IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: Newly upgraded sensor does not connect to the EDR server.

EDR: Newly upgraded sensor does not connect to the EDR server.

Environment

  • EDR (formerly known as CB Response): All Versions
  • EDR sensor : All 6.x versions

Symptoms

  • Sensor fails to check in to the EDR console after an upgrade attempt.
  • Sensor diagnostics "sensor.log" shows these errors:
Tid[11D4] 2019-03-15 17:51:13 (e): WinHttpSendRequest() failed: WinError[0x00002EE2] 
Tid[11D4] 2019-03-15 17:51:13 (e): Unable to complete request from HTTP transaction 
Tid[11D4] 2019-03-15 17:51:13 (w): Failed to registerHTTPCode[2147954402] HrError[0x80072EE2] 
Tid[11D4] 2019-03-15 17:51:13 (i): failed to register HrError[0x80072EE2] 
Tid[11D4] 2019-03-15 17:51:13 (w): Unable to properly synch with server HrError[0x80072EE2]

Cause

Sensor fails to check in to the EDR server after an upgrade attempt.

Resolution

1. Stop the EDR Sensor service in services.msc snapin.
2. Run these commands as elevated administrator in a command prompt
fltmc          (lists kernel drivers)
fltmc unload carbonblackk    (unload CB driver.. note the two "k's")
fltmc          (to confirm the driver is unloaded.
3. Now restart the EDR Sensor service and monitor the WebUI Sensors page

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎03-22-2019
Views:
3644
Contributors