"Ensure that raw sensor events are enabled in your EDR server" message received when running check on Event Forwarder
search cancel

"Ensure that raw sensor events are enabled in your EDR server" message received when running check on Event Forwarder

book

Article ID: 287255

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

"Ensure that raw sensor events are enabled in your EDR server (primary and minion) via the 'EnableRawSensorDataBroadcast' variable in /etc/cb/cb.conf" message received when running the following check on Event Forwarder Settings:

/usr/share/cb/integrations/event-forwarder/cb-event-forwarder -check

Environment

  • Carbon Black EDR Server: All Versions
  • Carbon Black EDR Event Forwarder: All Supported Versions

Cause

  • "EnableRawSensorDataBroadcast" variable may not be set correctly in /etc/cb/cb.conf.
  • If Event Forwarder configured correctly, this is just an informational message.

Resolution

This message will show when this check is run regardless if the Event Forwarder is setup correctly or not.

Additional Information

  • As long as a message starting with "Initialized output" is received when the check is run, then the Event Forwarder configurations are correct.