EDR: How To Use a Symlinked Location for Event Storage
search cancel

EDR: How To Use a Symlinked Location for Event Storage

book

Article ID: 285773

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

To  use a symlinked location for event storage

Environment

  • EDR Server: 6.X and higher

Resolution

1. Create a mount point in another location in the file system, such as /data2.
2. Create a symlink to the cbevents* directory inside the solr* directory that points to the mounted directory. For example:

  • ln -s /data2 /var/cb/data/solr/cbevents2

Note: depending on if you upgraded from an older version, it may be under solrN directory like the below example. Check for recent cbevents/cbevents_<date> to confirm which is correct. 

  • ln -s /data2 /var/cb/data/solr6/cbevents2

3. Ensure that the Cb Response user has write permissions in the mounted directory (/data2).

Additional Information

#%$Please note that there is no need to mkdir /var/ cb /data/solr5/cbevents2.#%$