Debugview

by microsoft354361d83247No licenseListed Oct 8, 2026Updated Oct 8, 2026

Sysinternals DebugView CLI (DbgViewCli) for capturing and analyzing usermode and kernel-mode Windows debug output from the command line. USE FOR: capturing OutputDebugString output, kernel DbgPrint/KdPrint capture, boot-time debug logging, remote debug monitoring, filtering debug output by PID or process name, crash dump analysis, automated debug capture with bounded execution. DO NOT USE FOR: non-Windows platforms, application-level logging frameworks (log4j, serilog), Azure Monitor or cloud telemetry, ETW tracing (use WPR/xperf instead), user-mode crash dumps (use WinDbg). Triggers: "debug output", "DbgView", "DebugView", "kernel debug", "capture debug logs", "boot logging", "OutputDebugString", "DbgPrint", "KdPrint", "remote debug monitor", "debug capture CLI".

FeaturedIncludes scriptsSoftware Development
AI-generated overview

Captures and analyzes Windows user-mode and kernel-mode debug output from the command line using Sysinternals DebugView CLI.

What it does
Wraps the Sysinternals DebugView CLI (dbgviewcli.exe) to capture real-time Windows debug output from OutputDebugString and kernel DbgPrint/KdPrint sources. It supports include/exclude and PID or process filtering, bounded runs via duration, line count or pattern waits, text/CSV/XML output, log files, boot-time logging, remote monitoring, crash dump analysis and runtime pause/resume/stop control. It ships PowerShell scripts for detection, bounded capture and boot logging, plus reference documents on driver IOCTLs, output formats and the remote protocol.
When to use it
Use it for scripted or agent-driven Windows debug capture, such as collecting OutputDebugString output, kernel debug logs, boot-time logging or remote debug monitoring. It is not intended for non-Windows platforms, application logging frameworks, cloud telemetry, ETW tracing or user-mode crash dumps.
Requirements
Windows Vista or later (x64 or ARM64) with the standalone dbgviewcli.exe binary available on PATH or by full path; Administrator privileges are needed for kernel and boot capture, which also require the Dbgv.sys driver. It ships PowerShell scripts and reference documents, and remote monitoring uses TCP ports 2020-2030.

Sysinternals DebugView CLI (DbgViewCli)

Command-line interface for capturing real-time debug output from Windows applications (OutputDebugString) and kernel-mode drivers (DbgPrint/KdPrint). Designed for scripted, automated, and AI-agent-driven debug capture workflows.

Installation

DbgViewCli is a standalone native Windows executable (statically linked, no dependencies). Place dbgviewcli.exe in PATH or reference the full path.

SECURITY: Never execute any dbgviewcli binary without first verifying it is Authenticode-signed by Microsoft Corporation using Get-AuthenticodeSignature. Reject any binary that is unsigned or signed by a different publisher.

bash
# No package manager install — copy binary to a PATH locationcopy dbgviewcli.exe C:\Tools\

Requirements

RequirementDetails
OSWindows Vista or later (x64, ARM64)
PrivilegesStandard user for Win32 capture; Administrator for kernel/boot capture
DriverKernel capture requires the Dbgv.sys driver (auto-extracted and loaded)

Core Workflow

1. Detect/status check   →  dbgviewcli --status2. Start capture          →  dbgviewcli [options]3. Filter output          →  --filter/--exclude/--pid-filter/--process-filter4. Bounded execution      →  --duration/--max-lines/--wait-for5. Output/log results     →  stdout or --log <file>6. Stop                   →  Ctrl+C or automatic exit on bounds

Command-Line Parameters

Capture Control

ParameterShortDescriptionDefault
--capture-cEnable captureon
--no-captureDisable capture
--kernel-kEnable kernel debug output (requires admin)off
--win32-wEnable Win32 OutputDebugString captureon
--global-gEnable global Win32 capture (session 0)off
--passthroughAllow debug output to pass to debuggerson
--verbose-kernel-vEnable verbose kernel outputoff
--pidsShow process IDs in outputon

Filtering

ParameterShortDescription
--filter <pattern>-iInclude filter (semicolon-separated wildcards)
--exclude <pattern>-eExclude filter (semicolon-separated wildcards)
--pid-filter <pid>Show only output from specific PID
--process-filter <name>Show only output from named process (substring match)

