CB Protection: Sattline is slow to write files.
book
Article ID: 290960
calendar_today
Updated On:
Products
Carbon Black App Control (formerly Cb Protection)
Issue/Introduction
Sattline application is slow to write files when CB Protection is installed
Environment
- CB Protection Server: All versions
- CB Protection Agent: All Versions
- Sattline application
Cause
CB Protection looks at .rv and .rt files created by Sattline and slows their writes.
Resolution
Two agent config properties need to be created
- Go to https://<servername>/agent_config.php
- Click on "Add Agent Config"
- Use the following values for the first exclusion:
- Property Name:: Exclude_Sattline_File_Access
- Host ID: 0
- Value: kernelFileOpExclusions=*.rv:128895,*.vt:128895
- Platform: All Platforms
- Status:: Enabled
- Use the following values for the second exclusion:
- Property Name: Exclude operations by main.exe
- Host ID: 0
- Value: KernelProcessExclusions=*\main.exe:131071
- Platform:: All Platforms
- Status:: Enabled
Additional Information
- Operation Code 128895 means that we will not process any operations on the .rv and .vt files EXCEPT executes and script executes
Feedback
thumb_up
Yes
thumb_down
No