IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard: Troubleshooting AV Signature Pack Updates From The Console

Endpoint Standard: Troubleshooting AV Signature Pack Updates From The Console

Environment

  • Endpoint Standard Console: All Supported Versions
  • Endpoint Standard Sensor: All Supported Versions

Objective

Troubleshooting signature packs reporting out of date.

Resolution

  1. Verify devices are actively checking in
  2. Review the devices and their policy settings
  3. Verify policy is set to allow updates and the update server URL is configured
    1. Verify 'On-Access File Scan Mode' is set to Normal/Aggressive, and "Allow Signature Updates" is Enabled
    2. Try increasing 'Frequency' to 2 hours and 'Randomization Window' to 1 hour
    3. Add https://updates2.cdc.carbonblack.io/update2 for update servers (only works with 3.3 Sensors and up)
  4. Sorting the endpoints page by the Sig outdated status
    1. Count the number of signature outdated devices
    2. Check how old the current updates are
    3. Anything within seven days is not of high concern
  5. If the above steps have not resolved the issue please reach out to support

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-14-2023
Views:
928
Contributors