IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CB Response: Windows Sensor slow to boot

CB Response: Windows Sensor slow to boot

Environment

  • CB Response Sensor: (All versions)
  • Microsoft Windows: All Supported Versions

Symptoms

  • Unusually slow bootup time on Windows endpoint

Cause

The AntiVirus software (such as Windows Defender) scans the CB Response Sensor directory, which consumes resources and causes delays in bootup.

Steps to confirm:

  1. Ensure the CB Response Sensor is installed
  2. Gather boot logs (requires a reboot)
  3. Open the captured boot log file
  4. Click the Tools menu > Process Activity Summary
  5. Click the CPU column to sort the entries
  6. Note the highest processes, which are likely to be AntiVirus software related (example: MsMpEng.exe is Windows Defender)

Resolution

  1. Configure the AntiVirus software to ignore the Cb Response Sensor directory (%WINDIR%\CarbonBlack\* by default)
  2. Configure the AntiVirus software to ignore the Cb Response Sensor Process (cb.exe)

Additional Notes

If the sensor process name was modified in the sensor groups page, please add the new process name to the exclusions list

Related Content


Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎05-24-2018
Views:
2693
Contributors