Troubleshooting Agent/Server Backlog
search cancel

Troubleshooting Agent/Server Backlog

book

Article ID: 286122

calendar_today

Updated On: 04-22-2025

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Troubleshooting steps to take when Agent and/or Server Backlog is consistently above the Threshold.

Environment

  • App Control Server: All Supported Versions

Cause

Agent/Server backlog increases when there is an influx of file activity such as Windows Patching, OS upgrades, or other software deployments.

Resolution

Reminder: Some Backlog is expected, as Agents will always generate File and Event data for the Server to process. These steps should be taken when Backlog is consistently above the Threshold.

 

  1. Verify the App Control Server is upgraded to the latest version.
  2. Use Tech Docs to verify the App Control Server is meeting:
  3. Consider creating an ABExclusion for PowerShell temporary files and events
  4. Consider creating an ABExclusion for .NET activity.
  5. Consider discarding information about Locally Approved support files at the Agent.
    • Microsoft files may account for more than half (or more) of all of the files in the Windows environment.
  6. Check for any Drift Reports (Reports > Baseline Drift > Reports) that are no longer needed, and Disable accordingly.
  7. Audit for Custom Rules/Rapid Configs that are potentially triggering or generating Events more frequently than necessary.