EDR: How to Use Live Response to Collect Sensor Diags
book
Article ID: 285288
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
To obtain sensor/endpoint diagnostics with the help of CB response Live response (CBLR)
Environment
- EDR Server: 6.0.1 and Higher (formerly CB Response)
- Microsoft Windows: All Supported Versions
- 7zip
Resolution
6.2.2 and Above:
- Open Live response session from EDR Console.
- Generate sensor diagnostics by running the following command:
- Obtain the .zip by running
- A pop up will be prompt you to save the file.
Sensor Version 6.2.1 and Below:
- Open Live response session from EDR Console.
- Generate sensor diagnostics by running the following command:
- Confirm that diagnostics logs have been generated at C:\windows\carbonblack\diagnostics by checking that there is a list of current .log files there.
- Zip the diagnostic directory by running the following command from 7zip installation directory:
- Obtain the resultant .zip file by running:
- A pop up will be prompt you to save the file
Additional Information
7zip can be downloaded from https://www.7-zip.org/download.html and can be pushed on to the endpoint using the CB Live Response.
Feedback
thumb_up
Yes
thumb_down
No