.zip file that contains diagnostic information from a . Support bundles help you troubleshoot collection issues faster, reduce the need for direct access to the system where the collector runs, and give your team or SpecterOps support a consistent package of collector logs and diagnostics.
This is a SpecterOps-managed feature. If it is not enabled in your environment, contact your account team for assistance.
Use cases
Use support bundles when you need to shorten the path from a collector issue to troubleshooting:- Self-service troubleshooting: Request and download collector diagnostics from BloodHound Enterprise when you do not have direct access to the system where the collector runs.
- SpecterOps-assisted troubleshooting: Work with a SpecterOps support representative who has authorized access to your tenant. They can use the same BloodHound Enterprise workflow to retrieve the support bundle.
- Targeted diagnostic collection: Collect one support bundle for a specific client, download it through the browser, and delete it when you no longer need it or when you need a newer bundle.
Prerequisites
Before you can request, download, or delete a support bundle, you must have the following:- BloodHound Enterprise with the collector support bundle feature enabled by your account team.
- A user assigned the Administrator role. The support-bundle controls require permission to manage users and access client-management actions.
-
A SharpHound Enterprise or OpenHound collector client for one of the following collector versions:
Support bundles are currently available for SharpHound Enterprise and OpenHound clients. AzureHound Enterprise clients are not supported.
Support bundle lifecycle
Refer to the following table for the support-bundle lifecycle and what you can do at each stage:
Uploaded support bundles expire 90 days after the upload session is created. Deleting a bundle removes it sooner. Downloaded copies are outside the scope of BloodHound Enterprise retention.
BloodHound Enterprise allows one downloadable support bundle per client. To request a more recent bundle after one is available, delete the existing bundle first.
Request a support bundle
To request a support bundle, you must have the Administrator role. The request is asynchronous. BloodHound Enterprise checks for completion in the background and displays status notifications.1
Open the Manage Clients page
In the left menu, click Administration > Manage Clients.
2
Open the client action menu
Find the SharpHound Enterprise or OpenHound client you want to troubleshoot, then click the action menu in that client’s row.
3
Request the bundle
Click Request Support Bundle.The action menu changes to Requesting Support Bundle… while the collector processes the request.
4
Confirm the request
BloodHound Enterprise displays Support bundle requested successfully when the request is queued.
Download a support bundle
Provide your SpecterOps support representative with the.zip file through the approved support workflow, or inspect it locally if you are troubleshooting without SpecterOps support.
1
Open the client action menu
In Administration > Manage Clients, open the action menu for the SharpHound Enterprise or OpenHound client.
2
Download the bundle
Click Download Support Bundle.BloodHound Enterprise displays Support bundle download started. when your browser begins downloading the file.
3
Confirm the download
Your browser downloads the bundle as a
.zip file. The bundle contents depend on the collector type:- OpenHound
The file is named
sharphound_enterprise_support_bundle_<timestamp>.zip and contains the following files:SharpHound Enterprise support bundles do not include
auth.json files.Delete a support bundle
Delete a support bundle when you no longer need it or when you need to request a newer bundle for the same client.1
Open the client action menu
In Administration > Manage Clients, open the action menu for the SharpHound Enterprise or OpenHound client.
2
Start deletion
Click Delete Support Bundle.
3
Confirm deletion
In the Delete Support Bundle confirmation dialog, confirm that you want to delete the bundle.BloodHound Enterprise displays Support bundle deleted successfully when complete. The client action menu returns to Request Support Bundle after the client table refreshes.
Troubleshoot support bundles
Use the following issues to troubleshoot support-bundle requests, downloads, and deletion.Request Support Bundle is missing
Request Support Bundle is missing
Likely cause: The feature is not enabled, the client is not SharpHound Enterprise or OpenHound, the collector application is below the minimum supported version, or your role cannot use support-bundle controls.Action: Confirm that the client type is SharpHound Enterprise or OpenHound, and that the collector meets the minimum version: SharpHound Enterprise v2.16.0 or later or OpenHound v0.4.0 or later. Also confirm that you are assigned the Administrator role. Contact SpecterOps if the feature is not available in your tenant.
The request fails immediately
The request fails immediately
Likely cause: BloodHound Enterprise cannot queue the request because of permissions, feature availability, client visibility, or a temporary service error.Action: Retry once. If it fails again, record the client name, request time, and error text.
Requesting Support Bundle stays visible
Requesting Support Bundle stays visible
Likely cause: The collector has not picked up the request, is offline, or has not finished uploading the bundle.Action: Confirm the client status on Manage Clients. If the client is Disconnected, Delayed, or Unconfigured, troubleshoot collector connectivity before retrying.
BloodHound says the bundle does not exist
BloodHound says the bundle does not exist
Likely cause: The request completed without an uploaded artifact.Action: Request a new bundle. If the problem repeats, contact support with the client name, collector version, and request time.
The request failed or was canceled
The request failed or was canceled
Likely cause: The collector or server ended the support-bundle operation before a downloadable file was available.Action: Request a new bundle. If the second request fails, collect the visible notification text and contact support.
Download fails
Download fails
Likely cause: The browser, network path, permissions, or stored artifact is unavailable.Action: Try again. If it still fails, confirm that the bundle has not been deleted and contact support with the visible error.
You need a newer bundle
You need a newer bundle
Likely cause: BloodHound keeps one downloadable support bundle per client.Action: Delete the existing support bundle, then request a new one.