IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: How to Collect Diagnostic Logs for Performance Related Issues (Linux)

EDR: How to Collect Diagnostic Logs for Performance Related Issues (Linux)

Environment

  • EDR Sensor: 6.x and Higher
  • Linux: All Supported Versions

Objective

To collect relevant logs on a Linux endpoint in order to troubleshoot most performance-related issues. Typical issues may include:
  • General system performance issues
  • High CPU/Memory of EDR sensor process
  • High CPU/Memory of third-party applications

Resolution

  1. Log onto the Linux endpoint exhibiting performance issues.
  2. Gather an strace output for the cbdaemon process.
  3. Generate a Linux endpoint diag report
  4. Upload all log files to CB Vault
  5. Update your VMWare Carbon Black Technical Support case with further relevant information:
- Is this Linux endpoint also serving as an EDR console server (primary or secondary node?)

- Is the performance issue a reproducible scenario and if so, what steps, if any, are taken to reproduce it? 
(For example, were any backups, updates, or large file transfers being performed?)

- How many endpoints are affected? What are their general system profiles and function? 

- What other security applications/real-time scanners are installed? Have these exclusions been applied?
https://docs.vmware.com/en/VMware-Carbon-Black-EDR/services/cb-edr-sensor-install-guide/GUID-4205B17E-DF27-4AD9-AEDA-17BC9088F43F.html

- How long do the performance issues last? 

- What actions, if any, return the system performance to normal?

- Is the endpoint connected to any network shares? 

- Does this endpoint generate a large number of logs, binaries, or PDF reports?

 

Additional Notes

EDR Sensor version 7.2.0 contains improvements to memory and CPU performance, reference 'Resolved Issues' section in the release notes: 

Related Content


Labels (2)
Tags (3)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-24-2020
Views:
2212
Contributors