Carbon Black Cloud: How to Clean up ScanHost.log and ScanHost.log.tmp Files
search cancel

Carbon Black Cloud: How to Clean up ScanHost.log and ScanHost.log.tmp Files

book

Article ID: 288794

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense)

Issue/Introduction

How to clean up Scanhost.log and Scanhost.log.tmp files in situations where they're larger than they're supposed to be.

Environment

  • Endpoint Standard Sensor: All Supported Versions
  • Microsoft Windows: All Supported Versions

Resolution

Remotely:
  1. Clone the Policy
  2. Edit the Local Scan tab, setting the Scanner Config option below:
    On-Access File Scanning Mode = Disabled
  3. Move effected device to the new policy, and wait for it to receive the policy changes
  4. Place the device temporarily into Bypass Mode, and wait for the device to receive this change
  5. Launch GoLive
  6. Navigate to the following location:
    C:\ProgramData\CarbonBlack\Logs
  7. Delete Scanhost.log and ScanHost.log.tmp
  8. Disable Bypass Mode
  9. Move device back to original policy

Locally:
  1. Place effected device into Bypass mode
  2. Stop the services via repcli
  3. Zip the file:
    C:\ProgramData\CarbonBlack\Logs\scanhost.log
  4. Delete the file:
    C:\ProgramData\CarbonBlack\Logs\scanhost.log.tmp
  5. Run the following to start services
    net start cbdefense
  6. Bring the device out of Bypass mode