IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

EDR: Is it Possible to Filter Data in Event Forwarder?

EDR: Is it Possible to Filter Data in Event Forwarder?

Environment

  • EDR Event Forwarder: All Supported Versions Except For v3.8.4
  • EDR Server: All Supported Versions

Question

  • Can EDR Event Forwarder filter data?

Answer

  1. Yes, fields can be filtered within Event Forwarder.
  2. Add the following to the /etc/cb/integrations/event-forwarder/cb-event-forwarder.conf configuration file if missing: remove_from_output="field to be filtered"
    1. Example below would be for filtering out command lines from being forwarded: 
      remove_from_output=command_line,cmdline

Additional Notes

In Event Forwarder v3.8.4 remove_from_output variable functionality is broken.

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎01-15-2019
Views:
471