search
cancel
Search
Troubleshooting AV Signature Pack Updates
book
Article ID: 291104
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Show More
Show Less
Issue/Introduction
Troubleshooting signature packs reporting out of date issues
Signatures are displaying red triangle status on checking in sensors
Environment
Endpoint Standard Console: All Supported Versions
Endpoint Standard Sensor: All Supported Versions
Resolution
Troubleshooting from the Console
Verify the device(s) are actively connecting to the backend by confirming the "Last Check-in" time on the inventory page.
Expand the "Signature Status" Filter".
Note how many devices are "Up to date" vs "Out of Date"
Note that anything within 7 days is not of high concern, so they can be filtered out:
Select the filter "Out of Date"
Search for devices that have checked in within 7 days
Are there any differences between the devices that are "out of date" vs "Up to date"?
Note if this is a global issue or related to endpoints on a specific network, operating system, or policy
Navigate to Enforce > Policies > <PolicyName> Local Scan tab
Confirm "Allow Signature Updates" is enabled
Confirm the update server "https://updates2.cdc.carbonblack.io/update2" has been added
Note this requires sensor version
3.3.x.x and above
For more frequent update attempts set 'Frequency' to 2 hours/'Randomization Window' to 1 hour
Troubleshooting from the Sensor
Test the connect to the
Signature Update URL
Confirm
firefall exceptions
are in place and SSL Inspection is not occurring
If the issue still occurs,
Collect sensor logs
and contact support
Additional Information
Enterprise EDR sensors won't have Signature Packs without Endpoint Standard as the Local Scanner is an ES feature
The latest VDF versions can be determined using
this process
Feedback
thumb_up
Yes
thumb_down
No