Access official resources from Carbon Black experts
Alert email received while the alert within the Cb Response console is not found under Detect > Triage Alert.
Upload Cb Diags (i.e., Server Logs) for review.
Provide a copy of the email alert received. This will help Support determine if the issue is feed- or watchlist-related.
psql -d cb -p 5002 -c "select id,name,enabled,feed_url,update_timestamp from alliance_feeds where enabled='t' and delete_timestamp is null;"
4. Output results of the process doc as text: How to output a process document as text file for troubleshooting
5. If pertaining to the Cb Reputation Trust Feed, the Cb Reputation Threat Feed, or the deprecated VirusTotal Feed please provide a copy of the binary document from the Cb Response server:
curl http://localhost:8080/solr/cbmodules/select?q=md5%3A{MD5HashHere}&wt=json&indent=true" > /tmp/binarydoc.out && /usr/share/cb/cbpost /tmp/binarydoc.out
7. Attach the screenshot of the email alert to the case along with the process doc and the binary doc.
Additional Notes
Collecting logs for Troubleshooting [Server - Cb Response]
How to output a process document as text file for troubleshooting
Copyright © 2005-2023 Broadcom. All Rights Reserved. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.