Skip to main content

2 de junio de 2026 Archivado

Core Services Logging

Your Workspace ONE UEM deployment has several essential, or core, services that enable your deployment to run successfully. These services include the console, device services, API, and AWCM. To help you diagnose problems, Workspace ONE provides logging data if you have issues with any of these core services.

The core services of Workspace ONE UEM are its foundation, the pieces required for your deployment to run properly and efficiently. If the service you need assistance with does not display here, view the Integrated Component Logging section for an extensive list of integrated services and their log information.

There are two logging levels that provide different levels of detail. To reduce the use of hardware resources, deactivate the logging level if you are not troubleshooting a service.

  1. In the console with a system administrator level account at the global organization group, navigate to Groups & Settings > All Settings > Admin > Diagnostics > Logging.

  2. Select a service that needs an increased logging level. Set the service logging to Enabled.

  3. After you finish troubleshooting, revert the logging level to Disabled to preserve hardware resources.

How to Read a Workspace ONE UEM Log Entry

The ability to read a Workspace ONE UEM log entry is key to successfully analyzing and troubleshooting any issues you might encounter with your Workspace ONE UEM deployment.

Every log entry contains the following key information.

  1. Date and time

  2. Server identifier

  3. Server communication thread identifier

  4. Device or user identifier

  5. Workspace ONE UEM thread identifier

  6. Logging level

  7. Associated service

  8. Log message

Error Log Example

Workspace ONE UEM error logs use the following format:

2017/06/21 19:07:12.243**\[1\]**	EX-DS111**\[2\]**	11aaabbccc-dddee-1111-22ff-06gggg777777**\[3\]**	[0000000-0000000]**\[4\]**   (14)**\[5\]** 	Error**\[6\]**	AirWatch.CloudConnector.Client.AccServiceClient.SendRequest**\[7\]** 	Received a Failure message from AWCM: Destination not reachable at this moment**\[8\]**

Information Log Example

Workspace ONE UEM Information logs use the following format:

2017/09/07 14:46:57.852**\[1\]**             EX-DS111**\[2\]**           ca9562a7-c87c-4c3b-a1e1-ca35a88555ab**\[3\]**               [0000052-0000000]**\[4\]**   (20)**\[5\]**             Info**\[6\]**                WanderingWiFi.AirWatch.Console.Web.Controllers.HomeController**\[7\]**          Method: WanderingWiFi.AirWatch.Console.Web.Controllers.HomeController.Index; LocationGroupID: 7; UserID: 52; UserName: TEST_USER; Parameters: <N/A>;  69eddd96-9a81-47e9-a78a-dd20c845426b

Console Logging

Learn more about the Workspace ONE UEM logging functions available for the Console service. The API service is installed by default. All Logs are located in the <installdrive>:/AirWatch/Logs folder unless otherwise specified.

