EDR: How to Opt Out of CbAlerts Purge during 7.3.0 Server Upgrade
search cancel

EDR: How to Opt Out of CbAlerts Purge during 7.3.0 Server Upgrade

book

Article ID: 285684

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

During an upgrade from 7.2.0 or lower to 7.3.0 or higher, the cbalerts core is purged. This article provides steps to opt out of this for on-prem customers

Environment

  • EDR Console: 7.3.0 or Higher

Resolution

  1. Stop Services
  2. Run
    yum update cb-enterprise
  3. To adjust the retention cap, add the following config to /etc/cb/cb.conf. Primary server only for Clustered. Set to 0 to keep all alerts
    SolrReindexerKeepAlertsDays=DAYS
  4. Complete the upgrade
    /usr/share/cb/cbupgrade
  5. Start services

Additional Information