High RAM Utilization by EDR sensor
search cancel

High RAM Utilization by EDR sensor

book

Article ID: 286207

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

  • High Mem Utilization by sensor
  • bpf_event_collector.log shows " [W] EventFactory : AllocEvent : Failed to allocate PROCESS event: ##"
  • cbdaemon.log shows "[W] LogProcessExit: Process Details for pid[PID] and time[TIME] can't be found. Skipping process exit event"

Environment

  • EDR Server: All Supported versions
  • EDR Linux Sensor: 7.2.0

Cause

 The size of shared memory segment from EDR is initialized with 16MB, which is too small for huge set of events generated in such scenarios. 

Resolution

This is fixed in the 7.3.0 and Higher sensor versions