CB Response: How to purge the Yara 1.x database
book
Article ID: 288068
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
To purge the Yara database, most typically in order to allow the system to re-scan all binaries in the deployment.
Environment
- CB Response: 6.x
- CB Yara connector 1.x
Resolution
- Log into the CB Response master server
- Delete: /usr/share/cb/integrations/yara/db/sqlite.db
- Restart the Yara connector:
# service cb-yara-connector restart
Additional Information
A new sqlite.db file will be created after the cb-yara-connector process begins.
Feedback
thumb_up
Yes
thumb_down
No