A free, open-source log viewer and Windows troubleshooting tool. Drop in a log file and start reading — no install wizards, no prerequisites, no license keys.
Built as a modern replacement for Microsoft's CMTrace.exe with added Intune and Autopilot ESP diagnostics, DSRegCmd analysis, and real-time log tailing.
Format auto-detection, severity color coding, and one-click Windows error-code lookup.
A color-coded event timeline for Win32 apps, scripts, and downloads — success and failure at a glance.
A single-page Autopilot and Device Preparation cockpit with actionable workload, MSIEXEC, coverage, and live-log evidence.
Device join posture, PRT and certificate health, and prioritized issue cards.
Screenshots are generated by
npm run screenshots. See screenshots/README.md.
Download the latest release for your platform and run it. That's it — single file, no dependencies.
Build status and nightly downloads are shown on the CMTrace Open build page.
| Platform | Download |
|---|---|
| Windows (x64) | .msi + NSIS .exe installers |
| macOS (Apple Silicon) | .dmg |
| Linux (x64) | .deb / .AppImage |
All releases are signed. The Windows executable is code-signed and the macOS app is notarized.
On macOS you can install with Homebrew instead:
brew install --cask cmtrace-openApple Silicon only: the macOS build is arm64, so Homebrew refuses the install on an Intel Mac rather than falling back to Rosetta. The cask is staged in this repository at Casks/cmtrace-open.rb and is pending acceptance into homebrew-cask; the command works once that lands. See Casks/README.md for the submission and version-bump process.
On Windows you can install with Scoop instead:
scoop bucket add cmtraceopen https://github.com/adamgell/cmtraceopen
scoop install cmtracex64 and arm64, portable: Scoop drops the single-file executable in its own directory, so no installer runs and nothing lands in Program Files. Use scoop install cmtrace-lite for the Lite edition. This repository doubles as its own Scoop bucket: the manifests are in bucket/ and a release workflow bumps them. Submission to ScoopInstaller/Extras, which removes the scoop bucket add step, is still pending. See bucket/README.md for that process and for how the manifests stay current.
Startup update checks are disabled by default. Users can opt in from Settings > Updates. Managed Windows deployments can force-disable all app update checks with either installer:
CMTrace-Open_*_x64-setup.exe /S /DisableUpdateChecks
msiexec /i CMTrace-Open_<version>_x64.msi /qn DISABLEUPDATECHECKS=1The MSI option writes HKLM\Software\CMTrace Open\DisableUpdateChecks=1 and survives uninstall or upgrade until an administrator removes it. The NSIS switch writes the same value under the selected install registry hive. Existing user preferences cannot re-enable update checks on managed devices while this policy is present.
Note: You do not need Node.js, Rust, or any development tools to run CMTrace Open. Just download and run.
CMTrace Open ships as two standalone builds from the same source. Both are single-file executables with no installer or dependencies. The download page labels them "full edition" and "lite edition". Choose Full unless you specifically want the smallest possible download - it is the default build and includes everything.
The complete tool: the log viewer plus every specialized troubleshooting feature.
| Feature | What it does | Platform |
|---|---|---|
| Intune Diagnostics | IntuneManagementExtension (IME) log analysis, event timeline, and download statistics | All |
| ESP Diagnostics | Read-only Autopilot ESP and Device Preparation triage with bounded live evidence, MSIEXEC activity, and optional Microsoft Graph enrichment | All (live acquisition: Windows) |
| DSRegCmd | Entra join, hybrid join, PRT, MDM, and Windows Hello for Business triage | Windows |
| Software Deployment | Scan a folder of app-install logs (MSI, PSADT, Burn, PatchMyPC) for exit codes and failures | Windows |
| Event Log Viewer | Open and query Windows Event Log (.evtx) files; enumerate live channels |
All (live channels: Windows) |
| Sysmon | Sysmon operational event log analysis | Windows |
| Secure Boot Certs | Secure Boot certificate-rotation analysis and remediation | All (live scan: Windows) |
| macOS Diagnostics | Intune, Defender, configuration profile, and package diagnostics | macOS |
| Diagnostic Collection | Gather logs, registry keys, and event logs into an evidence bundle | Windows |
The core log viewer only. It keeps everything under Log Viewer below - format auto-detection, real-time tailing, virtual scrolling, find and filter, text highlighting, and the embedded error-code database - plus the Timeline and DNS / DHCP tools. It leaves out the nine specialized features above, which also drops the Windows Event Log and property-list parsers and makes the binary noticeably smaller. Choose Lite if you just want a fast, portable, CMTrace-style log reader with a minimal footprint.
