Does the Event Forwarder Cache Events When the Connection is Lost to the SIEM?
search cancel

Does the Event Forwarder Cache Events When the Connection is Lost to the SIEM?

book

Article ID: 415226

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

Does the cb-event-forwarder delete or cache the events when the network connectivity is lost to the SIEM?

Environment

  • Carbon Black EDR: All Versions
  • Cb-Event-Forwarder: All Versions

Resolution

The event forwarder will cache the data until the connection is established again. It will attempt to re-establish the connection every minute and then start submitting the data again when the connection is successful. 

Additional Information

  • The event forwarder writes a temporary file with a batch of events to /var/cb/data/event-forwarder. Once submitted successfully the temporary file is removed. During the connection loss these files will remain until connection is established again and removed as they are successfully sent. 
  • If there is a concern of a long standing connection issue, disk space can become full depending on how the system is partitioned. 
  • If the event forwarder service is stopped while the EDR services are running and ingesting data, this data will be lost. There is no way to resend the data missed during this time through the event forwarder.