IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: How To Check DeviceID On Endpoint (Windows, 3.7+)

Carbon Black Cloud: How To Check DeviceID On Endpoint (Windows, 3.7+)

Environment

  • Carbon Black Cloud Sensor: 3.7.x.x and Higher
  • Microsoft Windows: All Supported Versions

Objective

Explain the steps to confirm the DeviceID of a 3.7.x.x or higher Sensor on the machine where it is installed

Resolution

CMD.EXE

  1. Launch an elevated command prompt (right-click cmd.exe > Run as Administrator)
  2. Run the following command
    findstr "RegistrationId" C:\ProgramData\CarbonBlack\DataFiles\cfg.ini
  3. The output will be in the following format
    RegistrationId=<org_id>-<device_id>

Powershell

  1. Launch an elevated Powershell.exe instance (right-click powershell.exe > Run as Administrator)
  2. Run the following command
    Select-String "RegistrationId" C:\ProgramData\CarbonBlack\DataFiles\cfg.ini
  3. The output will be in the following format
    C:\ProgramData\CarbonBlack\DataFiles\cfg.ini:<Line#>:RegistrationId=<org_id>-<device_id>

Additional Notes

  • Confirming the DeviceID locally on the machine with the Sensor installed can be helpful in troubleshooting issues and reviewing Alerts and other Events within the Carbon Black Cloud Console
  • For example, with the DeviceID you can review Events specific to that single device on the Investigate page by replacing <DeviceID> with the ID retrieved using the above method
    https://<DashboardURL>/investigate?selected[deviceId]=<DeviceID>&selected[selectedTab]=DEVICE&s[searchWindow]=ALL&s[c][DEVICE_ID][0]=<DeviceID>
  • Searching for device_id on applicable Inventory pages will find the device tied to that registration, regardless of the current hostname
    • device_id is the unique identifier for a given Sensor in relation to VMware Carbon Black Cloud
    • Hostname, IP Address, and Active Directory information are all considered metadata for a device record as they all can be changed
  • Point of presence (PoP) or Backend can also be found in the cfg.ini file to ensure a given device is registered to the correct PoP/Backend
    cmd.exe
    \> findstr "BackendServer" C:\ProgramData\CarbonBlack\DataFiles\cfg.ini
    BackendServer=<Device_Services_URL>
    
    Powershell.exe
    \> Select-String "BackendServer" C:\ProgramData\CarbonBlack\DataFiles\cfg.ini
    C:\ProgramData\CarbonBlack\DataFiles\cfg.ini:<Line#>:BackendServer=<Device_Services_URL>
    

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎08-18-2021
Views:
1643
Contributors