Access official resources from Carbon Black experts
Version
Cb Defense - All Versions
Topic
This document answers some of the most commonly asked questions regarding what happens when a sensor is offline, whether it is considered On-Premises (On-Prem) or Off-Premises (Off-Prem) as far as your organization is concerned.
Q/A
Question 1
How often is data uploaded from a Cb Defense Sensor to the cloud?
Answer
The Cb Defense Sensor checks in with the Cb Defense cloud periodically (on a 5-minute recurring basis timed on the local machine from either the installation of the sensor or the last device reboot) to upload event data. Therefore, Event and Alert information visible in the console should not be considered to be real-time.
Question 2
What impact does being On-Prem or Off-Prem have on the uploading of data? If our organization has workstations which are taken for travel purposes or working from home, and intermittently connect to our corporate network via VPN or similar, will data or logs only be uploaded or will the sensors only check-in when connected to the corporate network?
Answer
The device being On-Prem or Off-Prem should not have an impact on the uploading of data as long as the sensor is able to connect to the Cb Defense Cloud. If the device is offline for an extended period of time, the following applies:
Question 3
Does any sort of "open" internet connection (i.e., at home or in a hotel) constitute connectivity to the cloud? Are there additional requirements or caveats (i.e., ethernet/WiFi, connection to original network adapter at time of installation, etc.)?
Answer
The requirements for connectivity are listed in Cb Defense: Firewall and Proxy Settings for Sensor Communications. To sum those up, the sensor needs to be able to connect to the Cb Defense Cloud on TCP port 443 (or alternate TCP port 54443). If those requirements are met, the sensor should be able to report back to the cloud when Off-Prem the same as it does while On-Prem. There are no other restrictions or limitations based on the specific wired or wireless connection. You also do not need to connect to the same network adapter that was used during the initial installation or the most recent On-Prem connection.
Important Notes
If you are seeing that some of your sensors are not reporting to the cloud while Off-Prem, our Support team would be happy to help troubleshoot such issues. Keep the device in question online and the sensor installed, so our Support team can grab sensor logs from it via the Cb Defense Cloud. Those will be needed for investigation. Please Create a Case in The Community and include the following information for Support to review:
Related Content
Cb Defense: Firewall and Proxy Settings for Sensor Communications
Cb Defense: How To Verify That Cb Defense Sensor for Windows is Actively Running
Cb Defense: How To Verify That Cb Defense Sensor for Mac is Actively Running