Environment
- Carbon Black Cloud Sensor: 3.5.0.1627 and Lower
- Windows Server: All supported versions
Symptoms
- High memory usage after query start
- Domain Controllers harder hit when user-based LiveOps queries are run
- Long-running queries will consume system resources until host and/or osquery process crash.
Cause
- Osquery bug
- Sensor logic not optimal
Resolution
Upgrade to sensor 3.5.0.1680 or Higher
Additional Notes
Related Content
#CarbonBlackCloud#EnterpriseEDR