Environment
- EDR Server: 7.1 and Higher (formerly CB Response)
- EDR Event Forwarder: 3.7.0 and Higher
Objective
Set up monitoring for the service status of Event Forwarder and start services if stopped
Resolution
- Determine how often to check the running state of the service
- Decide which scripting language / services to use to query the API
- Add a GET request for the status of the service
- Use the "state" field returned to determine if the service is running. Different states are Running,Stopped, and Unknown
- If stopped, send a POST request to the same control to start services with the following body
Related Content