EDR Server: Watchlists and feeds are no longer running
book
Article ID: 292075
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Environment
- EDR (formerly CB Response) Server: 6.2.3 and lower
Cause
- Nested queries running longer, most noticeably with modload searches - CB-14781.
- Watchlist queries returning incomplete results lock up watchlist searches for hours - CB-17415.
Resolution
- Upgrade to 6.3 or higher to resolve both CB-17415 and CB-14781
- Upgrade to 6.2.3 to resolve CB-17415
- Workaround if an upgrade is not possible
- Determine which watchlist or threat report query is causing the hang
- Disable the query in the UI
Additional Information
The watchlist_search will eventually stop, but can be
stopped maually
Feedback
thumb_up
Yes
thumb_down
No