EDR: No messages sent to SIEM through Event Forwarder
search cancel

EDR: No messages sent to SIEM through Event Forwarder

book

Article ID: 290636

calendar_today

Updated On:

Products

Carbon Black EDR (formerly Cb Response)

Issue/Introduction

  • Nothing is logged to the output file location
  • Multiple output addresses are set in cb-event-forwarder.conf, but nothing is received
    • ex. both udpout and syslogout point to the same syslog server ip:port

Environment

  • EDR Server: All Versions (formerly CB Response)
  • Event Forwarder: All Versions

Cause

Only one output address and type can be used

Resolution

  1. Modify the configuration file to use only one of *out locations
  2. Restart Event Forwarder

Additional Information

  • Output will only be written to the outfile if output_type=file
  • Each instance of the Event Forwarder can only send data to one location