Folder Log Name Description
AirWatch API AW_Core_Api.log Contains information on calls made to the API endpoint for available API commands.
AirWatch API AW_MAM_Api.log Contains information relating to specifically the /API/MAM endpoint.
AirWatch API AW_MCM_Api.log Contains information relating to specifically the /API/MCM endpoint.
AirWatch API AW_MDM_Api.log Contains information relating to specifically the /API/MDM endpoint.
AirWatch API AW_MEM_Api.log Contains information relating to specifically the /API/MEM endpoint.
AirWatch Services AWServices.log Contains information on the AirWatch SOAP API.
DesiredStateManagement DSM.log Contains information about Windows 10 Device State Management.
IIS>W3SVC1 u_ex####.log Contains the history of IIS web endpoints accessed and response codes delivered (Example: /AirWatch & /Enroll).
C:/ > Inetpub > Logs > FailedReqLogFiles Fr####.xml Contains failed IIS request log traces. The log is deactivated by default. You must enable it.
Services AirWatchGemAgent.log Contains information on the GEM License assessing service and its back-end connections.
Services ApiWorkflowService.log This service log cites processed device commands from the REST API.
Services AW.Meg.Queue.Service.log Contains information on the email policy updates for SEG or Powershell integration, associated MSMQ reader information, SQL connection errors, and encryption ciphers.
Services AW.IntegrationService.log Contains information on all AW third-party integrations such as Apple School Manager APIs, VPP, and App Scan.
Services BackgroundProcessorServiceLogFile.txt Contains information on multiple different jobs that are processed in the background asynchronously such as console exports or report generation.
Services BulkProcessingServiceLogFile.txt Contains information on bulk commands such as SDK, certificates, APNS messages, DEP APIs, command queues, users, user groups, profiles, and apps.
Services ChangeEventOutboundQueueService.log Sends event notifications from source component to a central location (Example: Syslog).
Services ChangeEventQueue.log Contains information on event log entries, the batch save of those logs, syslog configuration loads, and policy updates for AW Tunnel.
Services ComplianceService.log Contains information about device compliance status and actions executed as part of compliance policies.
Services ContentDeliveryService.log Contains information on content delivery and relay server communication for product provisioning.
Services DirectorySyncServiceLogFile.txt Contains information on directory user and group syncs such as member lists and LDAP mapping and definitions.
Services EntityReconcileService.log Contains information on reconcile and sync for entities linked to smart groups.
Services MessagingServiceLog.txt Contains information on notifications sent to the various 3rd party messaging services (APNs, GCM, WNS).
Services PolicyEngine.log Contains information on the device policies queue and products information related to user, OG, and device compliance. It will also include information on product provisioning processing and delivery.
Services PurgeUtility.log Contains information on purge tasks and job run status.
Services SchedulerService.log Contains information on the various jobs that are executed by the scheduler service such as Automatic sync, VPP user invite sync, bulk notification push, and AD sync triggers. For an exhaustive list, see Groups & Settings > All Settings > Admin > Scheduler.
Services SmartGroupServiceLogFile.txt Contains information relating to reconciliation of smart group mappings resulting from enrollments, changes in device or user state, and reports the resulting change for smart groups.
Services SMSService.log Contains information on batch SMS sent to devices.
Services Ws1.Tunnel.Kestrel.log Tunnel services logs related to .net core based microservices.
Tools DeviceStateMigrationTool.log Contains information on legacy android device migration.
Tools EntitlementServiceMigrationTool.log Contains information on legacy android device migration.
Web console WebLogFile.txt Contains information on the console user interface.
TargetedLogging ####Airwatch.log TargetedLogging_<servicename>.log Contains information on targeted logging enabled devices or services.

Device Services and Self-Service Portal Logging

Learn more about the Workspace ONE UEM logging functions available for Device Services. The API service is installed by default. All Logs are located in the <installdrive>:/AirWatch/Logs folder unless otherwise specified.

Folder Log Name Description
AirWatch API AW_Core_Api.log Contains information on calls made to the API endpoint for available API commands.
AirWatch API AW_MAM_Api.log Contains information relating to specifically the /API/MAM endpoint.
AirWatch API AW_MCM_Api.log Contains information relating to specifically the /API/MCM endpoint.
AirWatch API AW_MDM_Api.log Contains information relating to specifically the /API/MDM endpoint.
AirWatch API AW_MEM_Api.log Contains information relating to specifically the /API/MEM endpoint.
AirWatch API ws1.gateway.log WS1-Services logs.
AirWatch Services AWServices.log Contains information on the AirWatch services including logging level and service details. This log also contains SOAP API related information.
AppCatalog AppCatalogLogFile.txt Contains information related to the application catalog such as application assignment, device requests when loading the app catalog, and user authentication.
DesiredStateManagement DSM.log Contains information about Windows 10 Device State Management.
DeviceManagement DeviceManagement.log Contains information on the early stages of enrollment including token or group ID validation, restriction checks, and authentication.
DeviceServices DeviceServicesLog.txt Contains information related to all device communications with Workspace ONE UEM.
DeviceService DevicesGateway.log Logging for the subset of APIs dedicated to devices.
Enroll Shortcut EnrollShortcut.log Information on URL redirects such as /enroll.
EntitlementService AirWatch.UEM.EntitlementService.Log Contains information on the provided APIs to create entitlement rules.
IdentityService IdentityService.log Information about the SAML web endpoint.
IIS>W3SVC1 u_ex####.log Contains history of IIS web endpoints accessed and response codes delivered (Example: /DeviceServices & /DeviceManagement).
C:/ > Inetpub > Logs > FailedReqLogFiles Fr####.xml Contains failed IIS request log traces. This log must be enabled as it is turned off by default.
MetadataTransformService Metadatatransfromservice.log Contains information on the stored metadata used to render the data driven user interface.
MyDevice WebLogfile.txt Contains information on actions taken within the self-service portal.
Services ws1tunnel.kestrel All the DB queries from Microservice. Log level is OFF by default.
Services ws1.tunnel.log Tunnel Microservice application/functional logs. These logs also contain the equivalent of IIS logs about API status, time taken, etc.
Services APIWorkflowService.log Contains information on the API such as logging level, MSMQ reader errors, and SQL connection errors.
Services AW.IntegrationService.log Contains information on all AW third-party integrations such as Apple School Manager APIs, VPP, and App Scan.
Services AW.Meg.Queue.Service.log Contains information on the email policy updates for SEG or Powershell integration, associated MSMQ reader information, SQL connection errors, and encryption ciphers.
Services BulkProcessingServiceLogFile.txt Contains information on bulk commands related to SDK, certificates, APNS messages, DEP APIs, command queues, users, user groups, profiles, and apps.
Services ChangeEventQueue.log Contains information on event log entries, the batch save of those logs, syslog configuration loads, and policy updates for AW Tunnel.
Services EntityReconcileService.log Contains information on reconcile and sync for entities linked to smart groups.
Services InterrogatorQueueService.log Contains information related to processed device samples for all platforms to be updated to the DB such as Application and Profile samples from device.
Services MessagingServiceLog.txt Contains information on sends and response times to the various third-party messaging services (APNs, GCM, WNS).
Services ProvisioningPackageServicelogfile.txt Logs provisioning package information for auto enrollment of applicable Windows 10 device.
Services ChangeEventOutboundQueueService.txt Sends event notifications from source component to a central location (Example: Syslog).
Services SmartGroupServiceLogfile.log Information relating to reconciliation of smart group mappings resulting from enrollments or changes in device or user state, and the resulting change for smart groups.
TargetedLogging ####Airwatch.log TargetedLogging_<servicename>.log Contains information on targeted logging enabled devices or services.
Trust Service TrustService.log Logging associated with an on-premises instance of the Trust Service that is used for Certificate Pinning.

