External Event Logging (Syslog) Slowness
search cancel

External Event Logging (Syslog) Slowness

book

Article ID: 286039

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

Events sent to SIEM or external Syslog Server have a large delay or are otherwise very slow.

Environment

  • App Control Server: All Supported Versions
  • Syslog Enabled (System Configuration > Events > External Event Logging >Syslog Enabled)

Cause

Syslog export is unable to keep up with the current volume of Events coming from Agents among all other Server tasks.

Resolution

  1. Verify the application server is meeting the Operating Environment Requirements for
  2. Follow the steps, Reducing Events Generated in this article to help prevent sending Events by Agents that might not be necessary for the environment.
  3. Consider using the External Analytics feature instead, which may be able to export more Events.

Additional Information

  • There is a potential theoretical maximum of 20M Events/day being sent from the App Control Server to a Syslog Server.
  • In some instances, active environments or very busy App Control Servers may encounter this limit much sooner.