EDR: Alerts not being generated for Watchlists.
book
Article ID: 290305
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
- Watchlist hits are reported on the Watchlist page, however events are not appearing in the Triage Alerts page.
- /var/log/cb/datastore directory contains large amount of debug.log#######.tmp files
Cause
Known issue with the datastore.debug.log files, to be addressed in future release.
Resolution
- Open the /etc/cb/cron/cb.cron.template file to edit
- Set cronjob to remove .tmp files from '/var/log/cb/datastore/' older than 7 days:
0 0 * * * root find /var/log/cb/datastore -name *.tmp -mtime +7 -delete
Feedback
thumb_up
Yes
thumb_down
No