IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Carbon Black Cloud Linux Sensor: event_collector is not loaded in kernel

Carbon Black Cloud Linux Sensor: event_collector is not loaded in kernel

Environment

  • Carbon Black Cloud Sensor: 2.11 and newer
  • Linux: All Supported Versions

Question

Why is event_collector no longer loaded in kernel on 2.11+ sensor?

Answer

EEDR support for modern Linux distributions was introduced in 2.10.0. ES support for the same was added in 2.11.0. Both products use eBPF technology for event collection (no kernel driver needed), and it requires correct kernel headers to be installed on the system.

Additional Notes

  • You should now see event_collector in the output from ps aux
  • If the sensor reports as offline, headers will need to be installed

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-03-2021
Views:
781
Contributors