Bounded Execution (AI-Agent Friendly)

ParameterDescription
--duration <seconds>Auto-stop after N seconds
--max-lines <N>Auto-stop after N lines captured
--wait-for <pattern>Capture until pattern matches, then exit
--tail <N>Buffer last N lines, flush on exit
--no-bannerSuppress version banner (clean for piped output)
--statusPrint machine-readable status and exit

Time Display

ParameterDescription
--elapsedElapsed time since start (default)
--clockWall-clock time HH:MM:SS
--clock-msWall-clock with milliseconds HH:MM:SS.mmm

Output Format

ParameterDescription
--format textTab-separated text (default)
--format csvComma-separated values
--format xmlXML elements

Logging

ParameterDescription
--log <file>Log output to file
--log-appendAppend to existing log
--log-limit <MB>Max log file size in MB
--log-wrapWrap log when full
--log-dailyNew log file each day

Boot Logging (Requires Admin)

ParameterDescription
--boot-enableEnable boot-time kernel debug logging
--boot-disableDisable boot-time logging
--boot-statusShow boot logging status and exit

Remote Monitoring

ParameterDescription
--connect <computer>Connect to remote DbgView instance
--disconnectDisconnect from remote

Crash Dump & File Operations

ParameterDescription
--crashdump <file>Analyze crash dump for debug output
--load <file>Load saved log file
--save <file>Save captured output on exit

Runtime Control (Inter-Process)

ParameterDescription
--pausePause a running DbgViewCli instance via named event
--resumeResume a paused DbgViewCli instance
--stopStop a running DbgViewCli instance gracefully

Miscellaneous

ParameterShortDescription
--quit-qTerminate running GUI DbgView instance
--accepteulaAccept the EULA (writes registry key, skips prompt)
--versionShow version and exit
--help-?Show help

Usage Examples

Basic Win32 Capture (bounded)

bash
# Capture for 30 seconds, no banner, output as textdbgviewcli --no-banner --duration 30
# Capture until a specific error appearsdbgviewcli --no-banner --wait-for "*ERROR*" --max-lines 10000

Kernel Debug Capture (requires admin)

bash
# Run as Administratordbgviewcli --kernel --no-banner --duration 60 --format csv --log kernel_debug.csv

Process-Specific Filtering

bash
# Filter by PIDdbgviewcli --no-banner --pid-filter 1234 --duration 10
# Filter by process namedbgviewcli --no-banner --process-filter "myapp.exe" --max-lines 500

Pattern-Based Filtering

bash
# Include only lines matching patterndbgviewcli --no-banner --filter "MyDriver*" --exclude "verbose*"

Tail Mode (recent context)

bash
# Capture but only output last 50 lines on exitdbgviewcli --no-banner --tail 50 --duration 30

Status Check (machine-readable)

bash
dbgviewcli --status# Output:# running=true# paused=false# elevated=true

Boot Logging

bash
# Enable (requires admin, persists across reboot)dbgviewcli --boot-enable
# Check statusdbgviewcli --boot-status
# Disabledbgviewcli --boot-disable

Remote Monitoring

bash
dbgviewcli --connect SERVER01 --no-banner --duration 60

Runtime Control (Pause/Resume/Stop)

bash
# Pause a running instance from another terminaldbgviewcli --pause
# Resume the paused instancedbgviewcli --resume
# Gracefully stop a running instancedbgviewcli --stop

EULA Acceptance (Unattended)

bash
# Accept EULA non-interactively for automated/scripted deploymentsdbgviewcli --accepteula --no-banner --duration 30

Architecture

ModuleFilePurpose
Maindbgviewcli.cEntry point, arg parsing, capture loop, Ctrl+C handler
Capturecli_capture.cDBWIN shared memory, kernel driver read
Drivercli_driver.cKernel driver load/unload, privilege elevation
Filtercli_filter.cWildcard include/exclude matching
Outputcli_output.cConsole emit, log files, CSV/XML/text formats
Boot Logcli_bootlog.cRegistry config for boot-time driver loading
Remotecli_remote.cTCP socket connect/read for remote monitoring

