CB Response: Enabling New Feed updates process last_server_update
book
Article ID: 289565
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Old events become searchable after enabling a new feed.
Environment
CB Response Server: All versions
Cause
The process is tagged when it matches a query based report of the new feed.
Resolution
Working as designed
Additional Information
When a process matches a feed based query, it is tagged. This tag creates a new process segment in SOLR, which contains the metadata for the process, with a new timestamp. The tag is needed to correlate feed information in the process analyze few.
A side effect of this is that a watchlist searcher that runs will see it as a new activity of the process due to the time stamp.
There is no easy way to differentiate this type of an update from a regular update due to activity.