Environment
- Carbon Black Cloud Sensor: 2.11 and newer
- Linux: All Supported Versions
Question
Why is event_collector no longer loaded in kernel on 2.11+ sensor?
Answer
EEDR support for modern Linux distributions was introduced in 2.10.0. ES support for the same was added in 2.11.0. Both products use eBPF technology for event collection (no kernel driver needed), and it requires correct kernel headers to be installed on the system.
Additional Notes
- You should now see
event_collector
in the output from ps aux
- If the sensor reports as offline, headers will need to be installed
Related Content