IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Cb Defense: How To Verify Sensor Package Removal From Application Management GPO

Cb Defense: How To Verify Sensor Package Removal From Application Management GPO

Environment

  • Cb Defense Sensor: All Versions
  • Microsoft Windows: All Supported Versions
  • GPO deployment

Objective

When troubleshooting GPO deployment upgrade failures, the successful completion of the instructions found in PSC: How to Configure GPO to Allow Sensor Upgrades can be verified by checking the details for Event ID:303 in the System Event Log

Resolution

From the Event Viewer GUI:
1. Open Windows Event Viewer (eventvwr.msc)
2. Select the Sytem log
3. Select Filter Current Log
4. Enter Event ID: 303
5. Look for "The removal of the assignment of application Cb Defense Sensor xx-bit 3.x.x.x from policy %policy name% succeeded"

From locally stored System.evtx:
1. Open a command prompt
2. Change Directory (cd) into the folder where the local copy of System.evtx resides
3. Paste the following: 
wevtutil qe ".\system.evtx" /q:"*[System[(EventID=303)]]" /lf:true /c:20 /rd:true /f:text > GPO_assignment_check.txt
4. Open GPO_assignment_check.txt and look for: "The removal of the assignment of application Cb Defense Sensor xx-bit 3.x.x.x from policy %policy name% succeeded"

Additional Notes

If the above entry is not found, refer back to the step outlined in https://community.carbonblack.com/docs/DOC-11087 and verify that the appropriate policy has been selected and each step was followed.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-14-2018
Views:
540
Contributors