Version
This solution applies to all Carbon Black versions.
Topic
When a Binary Watchlist hit is observed, multiple Sensor Groups are reported in the resulting Syslog event. Some of the Sensor Group(s) may appear to be misleading.
Q/A
Why is a Syslog event reporting a "Default Group" Sensor Group when I have zero hosts that belong to this Group?
Carbon Black reports all of the Sensor Group(s) that this binary has been observed in. For example with zero Sensors in the Default Group and a Syslog event reports the Default Group, it means that at one point this particular binary was observed on a host that at one point existed in the Default Group. This is functioning as designed.