What Options are Available For Filtering Event Data?
search cancel

What Options are Available For Filtering Event Data?

book

Article ID: 424212

calendar_today

Updated On:

Products

Carbon Black EDR

Issue/Introduction

What options are there to filter event data from the EDR server? 

  • Increase Retention.
  • Lower Backlog. 

Environment

  • Carbon Black EDR Server: All Versions

Resolution

  1. Filter Known Modloads
  2. Retention Maximization.
    • Consolidates child processes into the parent process document, increasing retention and reducing incoming raw protobuf data. 
    • Advanced Settings
  3. Ingress Filters. 
    • Sensors collect the data. Server drops the matching data at the datastore queue.  
    • Ingress Filtering
  4. Sensor Exclusions. 

Additional Information