Access official resources from Carbon Black experts
Cb Response 5.x
How to query for process or binary solr documents from corresponding UI pages
Note: For 6.x check here: 6.x Query Documents Via Curl (SSH/Terminal)
Querying for a Process Document, Binary Document, and Common Errors
Example:
https://SERVERADDRESS/#analyze/PARTIALPROCESSID/SEGMENTID
https://192.168.111.129/#analyze/00000001-0000-0bb8-01d1-37c70078d47f/1
Note: this is not the complete unique_id or id field that is stored in Solr
192.168.111.5
cb-minion-optest
1
Example:
curl "http://127.0.0.1:8080/solr/SHARD/select?q=unique_id:PARTIALUNIQUEID*&wt=json&indent=true"
curl "http://127.0.0.1:8080/solr/1/select?q=unique_id:00000001-0000-0bb8-01d1-37c70078d47f*&wt=json&indent=true"
Example:
curl "http://127.0.0.1:8080/solr/SHARD/select?q=id:%22PARTIALUNIQUEID%22&wt=json&indent=true"
curl "http://127.0.0.1:8080/solr/0/select?q=id:%22-7459131266113492148%22&wt=json&indent=true"
Note: This is a URL Encoded Command. It includes “%22” (ASCII for quotes ") which are necessary when the number is negative
https://SERVERADDRESS/#/binary/MD5HERE
curl 'http://127.0.0.1:8080/solr/cbmodules/select?q=md5:MD5HERE&rows=5&indent=true'
The incorrect server server or shard has been queried (eg shard 0 does not exist on this server) or an incorrect Shard Id is being used.
If you are not getting any documents returned verify you have the correct Shard Id. If the page is still accessible in the UI, the data still exists. If you are receiving a 404 error in the UI, the document has been purged or does not exist.
Copyright © 2005-2023 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.