EDR: Process Analysis Displays HTTP 404 when Pulling Sensor Data after Loading Cold Partitions
book
Article ID: 287651
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
After mounting cold Solr cores to investigate events older than 30 days, EDR Console presents HTTP 404 on the Process Analysis page.
Environment
EDR Servers: 7.x.x
Cause
The cb.conf variable 'SensorLookupInactiveFilterDays' is set or the EDR Console "Sensor Display Settings" is configured. These settings limit the sensors being searched and their associated event data.
Resolution
Comment out 'SensorLookupInactiveFilterDays' in /etc/cb/cb.conf to view older sensors and their data. Repeat for each EDR server and restart cb-enterprise/cbcluster services.
Increase the "Sensor Display Settings" to a number of days that would include the sensor's event data under investigation.