IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud: How to verify Bypass Mode from the Console

Carbon Black Cloud: How to verify Bypass Mode from the Console

Environment

  • Carbon Black Cloud Console: All Versions
  • Carbon Black Cloud Sensor: All Versions
  • Microsoft Windows: All Versions
  • Apple MacOS: All Versions

Objective

How to verify Bypass Mode from the Carbon Black Cloud Console

Resolution

Endpoints Page

In order for Sensor Bypass actions to take effect, the sensor must check-in to the Carbon Black Cloud backend. Typically this occurs every 5-10 minutes.
  1. Search for the device where Bypass was Enabled. Status can be changed to "All" to widen the search scope or "Bypass" to narrows the search scope.
  2. Under Device Last Check-In there will be one of two bypass descriptions:

Inbox Page

Triggered: Admin requested Bypass via Console
Sent to Sensor: Sensor checked into Console, received Bypass hint
  • Bypass Enabled
    REQUEST TIME
    DEVICESUBTYPESTATUSREQUESTED BYACTION
    Date/Time{InstalledBy} / {DeviceName}BypassTriggered{AdminEmail}On
    Date/Time{InstalledBy} / {DeviceName}BypassSent to Sensor{AdminEmail}On
  • Bypass Disabled
    REQUEST TIME
    DEVICESUBTYPESTATUSREQUESTED BYACTION
    Date/Time{InstalledBy} / {DeviceName}BypassTriggered{AdminEmail}Off
    Date/Time{InstalledBy} / {DeviceName}BypassSent to Sensor{AdminEmail}Off

Additional Notes

Sensor UI Taskbar Icon Meanings
Pre 3.5Post 3.5Sensor Mode
pre-3.5 Activepost-3.5 ActiveActive
pre-3.5 Bypasspost-3.5 BypassBypass
pre-3.5 Quarantinepost-3.5 QuarantineQuarantine
The Sensor Bypass (Admin Action) status is currently used as the default reason if there is a driver failure as well. So this status does not always mean that an Admin initiated the bypass. There is an enhancement request to enable additional bypass reasons here.

Related Content


Was this article helpful? Yes No
100% helpful (1/1)
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
5953
Contributors