Collect Interoperability Logs for Carbon Black Cloud Sensor
book
Article ID: 291477
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint StandardCarbon Black Cloud Enterprise EDRCarbon Black Cloud Workload
Issue/Introduction
Steps to locally collect interoperability logs for the Carbon Black Cloud Sensor on Windows to identify and troubleshoot software conflicts with third-party applications.
Note: Troubleshooting cannot take place with the sensor uninstalled. Support will need access to a device with the sensor installed and experiencing the issue.
Open a case with Carbon Black Support and the provide the following:
Relevant Information:
Date/Time interoperability issue occurred (did any change precede the start of it?)
Application name experiencing interoperability
Does the vendor of the application have a recommended exclusion list and has it been implemented?
Any paths/processes known to be associated with the application (This can be derived from a procmon capture)
Are there any blocks seen locally or within the Carbon Black console during the interop issue?
Is there any other security software which could be scanning the sensor or the application in question?
If there is other security software running is Carbon Black scanning it?
Action being performed when interop issue occurs (Expected outcome vs actual outcome)
Are results the same if the sensor is in bypass mode or uninstalled?