search
cancel
Search
What Options are Available For Filtering Event Data?
book
Article ID: 424212
calendar_today
Updated On:
Feedback
Subscribe
Products
Carbon Black EDR
Show More
Show Less
Issue/Introduction
What options are there to filter event data from the EDR server?
Increase Retention.
Lower Backlog.
Environment
Carbon Black EDR Server: All Versions
Resolution
Filter Known Modloads
Filters known dlls from Windows
Advanced Settings
Retention Maximization.
Consolidates child processes into the parent process document, increasing retention and reducing incoming raw protobuf data.
Advanced Settings
Ingress Filters.
Sensors collect the data. Server drops the matching data at the datastore queue.
Ingress Filtering
Sensor Exclusions.
Data is dropped at the sensor level.
Exclusion Settings
Additional Information
What Known Modloads are Filtered when the Feature is Enabled?
How Does Retention Maximization Setting Affect Process Queries?
How to Determine Top Noisy and Chatty Hosts and Processes
Feedback
thumb_up
Yes
thumb_down
No