Both editions read the same log formats and share the same viewer, so a log you can open in Full opens identically in Lite.
- Auto-detection — automatically identifies CCM, CBS, DISM, Panther, simple, and plain text log formats
- Real-time tailing — live file watching with pause/resume
- Virtual scrolling — smooth performance with 100K+ line files
- Severity color coding — Errors (red), Warnings (yellow), Info (default)
- Find and Filter — Ctrl+F search with F3 navigation; filter by message, component, thread, or timestamp
- Text highlighting — configurable keyword highlighting
- Error code lookup — 700+ embedded Windows, Windows Update, BITS, ConfigMgr, Intune, MSI, and PSADT error codes
- Flexible input — open files, folders, drag and drop, or use built-in source presets
- File association — register as an available Windows log-file handler and open Default Apps to choose it
Analyze Intune Management Extension logs without reading raw text line by line.
- Parse a single IME log or an entire
IntuneManagementExtension\Logsfolder - Color-coded event timeline for Win32 apps, WinGet apps, PowerShell scripts, remediations, ESP, and sync sessions
- Download statistics with size, speed, and Delivery Optimization percentage
- Summary dashboard with event counts, success/failure rates, and log time span
- Automatic GUID extraction for app and policy identifiers
- Issue clustering with suggested next steps
Troubleshoot Windows Autopilot Enrollment Status Page (ESP), Autopilot Device Preparation, and software-install failures in one read-only workspace. Live collection runs on Windows; captured CMTrace Open evidence folders, manifest.json, CAB, and ZIP inputs can be analyzed on every supported desktop platform.
- Single full-width cockpit with no left sidebar: current phase, findings, workload status, enrollment evidence, Delivery Optimization, coverage, and What MSIEXEC is doing now stay visible together
- Classic ESP and Device Preparation are classified separately, including the applicable profile, enrollment, app, script, policy, certificate, Office, NodeCache, hardware, and event evidence from the PowerShell v6.3 diagnostic contract
- Every device and user enrollment session is retained; the latest session is identified chronologically, and a session selector can isolate any earlier attempt without collapsing retries
- Running as administrator is recommended as soon as a non-elevated Windows process enters the workspace because protected registry, event-log, process-command-line, SYSTEM-temp, and user-temp evidence materially improves coverage; non-elevated analysis still works and reports each unavailable source explicitly
- Live deployment logs are discovered only from curated IME/deployment roots and shallow, high-signal temporary locations; there is no deep scan or full-drive search
- Open live logs keeps collecting while collapsed, opens a vertically resizable dock, and can expand the logs to the full workspace with a clear restore action
- MSIEXEC sampling covers zero, one, or multiple processes and labels exact, parent-chain, identifier, temporal, or ambiguous correlation instead of guessing
- Local evidence and raw identifiers are always shown. The existing opt-in Windows WAM connection can add Intune names, assignments, Autopilot/ESP configuration, and device status without replacing local provenance. Opening or refreshing the ESP workspace never initiates WAM or
graph_request_missing_permissions; when Graph is persisted on, application startup may still run its existing authentication flow before ESP opens. Settings can explicitly open WAM to sign in or, for an authenticated partial connection, to re-request the complete fixed five-permission read-only union - Graph sections fail independently and label beta endpoints. Disabled, disconnected, denied, offline, throttled, partial, and cancelled Graph states never erase local logs or conclusions
- Graph requests are limited to the existing delegated read scopes
DeviceManagementManagedDevices.Read.All,DeviceManagementServiceConfig.Read.All,DeviceManagementApps.Read.All,DeviceManagementConfiguration.Read.All, andDeviceManagementScripts.Read.All; no write or group-membership permission is requested - Findings recommend read-only checks; the workspace does not install or retry applications, sync MDM, start or stop services, change registry values, run remediation, or modify Intune
- Missing, permission-denied, malformed, unsupported, and retention-limited sources remain explicit coverage gaps. A gap means the conclusion is incomplete, not that the device or workload is healthy
- Sensitive UPN, SID, tenant, EntDMID, serial, and NodeCache fields are masked by default, command lines are sanitized, access tokens remain memory-only, and raw hardware hashes are excluded from normal UI, logs, screenshots, copy, and export
Triage Entra join, hybrid join, PRT, MDM, and Windows Hello for Business issues.
