Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: How to find the sensors with large Event/Binary queue size

EDR: How to find the sensors with large Event/Binary queue size

Environment

  • EDR: All supported versions
  • Linux: All supported versions

Objective

Provide information of how to find the sensors with large queue size

Resolution

  1. Logged into EDR console
  2. Go to Sensors page and select the group of sensor to check
  3. Click Export -> Export Visible (or Export All) to download the export CSV
  4. Open CSV and Sort by column "num_eventlog_bytes" for Event queue size check, and by column "num_storefiles_bytes" for Binary queue size check

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎06-20-2022
Views:
82
Contributors