High RAM Utilization by EDR sensor
book
Article ID: 286207
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
- High Mem Utilization by sensor
- bpf_event_collector.log shows " [W] EventFactory : AllocEvent : Failed to allocate PROCESS event: ##"
- cbdaemon.log shows "[W] LogProcessExit: Process Details for pid[PID] and time[TIME] can't be found. Skipping process exit event"
Environment
- EDR Server: All Supported versions
- EDR Linux Sensor: 7.2.0
Cause
The size of shared memory segment from EDR is initialized with 16MB, which is too small for huge set of events generated in such scenarios.
Resolution
This is fixed in the 7.3.0 and Higher sensor versions
Feedback
thumb_up
Yes
thumb_down
No