- Live capture, paste, text file, or evidence bundle input
- Join posture, failure stage, and capture confidence at a glance
- Issue cards with severity, evidence, and suggested fixes
- Registry-backed Windows Hello for Business policy correlation
- Export as JSON or summary for case handoff
See the DSRegCmd workspace guide for a detailed walkthrough.
- Download the release for your platform from the CMTrace Open download page
- Run the executable — no install required (or use the Windows MSI/NSIS installer)
- Open a log — drag and drop a file, use File > Open, or use a source preset
- Explore — use Find (Ctrl+F), Filter, or switch to the Intune/DSRegCmd workspace
event-log-export is a headless exporter for .evtx files. It runs without the
GUI, which is what makes it useful on a machine where you would rather not launch
the app — pulling a channel from a customer's host, or scripting an export.
The release workflow builds separate Windows x64, macOS arm64 and Linux x64
assets, named for their version and target (for example
event-log-export-1.6.0-x86_64-pc-windows-msvc.exe). CI also builds and smoke-tests
the exporter with the same feature selection.
usage: event-log-export --source <file.evtx>... [--manifest <manifest.json>]
[--format csv|tsv|json|xml|html|rawXml] [--output <path|->]
[--channel <name>]... [--level <level>]... [--event-id <id>]...
[--search <text>]
# Print one channel as CSV
event-log-export --source System.evtx --channel System --format csv --output -
# Critical and Error events, as JSON, to a file
event-log-export --source Application.evtx --level Critical --level Error \
--format json --output application-errors.json
# Export the sources and filters named by a manifest rather than on the command line
event-log-export --manifest export.json --format json --output ---output - writes to stdout. The filters combine across flags: an event is
exported only when it satisfies every flag you supply, while several values for
one flag are alternatives to each other — --level Critical --level Error keeps
events at either level. --manifest cannot be combined with --source or with
the filter arguments.
Build it from a checkout with:
cd src-tauri
cargo build --locked --release --no-default-features --features event-log --bin event-log-exportThe event-log feature is required and is already included by the default
full feature. The command above selects only event-log; the binary is written
to src-tauri/target/release/ (event-log-export.exe on Windows).
The exporter shares the app's Rust library, so source builds still need the platform prerequisites, including GTK/WebKit development libraries on Linux. This direct Cargo build does not require Node.js or built frontend assets. It runs without opening a window but retains native library dependencies; Linux hosts need the GTK/WebKit runtime libraries.
| Format | Examples |
|---|---|
| CCM | <![LOG[...]LOG]!> — ConfigMgr client logs |
| CBS / DISM / Panther | CBS.log, dism.log, setupact.log, setuperr.log |
| Simple | $$< delimited — older SCCM-style logs |
| Plain text | Any .log or .txt file with or without timestamps |
Format detection is automatic. Open any log file and CMTrace Open will pick the right parser.
Visit the CMTrace Open Wiki for detailed guides:
- Getting Started — installation, first log, basic navigation
- Log Viewer Guide — find, filter, highlight, tailing
- Intune Workspace — IME log analysis and diagnostics
- DSRegCmd Workspace — device join and identity troubleshooting
- FAQ — common questions and answers
CMTrace Open welcomes contributions. See CONTRIBUTING.md for development setup, build commands, architecture overview, and coding guidelines.
Questions, feedback, feature ideas, and general discussion all belong in GitHub Issues. Open a feedback or question issue.
CMTrace is a tool developed and distributed by Microsoft Corporation. CMTrace Open is an independent open-source project and is not affiliated with, endorsed by, or connected with Microsoft Corporation. See DISCLAIMER.md for full details.