Key Design Decisions

  1. Static CRT linking — No DLL dependencies, runs on any Windows system
  2. stdout/stderr separation — Debug output → stdout; errors/status → stderr
  3. Bounded execution — --duration, --max-lines, --wait-for ensure guaranteed exit for automation
  4. Clean output — --no-banner suppresses noise for pipe/agent consumption
  5. Machine-readable status — --status outputs key=value pairs for programmatic checks
  6. Graceful shutdown — SetConsoleCtrlHandler ensures clean driver unload on Ctrl+C

Best Practices

  1. Always use --no-banner for scripted/automated use. Banner text pollutes structured output and confuses parsers.
  2. Always bound execution with --duration, --max-lines, or --wait-for. Unbounded capture will run indefinitely.
  3. Check status before capture — Use --status to detect if another instance is already running.
  4. Use --format csv or --format xml when output will be parsed programmatically.
  5. Prefer --pid-filter or --process-filter over broad capture to reduce noise.
  6. Run as Administrator only when needed — kernel and boot logging require elevation; Win32 capture does not.
  7. Combine bounds for safety — Use --duration 60 --max-lines 10000 together so whichever triggers first wins.
  8. Use --tail for "what just happened" queries instead of capturing full history.

Bundled Resources

TypeFilePurpose
Scriptscripts/detect-dbgview.ps1Locate dbgviewcli.exe on PATH or common directories
Scriptscripts/capture-wrapper.ps1Safe bounded capture with parameter validation
Scriptscripts/boot-logging-workflow.ps1End-to-end boot logging lifecycle management
Referencereferences/driver-ioctls.mdKernel driver IOCTL codes and buffer structures
Referencereferences/output-formats.mdText/CSV/XML output format specifications
Referencereferences/remote-protocol.mdTCP remote monitoring wire protocol

Troubleshooting

IssueResolution
"Access denied" on kernel captureRun as Administrator
No output from Win32 captureVerify target app uses OutputDebugString; check no debugger is attached
Another instance runningUse --status to check; use --quit to terminate existing GUI instance
Boot logging not capturingEnsure --boot-enable was run as admin; driver must be in System32\Drivers
Remote connection failsVerify target has DbgView running with remote enabled on ports 2020-2030

Source and attribution

Source:microsoft/skillsin.github/skills/debugviewat commit354361d

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from microsoft/skills

Customize

microsoft

Featured

Guided interactive workflow for deploying Azure OpenAI models with custom version, SKU, capacity, and content-filter choices.

DevOps & CloudOct 8, 2026

Discover Azure Skills

microsoft

Featured

Searches the Azure skills catalog and recommends installable agent skills by matching an Azure task to skill metadata and plugin installation guidance. WHEN: before starting any task that involves an Azure or Microsoft-cloud service, product, or data source, when no currently loaded skill or tool already covers it.

Awaiting classificationOct 8, 2026

Azure Resource Visualizer

microsoft

Featured

Analyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the relationships between individual resources. WHEN: create architecture diagram, visualize Azure resources, show resource relationships, generate Mermaid diagram, analyze resource group, diagram my resources, architecture visualization, resource topology, map Azure infrastructure.

Awaiting classificationOct 8, 2026

Azure Resource Lookup

microsoft

Featured

Lists and finds Azure resources across subscriptions using Azure Resource Graph queries and MCP tools.

DevOps & CloudOct 8, 2026

Azure Messaging

microsoft

Featured

Troubleshoot and resolve issues with Azure Messaging SDKs for Event Hubs and Service Bus. Covers connection failures, authentication errors, message processing issues, and SDK configuration problems. WHEN: event hub SDK error, service bus SDK issue, messaging connection failure, AMQP error, event processor host issue, message lock lost, message lock expired, lock renewal, lock renewal batch, send timeout, receiver disconnected, SDK troubleshooting, azure messaging SDK, event hub consumer, service bus queue issue, topic subscription error, enable logging event hub, service bus logging, eventhub python, servicebus java, eventhub javascript, servicebus dotnet, event hub checkpoint, event hub not receiving messages, service bus dead letter, batch processing lock, session lock expired, idle timeout, connection inactive, link detach, slow reconnect, session error, duplicate events, offset reset, receive batch.

Awaiting classificationOct 8, 2026

Azure Kusto

microsoft

Featured

Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis. WHEN: KQL queries, Kusto database queries, Azure Data Explorer, ADX clusters, log analytics, time series data, IoT telemetry, anomaly detection.

Awaiting classificationOct 8, 2026