Environment
- Carbon Black Cloud: Version 1.21 and Earlier
Symptoms
Marking a hash to be deleted from a small group (or single) sensor appears to have a wider effect than expected creating an Audit log trail showing almost ALL endpoints have the hash removed.
Cause
When the hash is marked to be deleted from sensors, if it is not found on an endpoint, it will still be included in origins index on all endpoints and create a false positive effect in the Audit logs and Binary details pages showing the hash being deleted everywhere.
Resolution
Created DSER-47845 and the issue was fixed in 1.22 backend release (January 18th 2024)