EDR: Partial or Truncated Messages using Syslog/Event Forwarder
book
Article ID: 287752
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Messages being sent to from the EDR server to the SIEM are incomplete or truncated.
You will see a similar message in /var/log/cb/notifications/cb-all-notifications.log. Specifically noting the gap between <warning> and the next line starting with "..."