Online sensor count in the EDR dashboard is too low
book
Article ID: 368027
calendar_today
Updated On:
Products
Carbon Black EDR (formerly Cb Response)
Issue/Introduction
The online sensor count in the EDR dashboard is lower than the actual number of sensors reporting in and uploading data.
Environment
EDR Server: 7.x
EDR Sensors: All versions
Linux: All versions
Cause
There is a timeout value of 5 minutes. If this time window is exceeded, the sensor is considered offline and therefore not included in the online total.
Resolution
The issue may be resolved by increasing the server's timeout value by:
editing /etc/cb/cb.conf (on the Primary only for clusters)
uncomment #SensorCheckinOnlineIntervalMin=5 and set this to a number higher that 5. For example:
SensorCheckinOnlineIntervalMin=10
restart EDR server / cluster services
Additional Information
The primary server's /var/log/cb/nginx/access.log flooded with 499 errors.
The /var/log/cb/nginx/error.log is showing these errors:
upstream prematurely closed connection while reading response header from upstream