Cb Defense: How To Verify Sensor Package Removal From Application Management GPO
search cancel

Cb Defense: How To Verify Sensor Package Removal From Application Management GPO

book

Article ID: 285524

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense)

Issue/Introduction

When troubleshooting GPO deployment upgrade failures, the successful completion of the instructions found in https://community.carbonblack.com/t5/Knowledge-Base/Cb-Defense-How-to-Configure-GPO-to-Allow-Sensor-Upgrades/ta-p/40766 can be verified by checking the details for Event ID:303 in the System Event Log

Environment

  • Cb Defense Sensor: All Versions
  • Microsoft Windows: All Supported Versions
  • GPO deployment

Resolution

From the Event Viewer GUI:
1. Open Windows Event Viewer (eventvwr.msc)
2. Select the Sytem log
3. Select Filter Current Log
4. Enter Event ID: 303
5. Look for "The removal of the assignment of application Cb Defense Sensor xx-bit 3.x.x.x from policy %policy name% succeeded"

From locally stored System.evtx:
1. Open a command prompt
2. Change Directory (cd) into the folder where the local copy of System.evtx resides
3. Paste the following: 
wevtutil qe ".\system.evtx" /q:"*[System[(EventID=303)]]" /lf:true /c:20 /rd:true /f:text > GPO_assignment_check.txt
4. Open GPO_assignment_check.txt and look for: "The removal of the assignment of application Cb Defense Sensor xx-bit 3.x.x.x from policy %policy name% succeeded"

Additional Information

If the above entry is not found, refer back to the step outlined in https://community.carbonblack.com/docs/DOC-11087 and verify that the appropriate policy has been selected and each step was followed.