CB Response: Why am I seeing multiple hits per process in a search
book
Article ID: 285354
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Why do multiple results sometimes appear for the same process when performing a process search in the CB Response Console?
Environment
CB Response Server: 6.0.1 and above
Resolution
For performance reasons, CB Response stores a single longer-running process as multiple documents which are called segments in our backend database. Searches may provide hits on more or more segments of a process, resulting in multiple results in a process search. You may select the "GROUP BY PROCESS" checkbox on the on the Process Search page in order to eliminate duplicate results that are associated with the same process if you are only interested in reviewing unique process results.