Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: How to remediate ContentDownloadFailure alarms (Linux)

Carbon Black Cloud: How to remediate ContentDownloadFailure alarms (Linux)

Environment

  • Carbon Black Cloud Console: All Versions
    • Endpoint Standard
    • Enterprise EDR
    • Audit & Remediation
    • Workload
  • Carbon Black Cloud Sensor: 2.12.x.x and Higher
  • Linux: All Supported Versions

Objective

Provide steps for correcting issues for Linux Sensors with downloading of content manifest data from content.carbonblack.io after receiving a related Alert

Resolution

  1. Check access to content.carbonblack.io from endpoint
  2. Verify that any configured proxy or firewall allows outbound (endpoint to cloud) communication
    URLPortDirectionSSL Inspection
    content.carbonblack.ioTCP/443OutboundDisabled
  3. Check status of Manifest downloads and ContentDownloadFailure alarms
  4. If the ContentDownloadFailure alarms continue in log.txt, please open a case with Carbon Black Technical Support and provide
    Hostname
    Verification of access from step 1
    Configuration information of firewall/proxy exclusion from step 2 (along with date/time implemented)
    Firewall/proxy logs with any errors in communicating with content.carbonblack.io
    Output of step 3 above

Additional Notes

There is no need to perform these steps unless directed to do so by a CB Analytics Alert in the Carbon Black Cloud Console or by a member of VMware Carbon Black Technical Support.

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎04-14-2022
Views:
421
Contributors