Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

CB Response: Why do Procend or Procstarts still send from cb-event-forwarder when disabled?

CB Response: Why do Procend or Procstarts still send from cb-event-forwarder when disabled?

Environment

  • Carbon Black Response Server: All Versions
  • Carbon Black Event Forwarder: All Versions

Question

Why do Procend or Procstarts still send from cb-event-forwarder when disabled?

Answer

When Procend or Procstart is disabled in the cb-event-forwarder the disabled both events will still send. These event use the alias "process" at the ingress of the events.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎03-29-2019
Views:
252
Contributors