Presentation Identifier Goes Here
1
Memory Dump Analysis
Weibo ***@hushlight
Agenda
How to get memory dump
Load symbols
Basic mand
Q & A
Presentation Identifier Goes Here
2
Get memory dump
System Memory dumps
http://support./kb/254649
Application crash dumps
http://msdn./en-us/library/bb787181().aspx
http://blogs./askperf/archive/2007/06/15/capturing-application-crash-
http://support./kb/931673
Generating crash dumps:
http://msdn./en-us/
?article=153
Presentation Identifier Goes Here
3
Get dump from VM snapshot
Create snapshot
Download Snapshot to local
Convert the snapshot to memory dump
-W <vmsn_file_name>
Presentation Identifier Goes Here
4
Load symbols
Symbol Path
_NT_SYMBOL_PATH=srv*%SystemDrive%\symbols*http://msdl./download/symbols;C:\Mysymbols
_NT_SYMCACHE_PATH=%SystemDrive%\SymCache
Ctrl+D
.reload /f
Force a reload of all symbols
Presentation Identifier Goes Here
5
Useful mands
!analyze –v
Quick auto-analysis
Lm
List loaded modules
!process 0 0
List al
《内存转储分析》PPT课件 来自淘豆网m.daumloan.com转载请标明出处.