CB Response: Enabling New Feed updates process last_server_update
search cancel

CB Response: Enabling New Feed updates process last_server_update

book

Article ID: 289565

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

Old events become searchable after enabling a new feed.
 

Environment

  • CB Response Server: All versions

Cause

The process is tagged when it matches a query based report of the new feed.

Resolution

Working as designed

Additional Information

  • When a process matches a feed based query, it is tagged. This tag creates a new process segment in SOLR, which contains the metadata for the process, with a new timestamp. The tag is needed to correlate feed information in the process analyze few.
  • A side effect of this is that a watchlist searcher that runs will see it as a new activity of the process due to the time stamp.
  • There is no easy way to differentiate this type of an update from a regular update due to activity.