The data that is lost if the primary node in a cluster need to be restored
book
Article ID: 289974
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
What data will be lost if a primary node in a cluster must be restored if all the other nodes are running?
Environment
EDR Server: 7.x
Cluster
Resolution
In an eventless primary node
Any changes in the UI would be lost, i.e., watchlists, new sensor groups, etc.
Any binary files and metadata uploaded since the backup
In a primary node with events all of the above as well as process events would be lost
Additional Information
Some event data can be copied over from the minions. Cbmodules is synced over to the minions, so that can be copied over to the primary node. Any binaries themselves from the downtime would be lost, but metadata would still be there. New sensors seeing binary would upload the files.
If building a new primary node, copy certs from the minions. This should allow sensors to still check into the server, but would check in under the default group.