EDR SplunkApp: Unable to query 1000+ sensors using SplunkApp
book
Article ID: 287400
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
- Unable to query more than 1000 sensors at a time.
Environment
- EDR Server: 7.6.x +
- EDR SplunkApp: 3.0.3 or lower
Cause
- Changes in EDR Server 7.6.1 enabled pagination to help with application loading (see Related Content below).
- The EDR SplunkApp 3.0.3 and lower contains the 1.7.6 CB Python API, which has not bee updated for the pagination changes mentioned above.
Feedback
thumb_up
Yes
thumb_down
No