Environment
- EDR Server: All Versions
- EDR Sensor: All Versions
Symptoms
- A new alert is generated for an old process
- Event was never alerted on in the past
Cause
The sensor had not checked into the server since the event was originally recorded until recently
Resolution
This behavior is expected.
Additional Notes
- Event times are based on the local time of the endpoint. If the endpoint's clock is off, this will also occur
- When a sensor goes offline, it will continue to collect data until a pre-configured size limit. Once that limit is reached, no further data will be collected until other information is offloaded to the EDR server upon checkin.
Related Content