log. Save in Native Process Monitor Format (PML).
14. Save the Wireshark trace. Type Ctrl + S. Save as type Wireshark/tcpdump (*.pcap, *.cap).
15. Prepare a .txt file completely describing the configuration, IP addresses of involved machines, steps followed, expected results, actual results including any error messages, etc.
16. Zip the Process Monitor log, the PSR log, the Wireshark trace, and the .txt file as <your SR number + some unique identifier, such as the date>.zip and upload it to
17. Notify the support engineer that <the name of the file> has been uploaded to the FTP site.

Additional Information

Capturing a "Boot-up" LAN trace

In many cases, it is necessary to capture all the LAN traffic on a workstation, including that packets that are sent and received before the user is logged in and the desktop is available. See TID 7003237 for information on obtaining a boot-up LAN trace.

Capturing Process Monitor logs for issues occurring at machine boot:
(See NOTE below for additional steps currently needed for Windows 10)

Some problems occur before the desktop appears, so it is necessary to configure Process Monitor to capture events which occur before the desktop is available.

1. Run ProcMon.exe, which will start capturing information immediately. De-select "Capture Events" from the File menu (or in the toolbar) to stop collection.
2. From the "Options" menu, select "Enable Boot Logging".  Leave "Generate profiling events" de-selected, and press OK to save the boot logging configuration.
3. Close Process Monitor, and then restart (reboot) the workstation to duplicate the problem.
4. Once logged back into the machine, run ProcMon.exe again to start Process Monitor. 
5. Process Monitor will report "A log of boot-time activity was created by a previous instance of Process Monitor.  Do you wish to save this collected data now?"  Select "Yes" to begin the process of saving the boot-time data, and specify a .PML file into which Process Monitor should save the data.  Note that due to the volume of data, Process Monitor may end up saving multiple files (BOOT.PML, BOOT-1.PML, BOOT-2.PML, etc.).
6. Once saved, Process Monitor will open the saved boot data.
7. Use "Save" from the "File" menu, de-select "Also include profiling events", and select "Native Process Monitor Format (.PML)", and then specify a location to save the .PML file.


For Windows 10 users, the Microsoft utilities encounter a Windows 10-specific compatibility issue that prevents them from enabling "Log Boot" in the same manner that is successful on Windows 8.1 and earlier. Specifically, because Windows 10 holds a loaded driver file open, these utilities find they cannot overwrite their driver file once it is already loaded into memory. Enabling the "Log Boot" option on Windows 10 therefore requires some additional steps on the current versions of the Microsoft utilities, up to and including Process Monitor 3.2 (May 2015).

To select Process Monitor "Enable Boot Logging" on Windows 10:

1. When Process Monitor is launched normally, it creates and loads the "C:\Windows\System32\Drivers\PROCMON23.SYS" driver to capture kernel-level API interaction. When you attempt to select the "Enable Boot Logging" option from the "Options" menu, Process Monitor again tries to write the "C:\Windows\System32\Drivers\PROCMON23.SYS" driver to be ready to capture output during the next Windows boot.  On Windows 10 this second attempt fails because the PROCMON23.SYS driver is already loaded in memory.  Process Monitor presents the message "Unable to write PROCMON23.SYS" when attempting to select "Enable Boot Logging".

2. To work around this Windows 10-specific failure, open Windows Explorer and navigate to the "C:\Windows\System32\Drivers\" directory. Find the "PROCMON23.SYS" driver and rename that driver to "PROCMON23.disabled.sys" or a similar unique name.  The driver currently loaded into memory cannot be deleted, but can be renamed.  Now return to Process Monitor and attempt to select "Enable Boot Logging" again, and the attempt will be successful.

Memory Dump

For issues where a memory dump is required (such as when the application or system will crash, "blue screen," or "hang,"  see TID 7004093.

Registry Export

If your support engineer requests a registry export, export the Novell Client registry settings from a batch file or command prompt using the command:

regedit /e C:\NovellClient.reg HKEY_LOCAL_MACHINE\Software\Novell

This will save the registry branch to a file called C:\NovellClient.reg.