# Check what remains in a cluster WER report before relying on it

> Which cluster diagnostic artifacts should be preserved before a WER report is archived?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-123-check-what-remains-in-a-cluster-wer-report-before-relying-on-it/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:15:08+00:00
- Modified: 2026-09-08T18:23:27+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Which cluster diagnostic artifacts should be preserved before a WER report is archived?

## Potentially affected

Administrators collecting failover-cluster evidence through Windows Error Reporting.

## DSE recommendation

Agree on the diagnostic collection with the cluster owner before reproducing a failure.

## Article

## Source facts

Microsoft describes Windows Error Reporting as an event-driven mechanism for collecting information about detected Windows hardware and software problems. For cluster diagnostics, the DumpLogQuery resource property holds multiple XPath queries used to collect logs after the relevant event channels are enabled. Microsoft notes that uploaded reports in the WER archive retain Report.wer while the accompanying report data is deleted. [Microsoft documentation](https://learn.microsoft.com/en-us/windows-server/failover-clustering/troubleshooting-using-WER-reports).

## Applicability

Identify the failing cluster resource, event time, collection configuration, report location, and support case. Review which event channels are needed for the investigation and the permissions required to collect them.

## DSE recommendation

Agree on the diagnostic collection with the cluster owner before reproducing a failure. Preserve the report and relevant logs through the organization’s approved evidence process, documenting their origin and timestamps. Check the actual files present instead of assuming an archived report still contains every original artifact.

## Verification

Open the retained evidence and confirm that it covers the resource and failure window being investigated. Compare the collection queries with the included event channels and list missing files explicitly. Use supported analysis tools and keep any gap in the report separate from a conclusion about the cluster’s root cause.

## Official references

[Microsoft Learn: Troubleshooting a Failover Cluster using Windows Error Reporting](https://learn.microsoft.com/en-us/windows-server/failover-clustering/troubleshooting-using-WER-reports). Source reviewed September 8, 2026.

## Primary reference

- Name: Troubleshooting a Failover Cluster using Windows Error Reporting
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/failover-clustering/troubleshooting-using-WER-reports
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check what remains in a cluster WER report before relying on it,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-123-check-what-remains-in-a-cluster-wer-report-before-relying-on-it/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
