CB Response: Why am I seeing multiple hits per process in a search
search cancel

CB Response: Why am I seeing multiple hits per process in a search

book

Article ID: 285354

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

Why do multiple results sometimes appear for the same process when performing a process search in the CB Response Console?

Environment

  • CB Response Server: 6.0.1 and above

Resolution

For performance reasons, CB Response stores a single longer-running process as multiple documents which are called segments in our backend database.  Searches may provide hits on more or more segments of a process, resulting in multiple results in a process search.  You may select the "GROUP BY PROCESS" checkbox on the on the Process Search page in order to eliminate duplicate results that are associated with the same process if you are only interested in reviewing unique process results.