IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: How to Troubleshoot Sensor Interoperability Issues

Carbon Black Cloud: How to Troubleshoot Sensor Interoperability Issues

Environment

  • Carbon Black Cloud Sensor: All supported versions

Objective

How to Troubleshoot Sensor Interop Issues

Resolution

CRITICAL: PLEASE DO NOT UNINSTALL THE SENSOR
Troubleshooting cannot take place with sensor uninstalled as information needed is not available.

Please open a case with CB Support, the case will start by requesting:

  1. Device name in the Carbon Black Cloud Console
  2. Application experiencing interoperability
  3. Date/Time interoperability occurred
  4. Application actions performed or blocked
  5. Are results the same if Sensor is placed in Bypass?
  6. Remove Sensor from Bypass and attempt to implement a Permissions rule
  7. Test using a Permissions rule
  8. Is the interoperability issue reproducible?
    1. If yes and the OS is Windows, collect 2 separate Procmon logs:
    2. Steps for Windows 3.3.x.x Sensor and earlier or steps for Windows 3.4.x.x Sensor and higher
      1. Procmon with the Sensor Active and with the issue reproduced
      2. Procmon with the Sensor in Bypass taking the same steps as above
    3. After collecting Procmon logs, request Sensor logs:
    4. Collecting Sensor Logs Windows
    5. Collecting Sensor Logs Mac
    6. Collecting Sensor Logs Linux

If this issue cannot be solved with Support troubleshooting steps, it may need escalation to the Engineering team.  Escalation will require information collected in the steps above:

  1. Procmon with the Sensor Active
  2. Procmon with the Sensor in Bypass
  3. Sensor logs collected following the final Procmon log being saved

Additional Notes

Sensor interoperability issues display as one or more:
  1. Application slowness
  2. Delayed start of application
  3. An application operation not functioning
  4. Application is blocked or crashes

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-19-2020
Views:
2035
Contributors