下面的实例是使用UMDH抓取IBM Spectrum Symphony环境下的核心进程vemkd的core dump文件。
1. Install WinDbg, which will include GFlags and UMDH.参考下面MS的链接安装WinDbg,里面会带有GFlags和UMDH两个工具。 https://docs.microsoft.com/en-us/windows-hardware/drivers/debugger/ 2. Set below environment variables. _NT_SYMBOL_PATH points to where vemkd.pdb locates, OANOCACHE=1 disables BSTR caching so that UMDH can determine the owner of a memory allocation. 设置环境变量_NT_SYMBOL_PATH,这个变量会指向vemkd.pdb文件,而OANOCACHE=1则会把BSTR缓存去掉,这样UMDH就可识别内存分配属于谁。
C:\Users\Administrator>set _NT_SYMBOL_PATH=C:\SpectrumComputing\3.8\etc
C:\Users\Administrator>set OANOCACHE=1
3. Run below command to enable the user-mode stack trace database in UMDH.运行下面的命令来启动