IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Audit and Remediation: Why Are There Unexpected Number of Endpoints in Live query Results?

Audit and Remediation: Why Are There Unexpected Number of Endpoints in Live query Results?

Environment

  • Carbon Black Cloud Console: All Versions
  • Microsoft Windows: All Supported Versions
  • Audit and Remediation:July 2020 Backend Update
  • Linux: All Supported Versions
  • Apple MacOS 10.10+
  • Carbon Black Cloud Windows Sensor: 3.3 and Higher
  • Carbon Black Cloud MacOS Sensor: 3.3 and Higher
  • Carbon Black Cloud Linux Sensor: 2.3 and Higher 

Question

When running a live query on endpoints, the results seems to not be querying all of the endpoints in the environment. 

Answer

As of July 2 there were changes made on the backend to allow more results. VMware Carbon Black recently made a change to calculate the estimate of potential pool of devices on which the query can run whether you’ve selected a policy or All endpoints. Previously the estimate was number of devices that has checked in last in the last 2 hours. With the recent change that last check in time window was increased to 7 days.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎07-09-2020
Views:
437
Contributors