Cb Defense: How To Verify Sensor Package Removal From Application Management GPO
book
Article ID: 285524
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Issue/Introduction
When troubleshooting GPO deployment upgrade failures, the successful completion of the instructions found in https://community.carbonblack.com/t5/Knowledge-Base/Cb-Defense-How-to-Configure-GPO-to-Allow-Sensor-Upgrades/ta-p/40766 can be verified by checking the details for Event ID:303 in the System Event Log
Environment
Cb Defense Sensor: All Versions
Microsoft Windows: All Supported Versions
GPO deployment
Resolution
From the Event Viewer GUI: 1. Open Windows Event Viewer (eventvwr.msc) 2. Select the Sytem log 3. Select Filter Current Log 4. Enter Event ID: 303 5. Look for "The removal of the assignment of application Cb Defense Sensor xx-bit 3.x.x.x from policy %policy name% succeeded"
From locally stored System.evtx: 1. Open a command prompt 2. Change Directory (cd) into the folder where the local copy of System.evtx resides 3. Paste the following: wevtutil qe ".\system.evtx" /q:"*[System[(EventID=303)]]" /lf:true /c:20 /rd:true /f:text > GPO_assignment_check.txt 4. Open GPO_assignment_check.txt and look for: "The removal of the assignment of application Cb Defense Sensor xx-bit 3.x.x.x from policy %policy name% succeeded"
Additional Information
If the above entry is not found, refer back to the step outlined in https://community.carbonblack.com/docs/DOC-11087 and verify that the appropriate policy has been selected and each step was followed.