EDR: How to find the sensors with large Event/Binary queue size
book
Article ID: 291563
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
Provide information of how to find the sensors with large queue size
Environment
- EDR: All supported versions
- Linux: All supported versions
Resolution
- Logged into EDR console
- Go to Sensors page and select the group of sensor to check
- Click Export -> Export Visible (or Export All) to download the export CSV
- Open CSV and Sort by column "num_eventlog_bytes" for Event queue size check, and by column "num_storefiles_bytes" for Binary queue size check
Feedback
thumb_up
Yes
thumb_down
No