EDR: How to Collect Raw Sensor Events at the Server
book
Article ID: 287941
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
How to Collect Raw Sensor Events at the Server
Environment
- EDR Server: All Supported Versions
Resolution
- Collecting for All Sensors:
- Collecting for Specific Sensor(s). 7.1.1 Server or Higher Only
- Restart Services: EDR: How to restart server services
- After data collection, rename or delete the configuration file and restart services again to stop the verbose logging
Additional Information
- This feature is used to help investigate possible missing data in the Server UI or sent via CB-Event-Forwarder to a SIEM.
Feedback
thumb_up
Yes
thumb_down
No