Cb Defense: Unable To Automatically Dismiss Alerts From All Devices
book
Article ID: 288972
calendar_today
Updated On: 07-26-2019
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Issue/Introduction
How to implement a workaround for dismissing grouped Alerts to bulk-dismiss similar alerts but not dismiss them for future / with persistence.
Environment
- Cb Defense Web Console: All Versions
- Cb Defense Sensor: 2.0.2.x+ (Windows)
- Cb Defense Sensor: 1.2.3.x+ (Mac)
- Microsoft Windows: All Supported Versions
- Apple MacOS: All Supported Versions
Resolution
- Go to the Alerts page
- Turn Group Alerts on
- Select the desired Alert(s)
- Select Dismiss or Dismiss on all devices from the drop-down on the far-right
- Leave If this alert occurs in the future, automatically dismiss it from all devices unchecked
- Enter a Comment as desired in the (Optional) for audit log field
- Click Dismiss
Additional Information
If you are facing this same issue you do not need to submit a case at this time, as all cases to this point have shown the same behavior.
Follow the steps below to confirm you are facing the same issue.
- Go to the Alerts page
- Open Developer Tools (F12 in chrome and firefox)
- Select an Alert which you have previously been unable to dismiss with persistence or for the future
- From the drop-down on the far-right select Dismiss or Dismiss on all devices
- Check If this alert occurs in the future, automatically dismiss it from all devices
- Click Dismiss
- Check the Network tab in Developer Tools for the dismiss item
- Review the Response and you will see an error like the following
{"success":false,"message":"Threat <32digitThreatID> is already DISMISSED"}
- Copy the ThreatID
- Go to the Audit Log and search for that ThreatID with the time set to All Time to see the original dismissal
Feedback
Was this article helpful?
thumb_up
Yes
thumb_down
No