Carbon Black Cloud: Events Suppression in Linux Sensors
Carbon Black Cloud Sensor: 2.10.3, 2.11.3,2.12.0, 2.13.1
Linux: All Supported Versions
How events suppression works in various Linux Sensors ?
2.10.3 - Duplicates Events are not suppressed, Enterprise EDR and Endpoint Standard will have the same events count.
2.11.3 - Support was added for suppression of duplicate Enterprise EDR events and new rules were deployed which activate the suppression. Significant drop in Enterprise EDR event count Endpoint Standard events are unaffected.
2.12.0 - Rules were added to enable suppression of duplicate events Endpoint Standard events count drops.