Article Number: 000227088
Les utilisateurs peuvent rencontrer une erreur d’écran bleu après la mise à jour de CrowdStrike.
Le message d’erreur se lit comme suit :
Stop Code:Page_fault_in_nonpaged_area What failed: csagent.sys
La cause fait l’objet d’une enquête par CrowdStrike. Contactez CrowdStrike pour plus d’informations. https://www.crowdstrike.com/contact-us/
Cet article est mis à jour au fur et à mesure que de nouvelles informations sont disponibles.
Un redémarrage de l’ordinateur peut lui permettre de télécharger un fichier de canal fonctionnel.
Si l’erreur d’écran bleu se produit après un redémarrage, procédez comme suit pour contourner ce problème :
} | default(value="0", field=[CSUcounter, SHBcounter]) // Make sure both ConfigState update and SensorHeartbeat have happened | selfJoinFilter(field=[cid, aid, ComputerName], where=[{ConfigStateUpdate}, {SensorHeartbeat}]) // Aggregate results | groupBy([cid, aid], function=([{selectFromMax(field="@timestamp", include=[CFVersion])}, {selectFromMax(field="@timestamp", include=[@timestamp]) | rename(field="@timestamp", as="LastSeen")}, max(CSUcounter, as=CSUcounter), max(SHBcounter, as=SHBcounter)]), limit=max) // Perform check on selfJoinFilter | CFVersion=* LastSeen=* // Calculate time between last seen and now | LastSeenDelta:=now()-LastSeen // Optional threshold; 3600000 is one hour | LastSeenDelta>3600000 // Calculate duration between last seen and now | LastSeenDelta:=formatDuration("LastSeenDelta", precision=2) // Convert LastSeen time to human-readable format | LastSeen:=formatTime(format="%F %T", field="LastSeen") // Enrich aggregation with aid_master details | aid=~match(file="aid_master_main.csv", column=[aid]) | aid=~match(file="aid_master_details.csv", column=[aid], include=[FalconGroupingTags, SensorGroupingTags]) // Convert FirstSeen time to human-readable format | FirstSeen:=formatTime(format="%F %T", field="FirstSeen") // Move ProductType to human-readable format and add formatting | $falcon/helper:enrich(field=ProductType) | drop([Time]) | default(value="-", field=[MachineDomain, OU, SiteName, FalconGroupingTags, SensorGroupingTags], replaceEmpty=true) | case{ CSUcounter=0 AND SHBcounter=0 | Details:="OK: Endpoint did not receive channel file during impacted window. Endpoint was offline."; CSUcounter=0 AND SHBcounter=1 | Details:="OK: Endpoint did not receive channel file during impacted window. Endpoint was online."; CSUcounter=1 AND SHBcounter=1 | Details:="CHECK: Endpoint received channel file during impacted window. Endpoint was online. Endpoint has not been seen online in past hour.";
CrowdStrike
19 Jul 2024
3
Solution