API Logging

Learn more about the Workspace ONE UEM logging functions available for the API service. All Logs are located in the <installdrive>:/AirWatch/Logs folder unless otherwise specified.

Folder Log Name Description
AirWatch API AW_Core_Api.log Contains information on calls made to the API endpoint for available API commands.
AirWatch API AW_MAM_Api.log Contains information relating to specifically the /API/MAM endpoint.
AirWatch API AW_MCM_Api.log Contains information relating to specifically the /API/MCM endpoint.
AirWatch API AW_MDM_Api.log Contains information relating to specifically the /API/MDM endpoint.
AirWatch API AW_MEM_Api.log Contains information relating to specifically the /API/MEM endpoint.
AirWatch API CiscoiseLogfile.txt Information about CiscoISE integration.
AirWatch API ws1.gateway.log Information about devicesgateway API.
AirWatch Services AWServices.log Contains information on the Workspace ONE UEM services including logging level and service details. This log also contains SOAP API-related information.
IIS>W3SVC1 u_ex####.log Contains history of IIS web endpoints accessed and response codes delivered (Example: /ActiveSyncIntegrationServiceEndPoint).
C:/ > Inetpub > Logs > FailedReqLogFiles Fr####.xml Contains failed IIS request log traces. This log must be enabled as it is turned off by default.
Services APIWorkflowService.log Contains information on handing bulk requests from the API server such as bulk commands to devices.
Services AW.IntegrationService.log Contains information on all AW third-party integrations such as Apple School Manager APIs, VPP, and App Scan.
Services AW.Meg.Queue.Service.log Contains information on the email policy updates for SEG or Powershell integration, associated MSMQ reader information, SQL connection errors, and encryption ciphers.
Services BulkProcessingServiceLogFile.txt Contains information on bulk commands related to SDK, certificates, APNS messages, DEP APIs, command queues, users, user groups, profiles, and apps.
Services ChangeEventQueue.log Contains information on event log entries, the batch save of those logs, and syslog configuration loads.
Services EntityReconcileService.log Contains information on reconcile and sync for entities linked to smart groups.
Services MessagingServiceLog.txt Contains information on sends and response times to the various third-party messaging services (APNs, GCM, WNS).
Services ChangeEventOutboundQueueService.txt Log file for entering information into the MSMQ to be sent to central outbound component (Example: Syslog).
Services SmartGroupServiceLogfile.log Information relating to reconciliation of smart group mappings resulting from enrollments or changes in device or user state, and the resulting change for smart groups.
Services DataPlatformService.log Information about sending Windows 10 samples (requires Workspace ONE Intelligence).

AWCM Logging

Learn more about the Workspace ONE UEM logging functions available for the AWCM service. All Logs are located in the /AirWatch/Logs folder unless otherwise specified.

Folder Log Name Description
AWCM Awcm.log Contains information on AWCM such as status, history, properties, and additional sub-services.
AWCM AWCMservice.log Contains log information on AWCM Java service wrapper.

¿Le resultó útil esta página?

Enviar comentarios sobre este tema

¿Le resultó útil este tema?

No incluya información personal ni confidencial.

Generando el enlace…